Jan. 26, 2024, 8:15 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Windows batch files (.bat) are often seen by people as very simple but they can be pretty complex or… contain interesting encoded payloads! I found one that contains multiple payloads decoded and used by a Powershell process. The magic is behind how comments can be added to such files. The default (or very common way) is to use the “REM” keyword. But you can also use a double-colon:


Article Link: https://isc.sans.edu/diary/rss/30592


1 post - 1 participant


Read full topic

bat batch can comments default file files found magic people powershell process simple windows

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Senior Security Architect - Northwest region (Remote)

@ GuidePoint Security LLC | Remote

Senior Consultant, Cyber Security Architecture

@ 6point6 | Manchester, United Kingdom

Junior Security Architect

@ IQ-EQ | Port Louis, Mauritius

Senior Detection & Response Engineer

@ Expel | Remote

Cyber Security Systems Engineer ISSE Splunk

@ SAP | Southbank (Melbourne), VIC, AU, 3006