typetechniqueconfidencehighcreated2026-08-04updated2026-08-04batchobfuscationanti-staticsmokescreengoto

Batch Smokescreen Label Obfuscation

A DOS batch-script anti-static technique in which the real payload is preceded by thousands of fake GOTO labels, each followed by blocks of apparently legitimate Windows system-administration commands (registry queries, scheduled-task enumeration, event-log inspection, service checks, firewall queries). The labels are never reached by the actual control flow; they exist solely to overwhelm human reviewers, defeat naive string-extraction tools, and inflate file size to 4+ MB so that sandboxes and AV engines may skip or underestimate the sample.

Pipeline

Stage 1 — Label generation

The script defines thousands of labels with a fixed prefix and random suffix, e.g.:

:_wp7nx3
reg query "HKLM\SOFTWARE\Microsoft\PowerShell\3\PowerShellEngine" /v PowerShellVersion 2>nul | findstr REG_SZ
schtasks /query /tn "%_wp7nx3_task%" 2>nul | findstr /i "Ready Running Disabled"
wevtutil qe %_wpk3es_evtsrc% /c:16 /q:"*[System[Level<=2]]" /f:text 2>nul | findstr /c:"Event ID"
sc query WinDefend 2>nul | findstr "STATE"
netsh advfirewall show %_wpcu93_fwprofile% state 2>nul | findstr /i "State"

Each label block is 15–20 lines. With ~5,500 labels the file exceeds 4 MB. ^[/intel/analyses/c96b83fa0b190f3e09f92507e04b821b98eeed9f51a866a75c188ff08baa3b36.html]

Stage 2 — Control-flow isolation

The real payload lives in the first ~100 lines. A single GOTO at the top jumps over the smokescreen to the payload block. The smokescreen labels are referenced only by the preceding GOTO and are never executed. ^[/intel/analyses/c96b83fa0b190f3e09f92507e04b821b98eeed9f51a866a75c188ff08baa3b36.html]

Stage 3 — Inner payload

After the smokescreen, the script uses SET /A arithmetic and string-slice obfuscation to assemble a PowerShell .NET assembly loader that reads the batch file itself, extracts Base64 from REM lines, and reflectively loads the inner assembly. ^[/intel/analyses/c96b83fa0b190f3e09f92507e04b821b98eeed9f51a866a75c188ff08baa3b36.html]

Detection / Triage

  • File size: Batch scripts >1 MB are immediately suspicious. Legitimate batch files are rarely >100 KB.
  • Line count: wc -l returning tens of thousands suggests smokescreen.
  • Label density: grep -c "^:" returning thousands while grep -c "goto " returning one is a strong signal.
  • String entropy: The smokescreen uses real Windows command strings, so naive string matching may miss the payload. Look for REM blocks with high +// Base64-like character density.
  • Execution path: Trace the first GOTO from @echo off — everything before the target label is payload; everything after is noise.

Related