typeanalysisfamilyxloaderconfidencehighmalware-familyinfostealerscriptdefense-evasionexecutionpersistencec2loader
SHA-256: 5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed

xloader: 5a26fd46 — Three-tier batch→PowerShell→.NET dropper with AES/rail-fence payload and MSBuild proxy injection

Executive Summary

A 1.18 MB batch-script dropper delivering the XLoader infostealer family. The outer .bat decrypts an inner .bat via AES-CBC + rolling XOR; the inner .bat extracts a PowerShell block that decrypts a .NET Framework DLL (CryptoObfuscator-protected) and a 561 KB final payload via AES-256-CBC and a seeded rail-fence cipher. The .NET assembly reflectively injects the payload into MSBuild.exe under DigitalAudioForge.Processing audio-themed namespace masquerade. Persistence is via Task Scheduler (SystemTelemetrics / UserInterfaceProcessHost). Static-only — CAPE skipped batch files.

What It Is

  • Filename: LX_2026815111.bat ^[triage.json]
  • File type: DOS batch file, ASCII text, CRLF line terminators, 1,181,509 bytes ^[file.txt]
  • SHA-256: 5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed
  • Family: XLoader (high-confidence; author comment #XLOADER left in inner PowerShell) ^[inner.ps1:114]
  • Build date: Inner .NET DLL compiled Sat May 23 16:21:36 2026 (timestamp from PE header) ^[rabin2-info.txt]

How It Works

Tier 1 — Outer Batch Self-Launcher

The outer .bat checks if argument 1 equals the hardcoded token 297cfdb93967. If not, it spawns a hidden powershell.exe → cmd.exe chain that re-executes itself with the token. ^[strings.txt:1-5] This guarantees the payload runs inside a hidden console window regardless of how the victim launched it.

On :exec, it:

  1. Locates ---BEGIN_PS--- and ---BEGIN_ENC--- markers by line number using findstr.
  2. Tail-extracts the PowerScript block and Base64 blob via Get-Content -Tail.
  3. Decrypts the inner .bat with AES-CBC (hardcoded key/IV) then XORs the plaintext with a second 24-byte key. ^[strings.txt:26-51]
  4. Writes the result to %TEMP%\<random>.bat and executes it.
  5. Deletes temp files.

Tier 2 — Inner Batch + Persistence

The decrypted inner .bat (861 KB, 340 lines) is a self-contained persistence engine:

  • Relaunch: Same hidden powershell.exe → cmd.exe self-relaunch pattern with __hidden token. ^[payload.bat:6]
  • Persistence directory: %LOCALAPPDATA%\Local Studio (masquerades as a benign studio app). ^[payload.bat:18-19]
  • Persistence file: UserSessionManager.bat — a copy of the inner script itself. ^[payload.bat:22-23]
  • Task Scheduler: Creates a task named SystemTelemetrics (if elevated) or UserInterfaceProcessHost (if standard), triggered on logon and optionally on boot (elevated only). The task launches PowerShell to run the persistent .bat hidden. ^[payload.bat:27-35]
  • Self-delete guard: Skips deletion if the current path contains Local Studio, WindowsUpdate, MicrosoftEdge, OneDrive, Google, Adobe, \Temp\System, or ProgramData. ^[payload.bat:74]
  • Payload extraction: Finds ---BEGIN_PS--- at line 213 and extracts the remaining 128 lines into a volatile .ps1. ^[payload.bat:58]

Tier 3 — Inner PowerShell: Decryption + Reflective Injection

The volatile PowerShell script (~128 lines) contains two encrypted assets and an injection routine:

  • .NET DLL: Base64-encoded, AES-256-CBC encrypted (key 0x84,0x29,..., IV 0xEF,0x74,...). After decryption: a 73 KB PE32+ x64 Mono/.NET assembly. PDB path: C:\Users\UserPC\source\repos\jhPt\jhPt\bin\Debug\CryptoObfuscator_Output\jhPt.pdb. ^[rabin2-info.txt]
  • Final payload: Base64-encoded, 561 KB. Decrypted via AES-256-CBC, then unscrambled with a seeded rail-fence cipher using masterSeedPhrase = "ofD1*Vc9%Vzh6CMM#s*qG*Mz". ^[inner.ps1:8] The rail count and read-order permutation are both derived from the seed string's ASCII sum via System.Random, making the obfuscation deterministic but non-obvious without the seed.
  • Injection target: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe. ^[inner.ps1:112] The script explicitly comments: #XLOADER $targetProcess = [System.Diagnostics.Process]::GetCurrentProcess().MainModule.FileName. ^[inner.ps1:114]
  • Namespace masquerade: The loaded assembly exposes DigitalAudioForge.Processing namespace with benign-sounding classes (TrackQuery, AudioStreamOrchestrator, SystemPlaybackInitiator, AudioEffectProcessor). The payload bytes are passed as PcmData, and OrchestrateAudioSynthesis is invoked — all synonyms for process injection. ^[inner.ps1:106-127]
  • Window hiding: P/Invoke to FreeConsole() and ShowWindow via inline C# member definition. ^[inner.ps1:102-104]

Final Payload

The 561 KB decrypted payload (post rail-fence) has entropy 6.55 and begins with ZM (byte-swapped MZ). It contains an LZMA dictionary-size signature at offset 20356, suggesting a compressed or encrypted PE inner layer. Without dynamic execution the full API surface is not recoverable; the injection chain is sufficient evidence that this is the XLoader core.

Decompiled Behavior

Static-only (CAPE skipped batch files). The full behavioral chain is reconstructed from nested script decryption:

  1. cmd.exe → powershell.exe (hidden window, outer relaunch)
  2. powershell.exe decrypts outer .bat → writes temp .bat → cmd.exe (inner stage)
  3. Inner cmd.exe → powershell.exe (hidden, executes volatile .ps1)
  4. Volatile powershell.exe → decrypts .NET DLL + final payload → [System.Reflection.Assembly]::Load
  5. .NET assembly → Process.Start(MSBuild.exe) + OrchestrateAudioSynthesis (process hollowing/injection into trusted binary)

C2 Infrastructure

No hardcoded C2 URLs, IPs, or domains recovered from static extraction. XLoader historically uses HTTPS C2 with RC4-encrypted payloads and domain-fronting; this sample may resolve C2 at runtime from the final injected payload. The presence of LZMA-compressed data suggests a staged config or payload fetch.

Interesting Tidbits

  • Author fingerprint: The #XLOADER comment in the PowerShell source is an unambiguous family marker. ^[inner.ps1:114]
  • Builder environment: PDB path references UserPC and jhPt project name, compiled through CryptoObfuscator. The namespace DigitalAudioForge.Processing is likely auto-generated or manually chosen to evade string-based detection.
  • Filename pattern: LX_ prefix with numeric suffix (LX_2026815111.bat) resembles a delivery-campaign naming convention.
  • Self-delete sophistication: The guard string list (Local Studio, WindowsUpdate, MicrosoftEdge, etc.) is designed to prevent cleanup of the persistent copy while allowing the original dropper to erase itself.
  • No network downloader: Unlike many batch droppers that fetch stage-2 from a paste site, this sample is fully self-contained — all tiers are embedded in the single .bat. This makes single-file sandbox detonation more informative, though CAPE's batch-file skip prevented that.

How To Mess With It (Homelab Replication)

Reproducing this chain for educational purposes:

  1. Build a .NET DLL injector targeting MSBuild.exe using Process.Start with hidden window + Assembly.Load of a second payload.
  2. Obfuscate with CryptoObfuscator (trial available) to reproduce the CryptoObfuscator_Output PDB fingerprint.
  3. Encrypt the DLL with AES-256-CBC + Base64.
  4. Encrypt the payload with AES-256-CBC, then apply a seeded rail-fence cipher using a passphrase-derived System.Random permutation.
  5. Wrap in PowerShell with FreeConsole() P/Invoke and benign namespace (DigitalAudioForge.Processing).
  6. Embed in batch with ---BEGIN_PS--- / ---BEGIN_ENC--- markers and findstr extraction.
  7. Add persistence via schtasks.exe XML with LogonTrigger + optional BootTrigger.

Deployable Signatures

YARA Rule

rule XLoader_BatchDropper_2026 : xloader {
    meta:
        description = "XLoader three-tier batch dropper with AES/rail-fence payload"
        author = "PacketPursuit"
        date = "2026-08-24"
        sha256 = "5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed"
    strings:
        $a1 = "---BEGIN_PS---"
        $a2 = "---BEGIN_ENC---"
        $a3 = "297cfdb93967"
        $a4 = "Local Studio" nocase
        $a5 = "UserSessionManager.bat" nocase
        $a6 = "SystemTelemetrics" nocase
        $a7 = "UserInterfaceProcessHost" nocase
        $b1 = "DigitalAudioForge.Processing"
        $b2 = "TrackQuery"
        $b3 = "OrchestrateAudioSynthesis"
        $b4 = "PcmData"
        $c1 = "ofD1*Vc9%Vzh6CMM#s*qG*Mz"
        $c2 = "CryptoObfuscator_Output"
        $c3 = "#XLOADER"
    condition:
        (uint16(0) == 0x6540 or uint16(0) == 0x4065) and // '@e' or '@E' for @echo off
        filesize > 500KB and
        3 of ($a*) and
        2 of ($b*) and
        any of ($c*)
}

Behavioral Hunt Query (Sigma)

title: XLoader Batch Dropper Execution Chain
description: Detects the three-tier execution chain observed in XLoader sample 5a26fd46
logsource:
  category: process_creation
  product: windows
detection:
  selection_relaunch:
    CommandLine|contains:
      - 'powershell -WindowStyle Hidden -NonInteractive'
      - '297cfdb93967'
  selection_persistence:
    CommandLine|contains:
      - 'SystemTelemetrics'
      - 'UserInterfaceProcessHost'
      - 'Local Studio\UserSessionManager.bat'
  selection_injection:
    ParentImage|endswith: '\\powershell.exe'
    Image|endswith: '\\MSBuild.exe'
    CommandLine|contains: '__hidden'
  condition: selection_relaunch or selection_persistence or selection_injection
falsepositives:
  - Unknown
level: high

IOC List

Indicator Value Type
SHA-256 5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed Hash
Filename LX_2026815111.bat Filename
Mutex / Task Name SystemTelemetrics Scheduled Task
Mutex / Task Name UserInterfaceProcessHost Scheduled Task
Persistence Path %LOCALAPPDATA%\Local Studio\UserSessionManager.bat File Path
.NET Namespace DigitalAudioForge.Processing String
.NET Class TrackQuery String
.NET Method OrchestrateAudioSynthesis String
Decryption Seed ofD1*Vc9%Vzh6CMM#s*qG*Mz String
Injection Target C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe File Path
Builder PDB C:\Users\UserPC\source\repos\jhPt\jhPt\bin\Debug\CryptoObfuscator_Output\jhPt.pdb Build Artifact
AES Key (DLL) 842924A4AF2A7C68D047BAF786910DF02C928B90BDF8CBDF5E618AD621AB34D2 Key Material
AES IV (DLL) EF742128FD33F3C1EF16D92A17C193C1 Key Material

Behavioral Fingerprint

This threat actor delivers a single, large batch file (~1 MB) containing three embedded data zones. Upon execution, it relaunches itself via a hidden PowerShell/cmd.exe chain using a hardcoded token argument. It decrypts an inner batch script with AES-CBC and rolling XOR, which then stages persistence in %LOCALAPPDATA%\Local Studio and registers a logon-triggered scheduled task named SystemTelemetrics or UserInterfaceProcessHost. The inner script extracts a PowerShell block that decrypts a .NET assembly (CryptoObfuscator-obfuscated) and a 561 KB final payload using AES-256-CBC followed by a passphrase-derived rail-fence cipher. The .NET assembly loads reflectively, hides the console, and injects the final payload into MSBuild.exe under audio-themed class names (DigitalAudioForge.Processing.AudioStreamOrchestrator).

Detection Signatures (ATT&CK Mapping)

Technique ID Technique Name Evidence
T1059.001 PowerShell Outer and inner PowerShell execution with hidden window. ^[strings.txt:5] ^[payload.bat:7] ^[inner.ps1:1]
T1059.003 Windows Command Shell Batch file self-launch and extraction. ^[file.txt] ^[payload.bat:1]
T1027.002 Obfuscated Files or Information AES-CBC + Base64 + rolling XOR + rail-fence cipher + CryptoObfuscator. ^[strings.txt:26-51] ^[inner.ps1:4-8] ^[rabin2-info.txt]
T1055 Process Injection Reflective .NET assembly loads final payload and injects into MSBuild.exe. ^[inner.ps1:97,112,127]
T1127.001 Trusted Developer Utilities Proxy Execution Target process explicitly set to MSBuild.exe. ^[inner.ps1:112]
T1053.005 Scheduled Task/Job: Scheduled Task schtasks.exe XML task with LogonTrigger and optional BootTrigger. ^[payload.bat:35]
T1547.001 Boot or Logon Autostart Execution File copy to %LOCALAPPDATA%\Local Studio\UserSessionManager.bat. ^[payload.bat:22-23]
T1070.004 File Deletion Self-delete of temp scripts; guard against deleting persistent copy. ^[payload.bat:74]
T1564.003 Hide Artifacts: Hidden Window WindowStyle Hidden, FreeConsole(), ShowWindow. ^[strings.txt:5] ^[inner.ps1:102-104]
T1204.001 User Execution: Malicious Link/File Batch file social-engineering lure. ^[triage.json]

References

  • xloader — Family entity page
  • msbuild-proxy-execution — Procedure page for MSBuild abuse
  • rail-fence-cipher-payload-obfuscation — Technique page for seeded rail-fence payload encoding
  • audio-themed-namespace-masquerade — Technique page for benign-namespace process injection disguise
  • MalwareBazaar: LX_2026815111.bat (sha256: 5a26fd462a809c89b0448318591cb98a77a7b96fca658815dc0f547a51958bed)

Provenance

  • file.txt — file(1) output, file v5.44
  • triage.json — triage pipeline metadata
  • strings.txt — strings(1) output
  • rabin2-info.txt — radare2 rabin2 -I on decrypted .NET DLL
  • Inner PowerShell reconstructed from ---BEGIN_PS--- block in decrypted inner batch
  • Decryption performed manually with Python3 + OpenSSL AES-256-CBC + custom rail-fence reverse
  • Final payload entropy calculated with Shannon entropy (H ≈ 6.55)