APTMembers
APT

Executable’s batch file launched multiple PowerShell script requests

An executable invoked a temporary batch file whose PowerShell children named several remote scripts. A separately analyzed shortcut ran the same command for one script URL and produced a DNS lookup, but the records do not show that the executable launched that shortcut.

Oct 8, 2026, 23:52 (UTC+9)Last seenOct 8, 2026Severity100ByCTX TeamActorPatchworkChinastratsIOC23MITRE31RegionsUS

A Windows executable launched a temporary batch file whose child PowerShell processes named several remote script URLs. In a separate analysis, a Windows shortcut launched the same PowerShell command aimed at one of those URLs, http://marketprice.pk/zxcvb.ps1, and its sandbox recorded a DNS lookup for the domain. What connects the two files: a direct handoff, or a shared way of retrieving and executing code?

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence