Casting Light on BATLOADER: An Insight into its Role in Malware Delivery
ID: ed103de3-3441-5ded-ba17-01e854259f1d
STIX ID: report--ed103de3-3441-5ded-ba17-01e854259f1d
Feed Name: Seqrite Blog
Threat Score
This report details a batloader multi-stage infection chain used to deliver AgentTesla and other malware: an obfuscated .bat copies PowerShell, extracts a Base64 string, GZIP-decompresses and reverses it to reveal a .NET payload which is injected into a process; the document includes technical analysis, file/hex screenshots, example deobfuscation steps, IOCs (hashes), and vendor detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
