[ << ALL_FEED ]

Say a word about the obfuscated batch file...

More in General

A word about the obfuscated batch file…

We’re publishing this post as a follow-up to the recent one about the EXE hidden under a hex dump in a Base64 request for certificate creation: naturally, it won’t run on its own in such a scheme. Initially, the CSR file was merely part of a batch script packed into a RAR archive named Serkan_Yalgi.Tar.

📂 It could only be opened using WinRAR and UnRAR on Linux; Windows’ default extractor and 7-Zip get lost at the sight of this archive, as shown in the first screenshot (the UX of this sample is at a very low level).

Inside the archive is a batch file Serkan_Yalgi.cmd; the second screenshot shows a fragment of its contents. And there are about 400 lines of this mess, with the remaining 115,000 lines taken up by the EXE in Base64 mentioned in the previous post.

For a novice Windows administrator, these gibberish characters may be incomprehensible, but in reality it’s a valid batch file, just slightly obfuscated. The main operation in this script is extracting a substring from the source string, then concatenating and interpreting the result (you can read more about string operations in batch files here).

Armed with this knowledge, one could grab Python and start analyzing the script, but we took a trickier approach and used this tool.

Let’s apply the deobfuscator to the file:


python batch_interpreter.py –file Serkan_Yalgi.cmd

After cleaning up the output, we get the original script shown in the third screenshot (C:\Users\Public replaced with %PUBLIC% for brevity). The funniest part is that the BatCloak obfuscator didn’t ask the malware author and left advertising in his script (that’s what you get for using open source!).

As you can see, the script copies cmd.exe to the file alpha.exe using the extrac32 utility (to evade security tools), does the same with certutil -> kn, and then unpacks the Base64 and hex dump using the new certutil and launches the resulting EXE. This same behavior can be observed by running the file in a sandbox, for example in PT Sandbox (screenshot 4).

But behavior is a separate topic. How do we detect an obfuscated batch file? The idea for the following YARA rule was born:


strings:
  $subs = /:~\ *(-|\+)?\d{1,2},\ *(-|\+)?\d{1,3}%/
condition:
  #subs > 100

How’s that for information — does it motivate you to switch to Linux? 🧐

#Detect #Yara
@ptescalator

More from global_author

More from global_author

More in General