Unclassified Rouki-OBFUSCATOR Batch Dropper Family
Windows batch-script droppers obfuscated by the open-source Rouki-OBFUSCATOR tool (author EscaLag, GitHub github.com/rouki). Distinguished from the broader unclassified-batch-powershell-dropper cluster by its heavy use of kaomoji emoticons, CJK ideographs, and Arabic script fragments as undefined-variable noise padding, combined with %PUBLIC:~n,1%-driven command construction and Chinese-character-named substitution-alphabet string slicing.
Capabilities
- batch-kaomoji-cjk-arabic-noise-padding
- public-env-var-slice-command-assembly
- chinese-character-named-substitution-alphabet
- caret-escape-keyword-splitting
- base64-blob-echo-staging
- powershell-webclient-downloadfile
- startup-folder-persistence
- tls-12-pinned-download
- social-engineering-filename-lure
Build / RE
- Language: DOS batch file with inline PowerShell cradle
- Obfuscation engine: Rouki-OBFUSCATOR (open-source); five tiers visible in sample
448682ebd8: caret escapes,%public%slice command assembly, kaomoji/CJK/Arabic undefined-variable noise, Chinese-named 65-char substitution alphabets, base64 echo staging - Anti-analysis: No anti-VM or anti-debug; relies on massive noise injection (5.8 MB text) and non-binary format to evade sandbox detonation
- Code quality: Low — commodity obfuscator output with deterministic watermark (
:Rouki-OBFUSCATOR,__author__=EscaLag)
Deploy / ATT&CK
| Tactic | Technique | Evidence |
|---|---|---|
| Execution | T1059.003 (Windows Command Shell) | Batch script assembly and launch |
| Execution | T1059.001 (PowerShell) | powershell.exe -WindowStyle Hidden inline cradle |
| Command and Control | T1105 (Ingress Tool Transfer) | System.Net.WebClient.DownloadFile to GitHub raw URL |
| Defense Evasion | T1027.010 (Obfuscated Files or Information) | Kaomoji/CJK/Arabic noise padding, caret escaping, %var:~n,1% slice encoding |
| Defense Evasion | T1027 (Obfuscated Files or Information) | 289 KB base64 blob written via @echo |
| Persistence | T1547.001 (Boot or Logon Autostart Execution: Startup Folder) | %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\WindowSecuryti.bat |
| Defense Evasion | T1205 (Traffic Signaling) | TLS 1.2 forced via SecurityProtocol |
Sibling Analyses
448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193(Dental records + x-rays.bat, 5.8 MB) — First confirmed sibling in corpus. Full kaomoji/CJK/Arabic noise, five Chinese-named substitution alphabets, GitHub C2https://github.com/urerfie/base/raw/main/zdd.bat, Startup persistence asWindowSecuryti.bat. Static-only. ^[/intel/analyses/448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193.html]
Related
- unclassified-batch-powershell-dropper — Broader batch→PowerShell dropper family with different obfuscation tiers (natural-language SET names, token-substitution cipher, GOTO smokescreen)
- batch-kaomoji-cjk-noise-obfuscation — Technique page for the noise-injection pattern
- batch-powershell-variable-expansion-obfuscation — Related batch obfuscation technique