FILEMembers
FILE

Four-Detection BAT Stager Opens Door to Czech Utilities via Bitbucket CDN

An 8 KB DOS batch file evading 72 of 76 antivirus engines serves as the opening move in a campaign targeting Czech utilities infrastructure. The stager decodes a Bitbucket-hosted payload and chains to a ZeroSSL-certified Norwegian cloud node for command-and-control, with the confirmed MSIL trojan classified as trojan.msil/jalapeno.

Jun 1, 2026, 12:10 (UTC+9)Last seenJun 1, 2026Severity100ByCTX TeamIOC17MITRE34RegionsCZ

An 8-kilobyte DOS batch file that only four of 76 antivirus engines flag at submission time is the opening move in a campaign targeting Czech utilities infrastructure — and the low detection count is not an accident. The file, nott.bat, carries two YARA rule hits that expose its construction: SUSP_PS1_JAB_Pattern_Jun22_1, which detects UTF-16 and Base64-encoded PowerShell opening with a single-character variable, and Base64_Encoded_URL, which fires on embedded encoded URI strings.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence