typeentityfamilyunclassified-batch-powershell-dropperconfidencemediumcreated2026-06-03updated2026-08-13scriptdropperc2defense-evasionexecution

Unclassified Batch PowerShell Dropper Family

Windows batch-script droppers that assemble a PowerShell payload via SET/GOTO variable expansion, download or embed a second-stage .NET assembly, and execute it reflectively under a masquerade identity (e.g., MsBuild). The family has evolved through at least three obfuscation tiers:

  • Tier 1 (cae0056ac, eda47a53): Simple %var% expansion, paste-site downloaders (dpaste, pastefy, gitlab), MsBuild masquerade.
  • Tier 2 (ffd5d894): Natural-language phrase variable names decoded via batch expansion, no JScript polyglot layer.
  • Tier 3 (c96b83fa): Token-substitution cipher (#O→(, #R→$, etc.), ~5,500 fake GOTO smokescreen labels, conhost.exe --headless relaunch, REM-block Base64 payload extraction, language-mode gate, TLS 1.2 pinning, and HttpClient reflective assembly load.

Capabilities

  • batch-script-powershell-assembly-via-set-goto-expansion
  • inline-base64-obfuscation-f@-insertion-regex-cleanup
  • paste-site-failover-download-dpaste-pastefy-gitlab-ipfs
  • in-memory-dotnet-assembly-reflective-load
  • msbuild-proxy-masquerade-string-passthrough
  • regasm-proxy-masquerade-string-passthrough
  • reversed-string-url-anti-static
  • batch-smokescreen-label-obfuscation
  • powershell-token-substitution-loader
  • conhost-headless-window-suppression
  • rem-block-base64-payload-extraction
  • powershell-language-mode-gate
  • tls-12-pinned-download
  • phantomgate-reflective-loader-bootstrap
  • anydesk-version-info-masquerade

Build / RE

  • Language: DOS batch file (cmd.exe / cmd /c) with inline PowerShell
  • Obfuscation: Manual — no commercial packer. Three tiers of increasing sophistication (see above). Tier 3 adds caret escaping, arithmetic-driven string-slice alphabet, token-substitution cipher, and massive smokescreen.
  • Anti-analysis: No anti-VM or anti-debug; relies on being a trivial text file that sandboxes and AV may skip or underestimate. Tier 3 adds conhost --headless to suppress the console window.
  • Code quality: Low-to-medium — verbose repetitive batch patterns in Tier 1–2; Tier 3 shows deliberate engineering of the obfuscation pipeline.

Deploy / ATT&CK

Tactic Technique Evidence
Execution T1059.003 (Windows Command Shell) Batch script assembly and launch
Execution T1059.001 (PowerShell) Nested inline script, often -WindowStyle Hidden or conhost --headless
Command and Control T1105 (Ingress Tool Transfer) Paste-site download with failover (Tier 1–2); embedded REM-block payload (Tier 3)
Defense Evasion T1620 (Reflective Code Loading) [Reflection.Assembly]::Load without disk write
Defense Evasion T1127.001 (Trusted Developer Utilities Proxy Execution: MSBuild) Masquerade string MsBuild passed to invoked method (Tier 1–2)
Defense Evasion T1027.010 (Obfuscated Files or Information) Base64 assembly hidden between HTML-like delimiters in paste-site text (Tier 1–2); token-cipher + smokescreen (Tier 3)
Defense Evasion T1027.010 (Obfuscated Files or Information) Batch smokescreen labels and caret escaping (Tier 3)
Defense Evasion T1205 (Traffic Signaling) TLS 1.2 forced via SecurityProtocol (Tier 3)

Sibling Analyses

  • cae0056acc2f1b6285544c96e33a4e4c49b964f309b8e4df08b9bf55695389b8 — Tier 1 sibling: dpaste + pastefy → gitlab chain, myprogram.Homees.runss, Spanish-language URL indicators ^[/intel/analyses/cae0056acc2f1b6285544c96e33a4e4c49b964f309b8e4df08b9bf55695389b8.html]
  • eda47a53b9d17d5f8dd8866b245679d5a008916d366a1464677c63d109d7d6b0 — Tier 1 sibling: dual pastefy.app failover, reversed GitLab C2 sostsenrer2, MsBuild masquerade ^[/intel/analyses/eda47a53b9d17d5f8dd8866b245679d5a008916d366a1464677c63d109d7d6b0.html]
  • 2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2 — Tier 1 sibling: AnyDesk 9.6.11 version-info masquerade, PhantomGate reflective bootstrap, RegAsm masquerade string, IPFS + paste.sensio.no failover, reversed-string C2 103.83.86.24. Updated 2026-08-13. ^[/intel/analyses/2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2.html]
  • ffd5d894f5e350baace2342fc3c2c7de63a82138469db1694c35c732cf0c9df4 — Tier 2 sibling: natural-language phrase variable names, no polyglot layer ^[/intel/analyses/ffd5d894f5e350baace2342fc3c2c7de63a82138469db1694c35c732cf0c9df4.html]
  • c96b83fa0b190f3e09f92507e04b821b98eeed9f51a866a75c188ff08baa3b36 — Tier 3 sibling: token-cipher, 5,500 fake labels, conhost --headless, REM-block Base64, language-mode gate, TLS 1.2, HttpClient reflective load. Static-only. ^[/intel/analyses/c96b83fa0b190f3e09f92507e04b821b98eeed9f51a866a75c188ff08baa3b36.html]

Related

  • unclassified-js-dropper — Brazilian Portuguese WScript→PowerShell→.NET dropper with debugger/sandbox gate and HostGator C2. Similar chain but different obfuscation (JS string arrays vs batch SET/GOTO).
  • msbuild-proxy-execution — Procedure page for T1127.001 masquerade observed in Tier 1–2.
  • batch-smokescreen-label-obfuscation — Technique page for Tier 3 smokescreen.
  • powershell-token-substitution-loader — Technique page for Tier 3 inner-layer encoding.
  • unclassified-python-ngrok-rat — Python RAT distributed via batch stager + Python embeddable runtime download. Same low-skill commodity tier, different payload language (Python vs PowerShell/.NET).