Unclassified Batch PowerShell Dropper Family
Windows batch-script droppers that assemble a PowerShell payload via SET/GOTO variable expansion, download or embed a second-stage .NET assembly, and execute it reflectively under a masquerade identity (e.g., MsBuild). The family has evolved through at least three obfuscation tiers:
- Tier 1 (
cae0056ac,eda47a53): Simple%var%expansion, paste-site downloaders (dpaste,pastefy,gitlab),MsBuildmasquerade. - Tier 2 (
ffd5d894): Natural-language phrase variable names decoded via batch expansion, no JScript polyglot layer. - Tier 3 (
c96b83fa): Token-substitution cipher (#O→(,#R→$, etc.), ~5,500 fakeGOTOsmokescreen labels,conhost.exe --headlessrelaunch,REM-block Base64 payload extraction, language-mode gate, TLS 1.2 pinning, andHttpClientreflective assembly load.
Capabilities
- batch-script-powershell-assembly-via-set-goto-expansion
- inline-base64-obfuscation-f@-insertion-regex-cleanup
- paste-site-failover-download-dpaste-pastefy-gitlab-ipfs
- in-memory-dotnet-assembly-reflective-load
- msbuild-proxy-masquerade-string-passthrough
- regasm-proxy-masquerade-string-passthrough
- reversed-string-url-anti-static
- batch-smokescreen-label-obfuscation
- powershell-token-substitution-loader
- conhost-headless-window-suppression
- rem-block-base64-payload-extraction
- powershell-language-mode-gate
- tls-12-pinned-download
- phantomgate-reflective-loader-bootstrap
- anydesk-version-info-masquerade
Build / RE
- Language: DOS batch file (
cmd.exe/cmd /c) with inline PowerShell - Obfuscation: Manual — no commercial packer. Three tiers of increasing sophistication (see above). Tier 3 adds caret escaping, arithmetic-driven string-slice alphabet, token-substitution cipher, and massive smokescreen.
- Anti-analysis: No anti-VM or anti-debug; relies on being a trivial text file that sandboxes and AV may skip or underestimate. Tier 3 adds
conhost --headlessto suppress the console window. - Code quality: Low-to-medium — verbose repetitive batch patterns in Tier 1–2; Tier 3 shows deliberate engineering of the obfuscation pipeline.
Deploy / ATT&CK
| Tactic | Technique | Evidence |
|---|---|---|
| Execution | T1059.003 (Windows Command Shell) | Batch script assembly and launch |
| Execution | T1059.001 (PowerShell) | Nested inline script, often -WindowStyle Hidden or conhost --headless |
| Command and Control | T1105 (Ingress Tool Transfer) | Paste-site download with failover (Tier 1–2); embedded REM-block payload (Tier 3) |
| Defense Evasion | T1620 (Reflective Code Loading) | [Reflection.Assembly]::Load without disk write |
| Defense Evasion | T1127.001 (Trusted Developer Utilities Proxy Execution: MSBuild) | Masquerade string MsBuild passed to invoked method (Tier 1–2) |
| Defense Evasion | T1027.010 (Obfuscated Files or Information) | Base64 assembly hidden between HTML-like delimiters in paste-site text (Tier 1–2); token-cipher + smokescreen (Tier 3) |
| Defense Evasion | T1027.010 (Obfuscated Files or Information) | Batch smokescreen labels and caret escaping (Tier 3) |
| Defense Evasion | T1205 (Traffic Signaling) | TLS 1.2 forced via SecurityProtocol (Tier 3) |
Sibling Analyses
cae0056acc2f1b6285544c96e33a4e4c49b964f309b8e4df08b9bf55695389b8— Tier 1 sibling:dpaste+pastefy→gitlabchain,myprogram.Homees.runss, Spanish-language URL indicators ^[/intel/analyses/cae0056acc2f1b6285544c96e33a4e4c49b964f309b8e4df08b9bf55695389b8.html]eda47a53b9d17d5f8dd8866b245679d5a008916d366a1464677c63d109d7d6b0— Tier 1 sibling: dualpastefy.appfailover, reversed GitLab C2sostsenrer2,MsBuildmasquerade ^[/intel/analyses/eda47a53b9d17d5f8dd8866b245679d5a008916d366a1464677c63d109d7d6b0.html]2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2— Tier 1 sibling: AnyDesk 9.6.11 version-info masquerade,PhantomGatereflective bootstrap,RegAsmmasquerade string, IPFS +paste.sensio.nofailover, reversed-string C2103.83.86.24. Updated 2026-08-13. ^[/intel/analyses/2232eb680881fa7bc2e9402cfedbbf416ff065426cb5309bb0c9ce8224632cd2.html]ffd5d894f5e350baace2342fc3c2c7de63a82138469db1694c35c732cf0c9df4— Tier 2 sibling: natural-language phrase variable names, no polyglot layer ^[/intel/analyses/ffd5d894f5e350baace2342fc3c2c7de63a82138469db1694c35c732cf0c9df4.html]c96b83fa0b190f3e09f92507e04b821b98eeed9f51a866a75c188ff08baa3b36— Tier 3 sibling: token-cipher, 5,500 fake labels,conhost --headless,REM-block Base64, language-mode gate, TLS 1.2,HttpClientreflective load. Static-only. ^[/intel/analyses/c96b83fa0b190f3e09f92507e04b821b98eeed9f51a866a75c188ff08baa3b36.html]
Related
- unclassified-js-dropper — Brazilian Portuguese WScript→PowerShell→.NET dropper with debugger/sandbox gate and HostGator C2. Similar chain but different obfuscation (JS string arrays vs batch SET/GOTO).
- msbuild-proxy-execution — Procedure page for T1127.001 masquerade observed in Tier 1–2.
- batch-smokescreen-label-obfuscation — Technique page for Tier 3 smokescreen.
- powershell-token-substitution-loader — Technique page for Tier 3 inner-layer encoding.
- unclassified-python-ngrok-rat — Python RAT distributed via batch stager + Python embeddable runtime download. Same low-skill commodity tier, different payload language (Python vs PowerShell/.NET).