5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bedxloader: 5a26fd46 — Three-tier batch→PowerShell→.NET dropper with AES/rail-fence payload and MSBuild proxy injection
Executive Summary
A 1.18 MB batch-script dropper delivering the XLoader infostealer family. The outer .bat decrypts an inner .bat via AES-CBC + rolling XOR; the inner .bat extracts a PowerShell block that decrypts a .NET Framework DLL (CryptoObfuscator-protected) and a 561 KB final payload via AES-256-CBC and a seeded rail-fence cipher. The .NET assembly reflectively injects the payload into MSBuild.exe under DigitalAudioForge.Processing audio-themed namespace masquerade. Persistence is via Task Scheduler (SystemTelemetrics / UserInterfaceProcessHost). Static-only — CAPE skipped batch files.
What It Is
- Filename:
LX_2026815111.bat^[triage.json] - File type: DOS batch file, ASCII text, CRLF line terminators, 1,181,509 bytes ^[file.txt]
- SHA-256:
5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed - Family: XLoader (high-confidence; author comment
#XLOADERleft in inner PowerShell) ^[inner.ps1:114] - Build date: Inner .NET DLL compiled Sat May 23 16:21:36 2026 (timestamp from PE header) ^[rabin2-info.txt]
How It Works
Tier 1 — Outer Batch Self-Launcher
The outer .bat checks if argument 1 equals the hardcoded token 297cfdb93967. If not, it spawns a hidden powershell.exe → cmd.exe chain that re-executes itself with the token. ^[strings.txt:1-5] This guarantees the payload runs inside a hidden console window regardless of how the victim launched it.
On :exec, it:
- Locates
---BEGIN_PS---and---BEGIN_ENC---markers by line number usingfindstr. - Tail-extracts the PowerScript block and Base64 blob via
Get-Content -Tail. - Decrypts the inner
.batwith AES-CBC (hardcoded key/IV) then XORs the plaintext with a second 24-byte key. ^[strings.txt:26-51] - Writes the result to
%TEMP%\<random>.batand executes it. - Deletes temp files.
Tier 2 — Inner Batch + Persistence
The decrypted inner .bat (861 KB, 340 lines) is a self-contained persistence engine:
- Relaunch: Same hidden
powershell.exe→cmd.exeself-relaunch pattern with__hiddentoken. ^[payload.bat:6] - Persistence directory:
%LOCALAPPDATA%\Local Studio(masquerades as a benign studio app). ^[payload.bat:18-19] - Persistence file:
UserSessionManager.bat— a copy of the inner script itself. ^[payload.bat:22-23] - Task Scheduler: Creates a task named
SystemTelemetrics(if elevated) orUserInterfaceProcessHost(if standard), triggered on logon and optionally on boot (elevated only). The task launches PowerShell to run the persistent.bathidden. ^[payload.bat:27-35] - Self-delete guard: Skips deletion if the current path contains
Local Studio,WindowsUpdate,MicrosoftEdge,OneDrive,Google,Adobe,\Temp\System, orProgramData. ^[payload.bat:74] - Payload extraction: Finds
---BEGIN_PS---at line 213 and extracts the remaining 128 lines into a volatile.ps1. ^[payload.bat:58]
Tier 3 — Inner PowerShell: Decryption + Reflective Injection
The volatile PowerShell script (~128 lines) contains two encrypted assets and an injection routine:
- .NET DLL: Base64-encoded, AES-256-CBC encrypted (key
0x84,0x29,..., IV0xEF,0x74,...). After decryption: a 73 KB PE32+ x64 Mono/.NET assembly. PDB path:C:\Users\UserPC\source\repos\jhPt\jhPt\bin\Debug\CryptoObfuscator_Output\jhPt.pdb. ^[rabin2-info.txt] - Final payload: Base64-encoded, 561 KB. Decrypted via AES-256-CBC, then unscrambled with a seeded rail-fence cipher using
masterSeedPhrase = "ofD1*Vc9%Vzh6CMM#s*qG*Mz". ^[inner.ps1:8] The rail count and read-order permutation are both derived from the seed string's ASCII sum viaSystem.Random, making the obfuscation deterministic but non-obvious without the seed. - Injection target:
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe. ^[inner.ps1:112] The script explicitly comments:#XLOADER $targetProcess = [System.Diagnostics.Process]::GetCurrentProcess().MainModule.FileName. ^[inner.ps1:114] - Namespace masquerade: The loaded assembly exposes
DigitalAudioForge.Processingnamespace with benign-sounding classes (TrackQuery,AudioStreamOrchestrator,SystemPlaybackInitiator,AudioEffectProcessor). The payload bytes are passed asPcmData, andOrchestrateAudioSynthesisis invoked — all synonyms for process injection. ^[inner.ps1:106-127] - Window hiding: P/Invoke to
FreeConsole()andShowWindowvia inline C# member definition. ^[inner.ps1:102-104]
Final Payload
The 561 KB decrypted payload (post rail-fence) has entropy 6.55 and begins with ZM (byte-swapped MZ). It contains an LZMA dictionary-size signature at offset 20356, suggesting a compressed or encrypted PE inner layer. Without dynamic execution the full API surface is not recoverable; the injection chain is sufficient evidence that this is the XLoader core.
Decompiled Behavior
Static-only (CAPE skipped batch files). The full behavioral chain is reconstructed from nested script decryption:
cmd.exe→powershell.exe(hidden window, outer relaunch)powershell.exedecrypts outer.bat→ writes temp.bat→cmd.exe(inner stage)- Inner
cmd.exe→powershell.exe(hidden, executes volatile.ps1) - Volatile
powershell.exe→ decrypts .NET DLL + final payload →[System.Reflection.Assembly]::Load - .NET assembly →
Process.Start(MSBuild.exe)+OrchestrateAudioSynthesis(process hollowing/injection into trusted binary)
C2 Infrastructure
No hardcoded C2 URLs, IPs, or domains recovered from static extraction. XLoader historically uses HTTPS C2 with RC4-encrypted payloads and domain-fronting; this sample may resolve C2 at runtime from the final injected payload. The presence of LZMA-compressed data suggests a staged config or payload fetch.
Interesting Tidbits
- Author fingerprint: The
#XLOADERcomment in the PowerShell source is an unambiguous family marker. ^[inner.ps1:114] - Builder environment: PDB path references
UserPCandjhPtproject name, compiled through CryptoObfuscator. The namespaceDigitalAudioForge.Processingis likely auto-generated or manually chosen to evade string-based detection. - Filename pattern:
LX_prefix with numeric suffix (LX_2026815111.bat) resembles a delivery-campaign naming convention. - Self-delete sophistication: The guard string list (
Local Studio,WindowsUpdate,MicrosoftEdge, etc.) is designed to prevent cleanup of the persistent copy while allowing the original dropper to erase itself. - No network downloader: Unlike many batch droppers that fetch stage-2 from a paste site, this sample is fully self-contained — all tiers are embedded in the single
.bat. This makes single-file sandbox detonation more informative, though CAPE's batch-file skip prevented that.
How To Mess With It (Homelab Replication)
Reproducing this chain for educational purposes:
- Build a .NET DLL injector targeting
MSBuild.exeusingProcess.Startwith hidden window +Assembly.Loadof a second payload. - Obfuscate with CryptoObfuscator (trial available) to reproduce the
CryptoObfuscator_OutputPDB fingerprint. - Encrypt the DLL with AES-256-CBC + Base64.
- Encrypt the payload with AES-256-CBC, then apply a seeded rail-fence cipher using a passphrase-derived
System.Randompermutation. - Wrap in PowerShell with
FreeConsole()P/Invoke and benign namespace (DigitalAudioForge.Processing). - Embed in batch with
---BEGIN_PS---/---BEGIN_ENC---markers andfindstrextraction. - Add persistence via
schtasks.exeXML withLogonTrigger+ optionalBootTrigger.
Deployable Signatures
YARA Rule
rule XLoader_BatchDropper_2026 : xloader {
meta:
description = "XLoader three-tier batch dropper with AES/rail-fence payload"
author = "PacketPursuit"
date = "2026-08-24"
sha256 = "5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed"
strings:
$a1 = "---BEGIN_PS---"
$a2 = "---BEGIN_ENC---"
$a3 = "297cfdb93967"
$a4 = "Local Studio" nocase
$a5 = "UserSessionManager.bat" nocase
$a6 = "SystemTelemetrics" nocase
$a7 = "UserInterfaceProcessHost" nocase
$b1 = "DigitalAudioForge.Processing"
$b2 = "TrackQuery"
$b3 = "OrchestrateAudioSynthesis"
$b4 = "PcmData"
$c1 = "ofD1*Vc9%Vzh6CMM#s*qG*Mz"
$c2 = "CryptoObfuscator_Output"
$c3 = "#XLOADER"
condition:
(uint16(0) == 0x6540 or uint16(0) == 0x4065) and // '@e' or '@E' for @echo off
filesize > 500KB and
3 of ($a*) and
2 of ($b*) and
any of ($c*)
}
Behavioral Hunt Query (Sigma)
title: XLoader Batch Dropper Execution Chain
description: Detects the three-tier execution chain observed in XLoader sample 5a26fd46
logsource:
category: process_creation
product: windows
detection:
selection_relaunch:
CommandLine|contains:
- 'powershell -WindowStyle Hidden -NonInteractive'
- '297cfdb93967'
selection_persistence:
CommandLine|contains:
- 'SystemTelemetrics'
- 'UserInterfaceProcessHost'
- 'Local Studio\UserSessionManager.bat'
selection_injection:
ParentImage|endswith: '\\powershell.exe'
Image|endswith: '\\MSBuild.exe'
CommandLine|contains: '__hidden'
condition: selection_relaunch or selection_persistence or selection_injection
falsepositives:
- Unknown
level: high
IOC List
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed |
Hash |
| Filename | LX_2026815111.bat |
Filename |
| Mutex / Task Name | SystemTelemetrics |
Scheduled Task |
| Mutex / Task Name | UserInterfaceProcessHost |
Scheduled Task |
| Persistence Path | %LOCALAPPDATA%\Local Studio\UserSessionManager.bat |
File Path |
| .NET Namespace | DigitalAudioForge.Processing |
String |
| .NET Class | TrackQuery |
String |
| .NET Method | OrchestrateAudioSynthesis |
String |
| Decryption Seed | ofD1*Vc9%Vzh6CMM#s*qG*Mz |
String |
| Injection Target | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe |
File Path |
| Builder PDB | C:\Users\UserPC\source\repos\jhPt\jhPt\bin\Debug\CryptoObfuscator_Output\jhPt.pdb |
Build Artifact |
| AES Key (DLL) | 842924A4AF2A7C68D047BAF786910DF02C928B90BDF8CBDF5E618AD621AB34D2 |
Key Material |
| AES IV (DLL) | EF742128FD33F3C1EF16D92A17C193C1 |
Key Material |
Behavioral Fingerprint
This threat actor delivers a single, large batch file (~1 MB) containing three embedded data zones. Upon execution, it relaunches itself via a hidden PowerShell/cmd.exe chain using a hardcoded token argument. It decrypts an inner batch script with AES-CBC and rolling XOR, which then stages persistence in %LOCALAPPDATA%\Local Studio and registers a logon-triggered scheduled task named SystemTelemetrics or UserInterfaceProcessHost. The inner script extracts a PowerShell block that decrypts a .NET assembly (CryptoObfuscator-obfuscated) and a 561 KB final payload using AES-256-CBC followed by a passphrase-derived rail-fence cipher. The .NET assembly loads reflectively, hides the console, and injects the final payload into MSBuild.exe under audio-themed class names (DigitalAudioForge.Processing.AudioStreamOrchestrator).
Detection Signatures (ATT&CK Mapping)
| Technique ID | Technique Name | Evidence |
|---|---|---|
| T1059.001 | PowerShell | Outer and inner PowerShell execution with hidden window. ^[strings.txt:5] ^[payload.bat:7] ^[inner.ps1:1] |
| T1059.003 | Windows Command Shell | Batch file self-launch and extraction. ^[file.txt] ^[payload.bat:1] |
| T1027.002 | Obfuscated Files or Information | AES-CBC + Base64 + rolling XOR + rail-fence cipher + CryptoObfuscator. ^[strings.txt:26-51] ^[inner.ps1:4-8] ^[rabin2-info.txt] |
| T1055 | Process Injection | Reflective .NET assembly loads final payload and injects into MSBuild.exe. ^[inner.ps1:97,112,127] |
| T1127.001 | Trusted Developer Utilities Proxy Execution | Target process explicitly set to MSBuild.exe. ^[inner.ps1:112] |
| T1053.005 | Scheduled Task/Job: Scheduled Task | schtasks.exe XML task with LogonTrigger and optional BootTrigger. ^[payload.bat:35] |
| T1547.001 | Boot or Logon Autostart Execution | File copy to %LOCALAPPDATA%\Local Studio\UserSessionManager.bat. ^[payload.bat:22-23] |
| T1070.004 | File Deletion | Self-delete of temp scripts; guard against deleting persistent copy. ^[payload.bat:74] |
| T1564.003 | Hide Artifacts: Hidden Window | WindowStyle Hidden, FreeConsole(), ShowWindow. ^[strings.txt:5] ^[inner.ps1:102-104] |
| T1204.001 | User Execution: Malicious Link/File | Batch file social-engineering lure. ^[triage.json] |
References
- xloader — Family entity page
- msbuild-proxy-execution — Procedure page for MSBuild abuse
- rail-fence-cipher-payload-obfuscation — Technique page for seeded rail-fence payload encoding
- audio-themed-namespace-masquerade — Technique page for benign-namespace process injection disguise
- MalwareBazaar:
LX_2026815111.bat(sha256:5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed)
Provenance
file.txt— file(1) output,filev5.44triage.json— triage pipeline metadatastrings.txt— strings(1) outputrabin2-info.txt— radare2rabin2 -Ion decrypted .NET DLL- Inner PowerShell reconstructed from
---BEGIN_PS---block in decrypted inner batch - Decryption performed manually with Python3 + OpenSSL AES-256-CBC + custom rail-fence reverse
- Final payload entropy calculated with Shannon entropy (H ≈ 6.55)