Batch Smokescreen Label Obfuscation
A DOS batch-script anti-static technique in which the real payload is preceded by thousands of fake GOTO labels, each followed by blocks of apparently legitimate Windows system-administration commands (registry queries, scheduled-task enumeration, event-log inspection, service checks, firewall queries). The labels are never reached by the actual control flow; they exist solely to overwhelm human reviewers, defeat naive string-extraction tools, and inflate file size to 4+ MB so that sandboxes and AV engines may skip or underestimate the sample.
Pipeline
Stage 1 — Label generation
The script defines thousands of labels with a fixed prefix and random suffix, e.g.:
:_wp7nx3
reg query "HKLM\SOFTWARE\Microsoft\PowerShell\3\PowerShellEngine" /v PowerShellVersion 2>nul | findstr REG_SZ
schtasks /query /tn "%_wp7nx3_task%" 2>nul | findstr /i "Ready Running Disabled"
wevtutil qe %_wpk3es_evtsrc% /c:16 /q:"*[System[Level<=2]]" /f:text 2>nul | findstr /c:"Event ID"
sc query WinDefend 2>nul | findstr "STATE"
netsh advfirewall show %_wpcu93_fwprofile% state 2>nul | findstr /i "State"
Each label block is 15–20 lines. With ~5,500 labels the file exceeds 4 MB. ^[/intel/analyses/c96b83fa0b190f3e09f92507e04b821b98eeed9f51a866a75c188ff08baa3b36.html]
Stage 2 — Control-flow isolation
The real payload lives in the first ~100 lines. A single GOTO at the top jumps over the smokescreen to the payload block. The smokescreen labels are referenced only by the preceding GOTO and are never executed. ^[/intel/analyses/c96b83fa0b190f3e09f92507e04b821b98eeed9f51a866a75c188ff08baa3b36.html]
Stage 3 — Inner payload
After the smokescreen, the script uses SET /A arithmetic and string-slice obfuscation to assemble a PowerShell .NET assembly loader that reads the batch file itself, extracts Base64 from REM lines, and reflectively loads the inner assembly. ^[/intel/analyses/c96b83fa0b190f3e09f92507e04b821b98eeed9f51a866a75c188ff08baa3b36.html]
Detection / Triage
- File size: Batch scripts >1 MB are immediately suspicious. Legitimate batch files are rarely >100 KB.
- Line count:
wc -lreturning tens of thousands suggests smokescreen. - Label density:
grep -c "^:"returning thousands whilegrep -c "goto "returning one is a strong signal. - String entropy: The smokescreen uses real Windows command strings, so naive string matching may miss the payload. Look for
REMblocks with high+//Base64-like character density. - Execution path: Trace the first
GOTOfrom@echo off— everything before the target label is payload; everything after is noise.
Related
- batch-powershell-variable-expansion-obfuscation — Simpler batch obfuscation using
%var%expansion. - unclassified-batch-powershell-dropper — Family that uses this technique.
- powershell-token-substitution-loader — Inner-layer encoding paired with this smokescreen.