Suspicious PIF Payload Assembly via copy /b Binary Concatenation

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-21
Updated
2026-09-21

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the cmd copy command using the b binary flag to concatenate files into a pif output. An NSIS delivered Industries batch used copy /b to rebuild an AutoIt pif payload before AsyncRAT injection. Binary concatenation into a pif reassembles a split malicious executable to evade static delivery detection.

Related detections9 linkedT1027 — drag to rearrange
Obfuscated Encoded PowerShell Payload Deployed via Process Execution (via process_creation)
Malicious KB Document Masqueraded Executable Spawned by Script Interpreter via RoKRAT Loader (via process_creation)
Malicious Payload Assembly via MZ Header Prepend and copy Concatenation (via process_creation)
Suspicious DarkGate AutoIt3 Script Execution from C Test Directory
Suspicious AdsExhaust Batch Persistence in AppData wespmail Folder
Suspicious PowerShell Spawned from PyInstaller MEI Extraction Folder (via process_creation)
Suspicious PowerShell Encoded Command Execution
Suspicious Explorer Executing Path With Trailing Dot via LNK Stomping
Malicious BADIIS Driver Dropped to System32 Drivers Directory (via file_event)
Suspicious PIF Payload Assembly via copy /b Binary Concatenation
Pivot detection · T1027 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.