typeanalysisfamilyunclassified-batch-powershell-dropperconfidencemediumscriptdropperc2defense-evasionexecutiondotnetmasqueradepersistence
SHA-256: 2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2

unclassified-batch-powershell-dropper: 2232eb68 — AnyDesk-masquerade .NET batch dropper with PhantomGate loader and IPFS/paste C2

Executive Summary

A 32 KB .NET Framework PE32 executable masquerading as AnyDesk 9.6.11. The binary embeds a complete DOS batch script in its .text section that expands 60 SET variables into a UTF-16LE Base64-encoded PowerShell command. The PowerShell pins TLS 1.2, downloads a .NET assembly from an IPFS mirror or a Norwegian paste site, and reflectively loads it via a PhantomGate bootstrap class into myprogram.Homees.runss. Persistence is achieved by copying the batch to C:\ProgramData\khcrdab.bat. The builder shows the same myprogram.Homees type name and runss entry method observed across the unclassified-batch-powershell-dropper and unclassified-js-bitbucket-stego-dropper families, confirming this is a new morph of an established commodity builder rather than an isolated sample.

What It Is

  • SHA-256: 2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2 ^[metadata.json]
  • Filename: 10784_30601_10_PDF.exe (invoice/PDF masquerade, double-extension risk) ^[triage.json]
  • File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
  • Size: 32,768 bytes ^[triage.json]
  • Linker: .NET Framework v4.0.30319 (C# Roslyn / Visual Studio 2022-era IL) ^[strings.txt:5]
  • Compilation timestamp: Thu May 28 11:15:01 2026 UTC ^[pefile.txt:34]
  • Signed: No ^[rabin2-info.txt:27]
  • Version info masquerade: AnyDesk Software GmbH, FileDescription "AnyDesk", FileVersion "9.6.11" ^[exiftool.json:36-38] ^[pefile.txt:222-227]
  • SSDeep: 768:yz57Ngy0RKX/bFXnwwKsuGgReSUaq1LyJQz:8/bNnwfsuGyda ^[ssdeep.txt]

Family attribution: Tier 1 variant of the unclassified-batch-powershell-dropper cluster. Same SET/GOTO variable-expansion obfuscation, same paste-site/IPFS download chain, same myprogram.Homees.runss reflective invocation, but adds a professionally crafted AnyDesk version-info masquerade and a new RegAsm masquerade string (replacing the older MsBuild string). ^[entities/unclassified-batch-powershell-dropper.md]

How It Works

Stage 1: .NET PE32 wrapper

The binary is a standard C# console/GUI PE32 compiled to .NET Framework 4.0. Its entry point is Program.Main at 0x0040206c ^[rabin2-info.txt:11] ^[r2:entry0]. The .text section contains the batch payload as a string literal; the .rsrc section holds a 7-icon AnyDesk icon group and a VS_VERSIONINFO block cloned from legitimate AnyDesk metadata. ^[binwalk.txt:5] ^[pefile.txt:211-239]

Stage 2: Batch expansion

At runtime, the C# executable writes the batch script to a temporary location and launches it via ProcessStartInfo with WindowStyle.Hidden and CreateNoWindow=true. ^[capa.txt:29-34] The batch script uses 60 SET variables with random 8–10 character uppercase names (e.g., NOHONJGDHD, FOJDFGFFHD, HSJNGGJDDN) concatenated via %var% interpolation into a single command line. ^[strings.txt:119-335]

Stage 3: PowerShell decode

The concatenated string is Base64-decoded into a UTF-16LE PowerShell script. The script performs:

  1. Start-Sleep -Seconds 3 — simple anti-sandbox delay. ^[decoded payload]
  2. TLS 1.2 pinning: [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
  3. Defines PhantomGate.LoadAssembly(byte[]) — a trivial AppDomain.CurrentDomain.Load() wrapper. ^[decoded payload]
  4. Defines d($l) — failover downloader using Net.WebClient with Get-Random URL selection from an array $k. ^[decoded payload]
  5. Defines i($a,$t,$m,$p) — reflective assembly invoke: loads the bytes, resolves type by full name, resolves method by name + binding flags, creates instance if non-static, and invokes. ^[decoded payload]

Stage 4: C2 download

The URL array $k contains two failover endpoints:

  • https://arbitrary-chocolate-tiglon.myfilebase.com/ipfs/QmNaXFQZwK4XA3P94A8ug5gte97BQr8UuA87JeDAPKVCdK — IPFS-hosted payload via MyFileBase gateway.
  • https://paste.sensio.no/TripletsMechanic — Norwegian paste-site payload. ^[decoded payload]

The downloader fetches the payload, extracts a Base64 blob between <<START>> and <<END>> markers, decodes it, and passes it to i() along with the arguments:

i ([Convert]::FromBase64String($Matches[1])) 'myprogram.Homees' 'runss' @($gg, '1', 'khcrdab', 'RegAsm', '0', 'x86')

The $gg argument is a reversed-string URL: txt.iahegFS/20/42.68.38.301//:gsffsfsd with the last 8 characters stripped, then reversed, yielding ://103.83.86.24/02/SFgehai.txt (an HTTP endpoint on a Chinese-registered IP). ^[decoded payload]

Stage 5: Persistence

After launching the assembly, the PowerShell copies the original batch file to C:\ProgramData\khcrdab.bat via Copy-Item -Path '%~f0' -Destination 'C:\ProgramData\khcrdab.bat' -Force -ErrorAction SilentlyContinue. ^[decoded payload]

Decompiled Behavior

Ghidra analysis on CIL binaries yields minimal useful pseudo-C; radare2 confirms the entry point is Program.Main at 0x0040206c and identifies 51 functions total, most of them compiler-generated .cctor and LINQ closure methods (<Main>b__0_0 through <Main>b__0_11, ComputeSum, ComputeWeirdMetric). ^[r2:fcn.0040206c] ^[strings.txt:7-40] The actual malicious logic is not in the C# code itself but in the embedded batch string, making static decompilation of limited value. The capa fingerprint confirms .NET compilation, process creation with hidden window, file write, file delete, and console buffer manipulation — all consistent with a batch-executor wrapper. ^[capa.txt]

C2 Infrastructure

IOC Type Evidence
https://arbitrary-chocolate-tiglon.myfilebase.com/ipfs/QmNaXFQZwK4XA3P94A8ug5gte97BQr8UuA87JeDAPKVCdK IPFS payload mirror Decoded PowerShell
https://paste.sensio.no/TripletsMechanic Paste-site payload Decoded PowerShell
103.83.86.24 Second-stage IP (reversed-string decode) Decoded PowerShell
C:\ProgramData\khcrdab.bat Persistence file path Decoded PowerShell
PhantomGate .NET bootstrap class name Decoded PowerShell
myprogram.Homees .NET payload type name Decoded PowerShell
runss .NET payload entry method Decoded PowerShell
RegAsm Masquerade string passed to payload Decoded PowerShell

No hardcoded mutex, named pipe, or registry key was recovered. The C2 is entirely URL-based and depends on the paste sites remaining live.

Interesting Tidbits

  • AnyDesk masquerade is complete: The PE carries the full AnyDesk VS_VERSIONINFO (CompanyName, FileDescription, FileVersion 9.6.11, ProductName, LegalCopyright) and a 7-icon RT_ICON group. The legitimate AnyDesk binary is much larger (~4 MB+); this 32 KB impostor will stand out to any size-aware triage. ^[pefile.txt:222] ^[binwalk.txt:5]
  • Fresh compile: Build timestamp May 28 2026 11:15:01 UTC matches the MalwareBazaar ingestion time (May 28 2026 16:01 UTC). This was built and uploaded within ~5 hours. ^[pefile.txt:34] ^[exiftool.json:7]
  • PhantomGate class: The inner PowerShell defines PhantomGate.LoadAssembly() — a new class name not observed in prior siblings of this cluster, which used raw [Reflection.Assembly]::Load. The builder is evolving. ^[decoded payload]
  • RegAsm replaces MsBuild: Earlier Tier-1 siblings passed MsBuild as the masquerade string. This morph passes RegAsm, another trusted developer utility. The string is likely used for process-name masquerade or file-write path selection inside the inner payload. ^[decoded payload]
  • IPFS as CDN: Use of myfilebase.com (a public IPFS gateway) for payload hosting is a cheap, abuse-resistant hosting layer. The gateway domain resolves the content via the immutable IPFS hash QmNaXFQZwK4XA3P94A8ug5gte97BQr8UuA87JeDAPKVCdK. ^[decoded payload]
  • Reversed-string URL: The second-stage URL 103.83.86.24 is encoded as a reversed string with an 8-character junk suffix. This anti-static technique was also observed in the eda47a53 sibling (sostsenrer2 reversed GitLab URL). ^[decoded payload]
  • Floss failure: flare-floss exited with an argument error (--no flag collision), so no decoded strings were recovered automatically. Manual batch reconstruction was required. ^[floss.txt]

How To Mess With It (Homelab Replication)

Goal: Reproduce a .NET PE32 that embeds a batch script, expands it via ProcessStartInfo with hidden window, and executes a PowerShell payload.

Toolchain:

  • Visual Studio 2022 Community or dotnet new console -f net48
  • C# target: net48 (produces the same v4.0.30319 metadata)

Steps:

  1. Write a C# console app that reads a batch script from an embedded resource or string literal.
  2. Use ProcessStartInfo with WindowStyle = ProcessWindowStyle.Hidden, CreateNoWindow = true, and UseShellExecute = false.
  3. Write the batch to %TEMP%\anydesk_update.bat and launch cmd.exe /c on it.
  4. The batch script should use SET variables + %var% concatenation to assemble a powershell.exe -WindowStyle Hidden -Command "..." line.
  5. The PowerShell command Base64-encodes a UTF-16LE script that downloads a payload and reflectively loads it.
  6. Add VS_VERSIONINFO with AnyDesk (or other legitimate software) metadata and a borrowed icon group to complete the masquerade.

Verification: Run capa on the reproducer; it should hit the same .NET + create process + write file + delete file capabilities. Compare pefile output to verify 3-section PE32 with .text, .reloc, .rsrc.

Deployable Signatures

YARA Rule

rule Unclassified_Batch_PowerShell_Dropper_AnyDesk_Masquerade {
    meta:
        description = "Detects .NET PE32 embedding batch script with AnyDesk version masquerade"
        author = "PacketPursuit"
        date = "2026-08-13"
        hash = "2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2"
        family = "unclassified-batch-powershell-dropper"
    strings:
        $anydesk_company = "AnyDesk Software GmbH" wide ascii
        $anydesk_desc = "AnyDesk" wide ascii
        $anydesk_version = "9.6.11" wide ascii
        $batch_echo = "@echo off" ascii
        $batch_goto = "GOTO " ascii
        $batch_set = "SET " ascii
        $concat_marker = /%[A-Z]{8,10}%/ ascii
        $ps_b64prefix = "powershell.exe -WindowStyle Hidden" ascii
        $phantomgate = "PhantomGate" ascii
        $homees = "myprogram.Homees" ascii
    condition:
        uint16(0) == 0x5A4D and
        ($anydesk_company or $anydesk_desc) and
        ($batch_echo or $batch_goto or $batch_set) and
        ($concat_marker or $ps_b64prefix or $phantomgate or $homees) and
        filesize < 100KB
}

Sigma Rule

title: AnyDesk Masquerade Batch Dropper Execution
description: Detects the execution pattern of the 2232eb68 dropper — hidden cmd/powershell spawned by a small .NET PE with AnyDesk metadata, followed by network to paste/IPFS sites.
logsource:
    category: process_creation
    product: windows
detection:
    selection_pe:
        - Image|contains: 'AnyDesk'
        - CommandLine|contains:
            - 'khcrdab'
            - 'PhantomGate'
            - 'myprogram.Homees'
    selection_network:
        - DestinationHostname|contains:
            - 'myfilebase.com'
            - 'paste.sensio.no'
        - DestinationIp|contains: '103.83.86.24'
    selection_persistence:
        TargetFilename|contains: 'C:\\ProgramData\\khcrdab.bat'
    condition: selection_pe or selection_network or selection_persistence
falsepositives:
    - Unlikely; the `khcrdab` filename and `myprogram.Homees` type name are unique to this crimeware builder.
level: high

IOC List

IOC Type Context
2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2 SHA-256 Dropper PE32
10784_30601_10_PDF.exe Filename Invoice masquerade
C:\ProgramData\khcrdab.bat File path Persistence copy
arbitrary-chocolate-tiglon.myfilebase.com Domain IPFS payload gateway
paste.sensio.no Domain Paste-site payload host
103.83.86.24 IP Second-stage C2 (reversed-string decode)
PhantomGate Class name .NET reflective loader bootstrap
myprogram.Homees Type name .NET payload entry class
runss Method name .NET payload entry method
RegAsm String Masquerade argument passed to payload

Behavioral Fingerprint

This binary is a 32 KB .NET Framework PE32 with cloned AnyDesk version metadata and icon group. At runtime it drops and executes a hidden-window batch script that assembles 60 SET variables into a Base64-encoded PowerShell command. The PowerShell pins TLS 1.2, attempts to download a .NET assembly from an IPFS mirror or Norwegian paste site (failover), extracts a Base64 blob between <<START>>/<<END>> delimiters, and reflectively loads it via a PhantomGate bootstrap into myprogram.Homees.runss with a reversed-string C2 URL and a RegAsm masquerade string. Post-execution, it copies the batch file to C:\ProgramData\khcrdab.bat for persistence. The builder shares the myprogram.Homees type name and runss method with the unclassified-batch-powershell-dropper and unclassified-js-bitbucket-stego-dropper clusters.

Detection Signatures

Capability Namespace ATT&CK Mapping
manipulate console buffer host-interaction/console T1059.003
delete file host-interaction/file-system/delete T1070.004
write file in .NET host-interaction/file-system/write T1105
create a process with modified I/O handles and window host-interaction/process/create T1059.003, T1059.001
create process in .NET host-interaction/process/create T1059.003
terminate process host-interaction/process/terminate T1059.003
compiled to the .NET platform runtime/dotnet —

Additional ATT&CK mappings based on decoded payload:

  • T1059.001 (PowerShell) — inline nested script with hidden window.
  • T1059.003 (Windows Command Shell) — batch script parent.
  • T1105 (Ingress Tool Transfer) — paste-site/IPFS download.
  • T1620 (Reflective Code Loading) — [Reflection.Assembly]::Load via PhantomGate.
  • T1127.001 (Trusted Developer Utilities Proxy Execution: MSBuild) — masquerade string variant (RegAsm instead of MsBuild); see msbuild-proxy-execution.
  • T1027.010 (Obfuscated Files or Information) — Base64 + reversed-string URL + batch variable expansion.

References

  • MITRE ATT&CK T1059.001: https://attack.mitre.org/techniques/T1059/001/
  • MITRE ATT&CK T1059.003: https://attack.mitre.org/techniques/T1059/003/
  • MITRE ATT&CK T1105: https://attack.mitre.org/techniques/T1105/
  • MITRE ATT&CK T1620: https://attack.mitre.org/techniques/T1620/
  • MITRE ATT&CK T1127.001: https://attack.mitre.org/techniques/T1127/001/
  • MITRE ATT&CK T1027.010: https://attack.mitre.org/techniques/T1027/010/
  • Entity page: unclassified-batch-powershell-dropper
  • Technique page: version-info-masquerade
  • Procedure page: msbuild-proxy-execution
  • Related cluster: unclassified-js-bitbucket-stego-dropper

Provenance

Analysis based on static artifacts only (CAPE skipped — no Windows guest available). Source files: file.txt, exiftool.json, pefile.txt, strings.txt, floss.txt, capa.txt, binwalk.txt, rabin2-info.txt, metadata.json, triage.json. Decoded PowerShell payload reconstructed manually from 60 SET variable fragments in strings.txt via Base64 → UTF-16LE decode. Radare2 analysis run at level 2 on CIL binary. No dynamic execution observed; all C2 IOCs recovered from static batch reconstruction.