This page looks best with JavaScript enabled

Best Way To Obfuscate a Batch File

 ·  β˜• 1 min read  ·  🐱 thik

αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž“αŸαŸ‡αž‡αžΆαž€αžΌαžŠαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž’αŸ’αžœαžΎαž€αžΆαžš Obfuscate αž‘αŸ…αž›αžΎ Batch Script αžŠαŸ„αž™αž’αŸ’αžœαžΎαž€αžΆαžšαž”αŸ†αž”αŸ’αž›αŸ‚αž„αž€αžΌαžŠαž‘αžΆαŸ†αž„αž“αŸ„αŸ‡αž‘αŸ…αž‡αžΆαž—αžΆαžŸαžΆαžšαž•αŸ’αžŸαŸαž„αž˜αž½αž™αž‘αŸ€αžαžŠαŸ‚αž›αž–αž·αž”αžΆαž€αž™αž›αŸ‹ αŸ”

αž’αžšαž‚αž»αžŽαž…αŸ†αž–αŸ„αŸ‡ aGerman αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αžΌαžŠαž˜αž½αž™αž“αŸαŸ‡ αŸ”

PWN the Script

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
@echo off
if "%~1"=="" exit /b
if /i "%~x1" neq ".bat" if /i "%~x1" neq ".cmd" exit /b
for /f %%i in ("certutil.exe") do if not exist "%%~$path:i" (
  echo CertUtil.exe not found.
  pause
  exit /b
)
>"temp.~b64" echo(//4mY2xzDQo=
certutil.exe -f -decode "temp.~b64" "%~n1___%~x1"
del "temp.~b64"
copy "%~n1___%~x1" /b + "%~1" /b

Usage

αž…αž˜αŸ’αž›αž„αž€αžΌαžŠαžαžΆαž„αž›αžΎαž αžΎαž™αžšαž€αŸ’αžŸαžΆαž‘αž»αž€αžœαžΆαž‡αžΆ anyname.bat αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž˜αž€αž’αŸ’αžœαžΎαž€αžΆαžšαž‘αŸ†αž›αžΆαž€αŸ‹αž―αž€αžŸαžΆαžš Batch αžšαž”αžŸαŸ‹αž’αŸ’αž“αž€αžŠαŸ‚αž›αž…αž„αŸ‹αž”αŸ†αž”αŸ’αž›αŸ‚αž„αž“αŸ„αŸ‡αž‘αŸ…αž›αžΎαž―αž€αžŸαžΆαžšαž˜αž½αž™αž“αŸαŸ‡ αž“αŸ„αŸ‡αžœαžΆαž“αžΉαž„αž’αŸ’αžœαžΎαž€αžΆαžšαž”αŸ†αž”αŸ’αž›αŸ‚αž„αž€αžΌαžŠαžŠαžΎαž˜αž‘αŸ…αž‡αžΆαž€αžΌαžŠαžαŸ’αž˜αžΈαž˜αž½αž™αž•αŸ’αžŸαŸαž„αž‘αŸ€αžαžŠαŸ„αž™αžαŸ’αž›αž½αž“αž―αž„ αŸ”

Reverse Back

αžŠαŸ„αž™αž”αŸ’αžšαžΎαž€αžΌαžŠαžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž“αŸαŸ‡αž™αžΎαž„αž’αžΆαž…αž”αŸ†αž”αŸ’αž›αŸ‚αž„αž€αžΌαžŠαžαžΆαž„αž›αžΎαžŠαŸ‚αž›αž”αŸ†αž”αŸ’αž›αŸ‚αž„αžšαž½αž… αž²αŸ’αž™αžαŸ’αžšαž›αž”αŸ‹αž˜αž€αžŠαžΎαž˜αžœαž·αž‰αž”αžΆαž“αŸ–

1
2
3
4
5
6
7
8
9
@echo off
if "%~1"=="" exit /b
if /i "%~x1" neq ".bat" if /i "%~x1" neq ".cmd" exit /b
if exist "%~n1___%~x1" del "%~n1___%~x1"
for /f "skip=1 delims=" %%L in ('CMD /U /C Type "%~1"') do (
   echo %%L
   echo %%L >>"%~n1___%~x1"
)
pause>nul

αž«αž€αŸαž€αžΌαžŠαžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž”αŸ’αžšαžΎαž”αžΆαž“αžŠαžΌαž…αž‚αŸ’αž“αžΆ

1
2
3
4
@echo off &setlocal
if "%~1"=="" exit /b
if /i "%~x1" neq ".bat" if /i "%~x1" neq ".cmd" exit /b
<"%~1" ((for /l %%N in (1 1 8) do pause)>nul&findstr "^">"%~n1___%~x1")

Usage

αžŠαžΌαž…αž‚αŸ’αž“αžΆαž“αŸαŸ‡αžŠαŸ‚αžšαž‚αžΊαž‚αŸ’αžšαžΆαž“αŸ‹αžαŸ‚αžšαž€αŸ’αžŸαžΆαžœαžΆαž‘αž»αž€αž‡αžΆ *.bat αžšαž½αž…αž αžΎαž™αž‘αŸ†αž›αžΆαž€αŸ‹αž€αžΌαžŠαžŠαŸ‚αž›αž”αžΆαž“αž”αŸ†αž”αŸ’αž›αŸ‚αž„αžšαž½αž…αž‘αŸ…αž›αžΎαžœαžΆ αž“αŸ„αŸ‡αžœαžΆαž“αžΉαž„αž”αŸ†αž”αŸ’αž›αŸ‚αž„αž€αžΌαžŠαžŠαžΎαž˜αž…αŸαž‰αž˜αž€αžœαž·αž‰ αŸ•

Share on

Thik
WRITTEN BY
thik
Security Researcher