Jan. 26, 2024, 8:15 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Windows batch files (.bat) are often seen by people as very simple but they can be pretty complex or… contain interesting encoded payloads! I found one that contains multiple payloads decoded and used by a Powershell process. The magic is behind how comments can be added to such files. The default (or very common way) is to use the “REM” keyword. But you can also use a double-colon:


Article Link: https://isc.sans.edu/diary/rss/30592


1 post - 1 participant


Read full topic

bat batch can comments default file files found magic people powershell process simple windows

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC