Unclassified Danish Batch PowerShell Dropper Family
Windows batch-script droppers that embed an obfuscated PowerShell one-liner using a custom character-skip cipher (Beting) to decode strings at runtime. Linguistic fingerprint: predominantly Danish/Nordic variable names. Downloads a Base64-wrapped second stage from a hardcoded HTTPS URL and reflectively executes a payload extracted from a hardcoded offset within the downloaded blob.
Capabilities
- batch-script-powershell-stager
- character-skip-cipher-string-deobfuscation
- https-download-tls12-enforced
- base64-wrapped-blob-payload-extraction
- hardcoded-offset-payload-carving
- iex-reflective-execution
- service-termination-prior-to-staging
- user-agent-masquerade-fabricated-browser-version
Build / RE
- Language: DOS batch file (
cmd.exe) wrapping inline PowerShell - Obfuscation: Custom
Betingcipher — real characters sit at every 4th position starting from index 3 inside noise-padded string literals. Trivially reversible with a regex stride extractor. Dead-code assignments ($mari=Compare-Object stormest beau) pad the decoder loop to slow naive regex approaches. ^[/intel/analyses/402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177.html] - Evolution (sibling
afc82dc9): The character-skip offset escalates to 58 (from 3 in prior siblings), and the obfuscation gains two additional layers: aGries156Base64+XOR decoder (keyGarversv) and apudgper-element XOR loop over a byte array. TheIEXexecutor is assembled character-by-character from three separate 59-charspittlesshliterals. ^[/intel/analyses/afc82dc9be3d3bcf759c0270f16ae517b20e612a88abcab4da18479b9b216991.html] - Anti-analysis: No VM/debug detection; relies on being a plain text file that sandboxes may skip. The noise-padding defeats naive string-matching but not structural analysis. ^[/intel/analyses/402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177.html]
- Code quality: Low — hardcoded offsets, hardcoded URL, single C2 with no failover, fabricated User-Agent string with a non-existent Firefox version number. Suggests commodity-tier tooling. ^[/intel/analyses/402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177.html]
- Linguistic fingerprint: Variable names are Danish or Nordic (
driftssik,udglatte,smsyninger,thalassom187,tolerer,totalo,duktili). This is a strong attribution clue and distinguishes the family from Spanish/Portuguese or English-named alternatives. ^[/intel/analyses/402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177.html]
Deploy / ATT&CK
| Tactic | Technique | Evidence |
|---|---|---|
| Execution | T1059.003 (Windows Command Shell) | Batch script launches PowerShell |
| Execution | T1059.001 (PowerShell) | Inline -windowstyle hidden with IEX |
| Command and Control | T1105 (Ingress Tool Transfer) | Net.WebClient.DownloadFile over HTTPS |
| Defense Evasion | T1620 (Reflective Code Loading) | IEX executes payload without disk write |
| Defense Evasion | T1027 (Obfuscated Files or Information) | Beting character-skip cipher |
| Impact | T1070.004 (File Deletion) | spsv ichoglanop — stops prior service |
Capabilities
- batch-script-powershell-stager
- character-skip-cipher-string-deobfuscation
- base64-xor-encrypted-command-fragments
- google-drive-c2-staging
- tls12-enforced-download
- base64-wrapped-blob-payload-extraction
- hardcoded-offset-payload-carving
- iex-reflective-execution
- user-agent-masquerade-fabricated-browser-version
- multi-layer-cipher-pipeline (character-skip + base64-xor + per-element-xor)
- italian-social-engineering-lure
Sibling Analyses
402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177— First observed sibling:123.bat, Italian C2libreriaduepuntozero.it, Firefox 143.0 masquerade, Danish variable names, payload offset 428386 / length 22190. ^[/intel/analyses/402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177.html] |-93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0— Second confirmed sibling:PO# ATVHCWS26-387 HANSUNG VINA..bat, Google Drive C2 (14Led1yEUXipMpwH6VgGsTwaS0lN2tUNv), Firefox 150.0 masquerade, Base64+XORMonokromeencrypted fragments (keyBana), payload offset 138643 / length 15571. Adds per-fragment encryption and switches C2 from Italian HTTPS to Google Drive. ^[/intel/analyses/93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0.html] |-afc82dc9be3d3bcf759c0270f16ae517b20e612a88abcab4da18479b9b216991— Third confirmed sibling:Urgente Richiesta d'offerta B473_IREM_PDF.bat, Google Drive C2 (11h6D737JvfdjcP1KAari2XPs6C8M0LFM), Firefox 150.0 masquerade, three-layer decoder (spittlesshstride-4 offset-58 →Gries156Base64+XOR with keyGarversv→pudgper-element XOR loop), payload offset 125853 / length 14870 bytes. Italian purchase-order lure. Reuses same Google Drive C2 as sibling93aec3da. ^[/intel/analyses/afc82dc9be3d3bcf759c0270f16ae517b20e612a88abcab4da18479b9b216991.html]
Related
- unclassified-batch-powershell-dropper — Different family: Spanish/Portuguese batch→PowerShell dropper using SET/GOTO variable expansion and paste-site failover. Same staging concept, different obfuscation scheme.
- batch-powershell-variable-expansion-obfuscation — Technique page for the SET/GOTO family.
- character-skip-cipher-powershell-obfuscation — Technique page for the
Betingcipher observed in this family. - powershell-cradle-downloader — Generic PowerShell download cradle pattern.