typeentityfamilyunclassified-danish-batch-ps-dropperconfidencemediumcreated2026-06-14updated2026-08-13scriptdropperc2defense-evasionexecutionobfuscation

Unclassified Danish Batch PowerShell Dropper Family

Windows batch-script droppers that embed an obfuscated PowerShell one-liner using a custom character-skip cipher (Beting) to decode strings at runtime. Linguistic fingerprint: predominantly Danish/Nordic variable names. Downloads a Base64-wrapped second stage from a hardcoded HTTPS URL and reflectively executes a payload extracted from a hardcoded offset within the downloaded blob.

Capabilities

  • batch-script-powershell-stager
  • character-skip-cipher-string-deobfuscation
  • https-download-tls12-enforced
  • base64-wrapped-blob-payload-extraction
  • hardcoded-offset-payload-carving
  • iex-reflective-execution
  • service-termination-prior-to-staging
  • user-agent-masquerade-fabricated-browser-version

Build / RE

  • Language: DOS batch file (cmd.exe) wrapping inline PowerShell
  • Obfuscation: Custom Beting cipher — real characters sit at every 4th position starting from index 3 inside noise-padded string literals. Trivially reversible with a regex stride extractor. Dead-code assignments ($mari=Compare-Object stormest beau) pad the decoder loop to slow naive regex approaches. ^[/intel/analyses/402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177.html]
  • Evolution (sibling afc82dc9): The character-skip offset escalates to 58 (from 3 in prior siblings), and the obfuscation gains two additional layers: a Gries156 Base64+XOR decoder (key Garversv) and a pudg per-element XOR loop over a byte array. The IEX executor is assembled character-by-character from three separate 59-char spittlessh literals. ^[/intel/analyses/afc82dc9be3d3bcf759c0270f16ae517b20e612a88abcab4da18479b9b216991.html]
  • Anti-analysis: No VM/debug detection; relies on being a plain text file that sandboxes may skip. The noise-padding defeats naive string-matching but not structural analysis. ^[/intel/analyses/402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177.html]
  • Code quality: Low — hardcoded offsets, hardcoded URL, single C2 with no failover, fabricated User-Agent string with a non-existent Firefox version number. Suggests commodity-tier tooling. ^[/intel/analyses/402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177.html]
  • Linguistic fingerprint: Variable names are Danish or Nordic (driftssik, udglatte, smsyninger, thalassom187, tolerer, totalo, duktili). This is a strong attribution clue and distinguishes the family from Spanish/Portuguese or English-named alternatives. ^[/intel/analyses/402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177.html]

Deploy / ATT&CK

Tactic Technique Evidence
Execution T1059.003 (Windows Command Shell) Batch script launches PowerShell
Execution T1059.001 (PowerShell) Inline -windowstyle hidden with IEX
Command and Control T1105 (Ingress Tool Transfer) Net.WebClient.DownloadFile over HTTPS
Defense Evasion T1620 (Reflective Code Loading) IEX executes payload without disk write
Defense Evasion T1027 (Obfuscated Files or Information) Beting character-skip cipher
Impact T1070.004 (File Deletion) spsv ichoglanop — stops prior service

Capabilities

  • batch-script-powershell-stager
  • character-skip-cipher-string-deobfuscation
  • base64-xor-encrypted-command-fragments
  • google-drive-c2-staging
  • tls12-enforced-download
  • base64-wrapped-blob-payload-extraction
  • hardcoded-offset-payload-carving
  • iex-reflective-execution
  • user-agent-masquerade-fabricated-browser-version
  • multi-layer-cipher-pipeline (character-skip + base64-xor + per-element-xor)
  • italian-social-engineering-lure

Sibling Analyses

  • 402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177 — First observed sibling: 123.bat, Italian C2 libreriaduepuntozero.it, Firefox 143.0 masquerade, Danish variable names, payload offset 428386 / length 22190. ^[/intel/analyses/402879ff4b368a1dc489d8572137305c84b1983d9539d374f45f815bfa7c1177.html] |- 93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0 — Second confirmed sibling: PO# ATVHCWS26-387 HANSUNG VINA..bat, Google Drive C2 (14Led1yEUXipMpwH6VgGsTwaS0lN2tUNv), Firefox 150.0 masquerade, Base64+XOR Monokrome encrypted fragments (key Bana), payload offset 138643 / length 15571. Adds per-fragment encryption and switches C2 from Italian HTTPS to Google Drive. ^[/intel/analyses/93aec3da641e8a2d7191e5ec96e1678984c2441f129d6e91ad5741c896e1dfb0.html] |- afc82dc9be3d3bcf759c0270f16ae517b20e612a88abcab4da18479b9b216991 — Third confirmed sibling: Urgente Richiesta d'offerta B473_IREM_PDF.bat, Google Drive C2 (11h6D737JvfdjcP1KAari2XPs6C8M0LFM), Firefox 150.0 masquerade, three-layer decoder (spittlessh stride-4 offset-58 → Gries156 Base64+XOR with key Garversv → pudg per-element XOR loop), payload offset 125853 / length 14870 bytes. Italian purchase-order lure. Reuses same Google Drive C2 as sibling 93aec3da. ^[/intel/analyses/afc82dc9be3d3bcf759c0270f16ae517b20e612a88abcab4da18479b9b216991.html]

Related