Decoding BAT script - character set encoding
Dec 25, 2022
Unique way used by attacker to encode the bat script , commonly see in virus samples.
When you opened file in notepad++ , you can see data like
At first glance data looks like some clean chinese scripting data.
To decode such scripts you just have to change the encoding method of the file.
- Change the file extension to .doc
- Open the file into MS Word
- Choose the Text encoding as ‘MS-DOS’
Yaay!! You can able to see the script in readable format!