
Malicious Payload Targets Firefox Profile Directories Using File Size-Based Conditional Execution
A malicious payload uses cmd.exe with the /C flag to execute a command that loops through Firefox profile directories located in the Windows local application data environment variable. The payload employs a for loop to iterate through files and includes an if conditional that checks whether a specific variable equals exactly 17,635. When this condition is met, the script copies the matching file to a temporary directory as "t.bat" without displaying any output. The payload then executes this temporary batch script, representing what the analyst describes as a clever and uncommon technique not frequently observed. The attack specifically targets Firefox profile directories on Windows systems to identify and execute malicious batch files based on the file size condition.