Batch Kaomoji-CJK-Noise Obfuscation
A DOS batch-script anti-static technique in which the real payload is hidden among massive quantities of undefined-variable expansions containing kaomoji emoticons, CJK ideographs, and Arabic script fragments. These variables are never defined, so they expand to empty strings at runtime, but they bloat the file size to multiple megabytes and poison string-based extraction.
Pipeline
Stage 1 — Undefined-variable noise injection
The attacker wraps every token of the real batch payload inside %var% blocks where var contains:
- Kaomoji (Japanese emoticon):
ヾ(⌐■_■)ノ,┌(ಠ_ಠ)┘,◕‿◕,⊙ω⊙ - Arabic script:
ﺹﺼﮕﺼ,ﭲﭲ,◯ﺖك - CJK ideographs:
製秘魔文的訊,無神法無已,的字這製護字
Because these variables are never assigned, Windows cmd.exe expands them to empty strings. The visible file is therefore a 5+ MB wall of noise with the actual commands invisible without emulation. ^[/intel/analyses/448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193.html]
Stage 2 — %public:~n,1% command assembly
Even the literal command set is not written directly. Instead, each character is extracted from the %PUBLIC% environment variable (defaults to C:\Users\Public) via substring slicing: s = %public:~0,1%, e = %public:~5,1%, t = %public:~4,1%. This forces static analysis to know the default Windows environment to even recognize that a set command is being constructed. ^[/intel/analyses/448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193.html]
Stage 3 — Chinese-named substitution-alphabet encoding
After the noise, the actual payload is encoded as ~290,000 %varname:~n,1% slice tokens referencing five variables with Chinese-character names (爱豆尔斯, 耻色耻维, 色斯阿斯, 贝贝维爱, 饿贝豆尔). Each variable holds a 65-character permutation of printable ASCII, including @, =, and space. The payload characters are spelled out by indexing into these alphabets. ^[/intel/analyses/448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193.html]
Stage 4 — Base64 echo + PowerShell cradle
The decoded payload writes a 289 KB base64 blob via @echo, then appends a start /min powershell.exe -WindowStyle Hidden command that downloads a second-stage .bat and persists it to the Startup folder. ^[/intel/analyses/448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193.html]
Detection / Triage
- File size: Batch scripts >1 MB are suspicious; >5 MB with text content is a strong signal.
- Line count: Very few lines (25) despite 5+ MB file size — suggests very long lines carrying noise.
- Kaomoji density: Any
.batcontainingヾ(⌐■_■)ノor┌(ಠ_ಠ)┘is abnormal. - CJK/Arabic in batch: Legitimate Windows batch files almost never contain CJK ideographs or Arabic script.
- Emulation requirement: Static string extraction is defeated; behavioral analysis or a Windows batch emulator is required.
Reproduce on Your Own VMs
- Create five variables with 65-character ASCII permutations (include
@,=, space). - Encode a payload as
%varname:~index,1%tokens referencing those variables. - Wrap every token in undefined
%kaomoji%,%cjk%, and%arabic%blocks. - Use
%public:~n,1%to spell out the initialsetcommands. - Append
^inside keywords (ec^ho,cl^s) to break naive regex. - Verify: running the batch in a Windows VM should produce the intended payload while string-extraction tools see only noise.
Defensive Countermeasures
- EDR: Flag
cmd.exeprocesses spawned from.batfiles >1 MB that contain non-ASCII characters in the command line. - YARA: See the rule in unclassified-rouki-obfuscator-batch-dropper analysis.
- Behavioral: Flag
powershell.exe -WindowStyle HiddenwithDownloadFileto GitHub raw URLs when the parent iscmd.exeand the grandparent is a.batfile.
Pages Where Observed
- unclassified-rouki-obfuscator-batch-dropper — entity page for this family
448682ebd8— full analysis ^[/intel/analyses/448682ebd829c6c05dda879d4609106d8c115b80ac1df15e0f4d28dd7176c193.html]
References
- Rouki-OBFUSCATOR tool:
github.com/rouki(watermark observed in sample)