37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2exeinarchive: 37e8fc3692a6 — Payment-Swift JS dropper, Task Scheduler persistence, iteGroup.sbs C2
Executive Summary: Invoice-themed JavaScript dropper obfuscated with the javascript-obfuscator npm package. Downloads a PowerShell script from itegroup.sbs and establishes persistence via both Windows Task Scheduler and a Startup-folder LNK shortcut. Confirmed second sibling in the itegroup-sbs-dropper cluster.
What It Is
- Filename:
Payment-Swift-TT05294758.js^[triage.json] - File type: ASCII text, single line, 51 KB ^[file.txt]
- Language: JScript for Windows Script Host (WScript/CScript)
- Obfuscator:
javascript-obfuscatornpm package — 573-entry string-array lookup table, control-flow flattening, self-defend anti-debug regex trap ^[js-decoded-strings.txt] - Delivery: Business-document social-engineering lure (SWIFT payment reference)
- C2:
https://itegroup.sbs/downlload/yandex/stub.ps1(same base domain as sibling0bc60a0e; different path) ^[report.md:line-extracted] - Payload type: PowerShell
.ps1script downloaded via MSXML2.XMLHTTP and executed with-nop -ep bypass -windowstyle hidden - CAPE: Skipped — not a supported binary class ^[dynamic-analysis.md]
How It Works
Stage 1 — JScript Dropper
The outer .js file is heavily obfuscated by javascript-obfuscator. Literal strings are hoisted into a 573-element array W3 inside function N(), decoded at runtime by function s(H,C) which applies a constant arithmetic offset to map hex indices to array slots. ^[js-decoded-strings.txt]
The script instantiates three ActiveXObject interfaces:
WScript.Shell— for registry writes and process spawning ^[js-decoded-strings.txt:404]Scripting.FileSystemObject— for file system operations (CreateFolder, CreateTextFile, Save) ^[js-decoded-strings.txt:189]MSXML2.XMLHTTP— for HTTP GET download ^[js-decoded-strings.txt:292]
A config object HJ hardcodes the download URL, temp directory (C:\Temp\), task name, trigger delay (0x5 = 5), and max retries (0x3 = 3). ^[report.md:line-extracted]
Stage 2 — Download & Execute
- Creates
C:\Temp\if it does not exist (CreateFolder) ^[js-decoded-strings.txt:534] - Performs an HTTP GET to
https://itegroup.sbs/downlload/yandex/stub.ps1viaXMLHTTP^[report.md:line-extracted] - Saves the response to a
.ps1file in the temp directory usingCreateTextFile+Write^[js-decoded-strings.txt:348,101] - Spawns
powershell.exe -nop -ep bypass -windowstyle hidden -file "<temp_ps1>"^[js-decoded-strings.txt:550]
Stage 3 — Persistence (Dual Mechanism)
The dropper implements two persistence mechanisms:
A. Windows Task Scheduler (Schedule.Service COM API)
- Task name resolved from obfuscated string array ^[js-decoded-strings.txt:33]
- Description:
"Windows System Maintenance Utility"^[js-decoded-strings.txt:313] - Registration info author:
"Microsoft Corporation"^[js-decoded-strings.txt:253] - Trigger settings:
StartWhenAvailable,triggerDelay: 5,RestartInterval,RunOnlyIfIdle,StopIfGoingOnBatteries,DisallowStartIfOnBatteries,AllowHardTerminate,AllowDemandStart,WakeToRun^[js-decoded-strings.txt:34,148,521,364,149,310,145,495] - Executed via
RegisterTaskDefinition^[js-decoded-strings.txt:549]
B. Startup Folder LNK Shortcut
- Creates a
.lnkshortcut in the Startup special folder viaWScript.Shell→CreateShortcut^[js-decoded-strings.txt:353,511,410] - Shortcut properties:
TargetPath,WindowStyle = Hidden,IconLocation^[js-decoded-strings.txt:384,105,69]
Stage 4 — Registry Run Key (Tertiary)
- Writes to
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\viaRegWritewith typeREG_SZ^[js-decoded-strings.txt:515,32,142]
C2 Infrastructure
| Indicator | Value |
|---|---|
| URL | https://itegroup.sbs/downlload/yandex/stub.ps1 |
| Domain | itegroup.sbs |
| Path | /downlload/yandex/stub.ps1 |
| Method | HTTP GET |
| Transport | MSXML2.XMLHTTP |
| User-Agent | Default (no custom UA observed) |
Infrastructure note: The domain itegroup.sbs is shared with the first confirmed sibling (0bc60a0e). The .sbs TLD is cheap and mass-registration friendly. The /downlload/ path uses a double-l spelling (downlload vs download), a common anti-filtering trick.
Interesting Tidbits
- Payment-Swift lure: The filename masquerades as a legitimate SWIFT TT (Telegraphic Transfer) reference, targeting finance/procurement staff. ^[triage.json]
- No sandbox gate: Unlike the
exeinarchivecanonical pattern (which gates onaspnet_compiler.exe), this sample has no process-name or environment checks. It executes immediately when WScript runs. - No RC4/PowerShell/XOR .NET chain: The canonical
exeinarchivefour-stage chain (JS→Base64→RC4 PS→XOR .NET) is not present here. This is a simpler two-stage JS→PowerScript direct downloader, making it more of aitegroup-sbs-droppersibling than a trueexeinarchivevariant. The OpenCTIexe-in-archivelabel reflects delivery vector, not technical family. - Microsoft masquerade: The task description and registration info both claim Microsoft provenance, a common trust-abuse tactic. ^[js-decoded-strings.txt:253,313]
- Triple persistence: Task Scheduler + Startup LNK + Registry Run is unusually redundant for a simple downloader, suggesting the author prioritizes survivability over stealth.
Deploy / ATT&CK
| Tactic | Technique | Evidence |
|---|---|---|
| Initial Access | T1566.001 | Business-themed phishing lure (Payment-Swift-TT05294758.js) ^[triage.json] |
| Execution | T1059.005 | WScript execution of .js outer stage ^[js-decoded-strings.txt:404] |
| Execution | T1059.001 | PowerShell -nop -ep bypass -windowstyle hidden spawn ^[js-decoded-strings.txt:550] |
| Persistence | T1053.005 | Windows Task Scheduler via Schedule.Service COM with RegisterTaskDefinition ^[js-decoded-strings.txt:549,86] |
| Persistence | T1547.001 | HKCU Run registry key via WScript.Shell.RegWrite ^[js-decoded-strings.txt:515,32] |
| Persistence | T1547.009 | Startup-folder .lnk shortcut creation ^[js-decoded-strings.txt:353,511,410] |
| Defense Evasion | T1027 | javascript-obfuscator multi-layer obfuscation (573-entry string array, CFF, self-defend) ^[js-decoded-strings.txt] |
| Defense Evasion | T1070.004 | File saved to C:\Temp\ (common staging directory) ^[js-decoded-strings.txt:470] |
| Command & Control | T1071.001 | HTTP GET to itegroup.sbs via MSXML2.XMLHTTP ^[report.md:line-extracted] |
Deployable Signatures
YARA Rule
rule JS_IteGroupSBS_Dropper {
meta:
description = "JScript dropper with javascript-obfuscator obfuscation targeting iteGroup.sbs C2"
author = "PacketPursuit"
date = "2026-08-27"
sha256 = "37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2"
strings:
$s1 = "javascript-obfuscator" ascii wide nocase
$s2 = "MSXML2.XMLHTTP" ascii wide
$s3 = "WScript.Shell" ascii wide
$s4 = "Scripting.FileSystemObject" ascii wide
$s5 = "Schedule.Service" ascii wide
$s6 = "RegWrite" ascii wide
$s7 = "CreateShortcut" ascii wide
$s8 = "RegisterTaskDefinition" ascii wide
$s9 = "HKCU\\x5cSoftware\\x5cMicrosoft\\x5cWindows\\x5cCurrentVersion\\x5cRun" ascii wide
$s10 = "itegroup.sbs" ascii wide nocase
$s11 = "powershell.exe" ascii wide nocase
$s12 = "-nop\\x20-ep\\x20bypass" ascii wide
$s13 = "Windows\\x20System\\x20Maintenance\\x20Utility" ascii wide
$s14 = "Microsoft\\x20Corporation" ascii wide
$s15 = "C:\\x5cTemp\\x5c" ascii wide
$obf1 = /function\s+\w+\(\)\{var\s+\w+3=\[/
$obf2 = /function\s+\w+\(\w+,\w+\)\{\w+=\w+-\(/
condition:
filesize < 100KB and
(uint8(0) == 0x66 or uint8(0) == 0x76) and // 'f' or 'v' (function/var)
4 of ($s*) and
any of ($obf*)
}
Sigma Rule
title: JScript Dropper - IteGroup SBS Pattern
description: Detects JScript execution leading to PowerShell download from iteGroup.sbs
logsource:
category: process_creation
product: windows
detection:
selection_js:
CommandLine|contains:
- 'wscript.exe'
- 'cscript.exe'
CommandLine|endswith: '.js'
selection_ps:
CommandLine|contains:
- 'powershell.exe'
- '-nop'
- '-ep bypass'
- '-windowstyle hidden'
selection_network:
CommandLine|contains:
- 'itegroup.sbs'
- 'downlload'
- 'stub.ps1'
condition: selection_js and selection_ps and selection_network
falsepositives:
- Unknown
level: high
Behavioral Hunt Query (KQL)
let js_dropper_sigs = dynamic(["Payment-Swift", "Order-June", "invoice", "quotation", "purchase-order"]);
DeviceProcessEvents
| where ProcessCommandLine contains "wscript.exe" or ProcessCommandLine contains "cscript.exe"
| where ProcessCommandLine contains ".js"
| where FileName has_any (js_dropper_sigs) or ProcessCommandLine has_any (js_dropper_sigs)
| join kind=inner (
DeviceNetworkEvents
| where RemoteUrl contains "itegroup.sbs"
) on DeviceId, Timestamp
| project Timestamp, DeviceName, InitiatingProcessCommandLine, ProcessCommandLine, RemoteUrl
IOC List
| Type | Value | Context |
|---|---|---|
| SHA-256 | 37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2 |
Dropper JS |
| URL | https://itegroup.sbs/downlload/yandex/stub.ps1 |
Stage-2 payload |
| Domain | itegroup.sbs |
C2 / staging |
| Path | C:\Temp\ |
Local staging directory |
| Registry | HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ |
Persistence |
| File | %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\*.lnk |
LNK persistence |
| Task | Windows System Maintenance Utility |
Scheduled task masquerade |
Behavioral Fingerprint
This JavaScript dropper, when executed by WScript/CScript, performs the following observable chain: (1) instantiates ActiveXObject MSXML2.XMLHTTP and WScript.Shell within the first second; (2) issues an HTTP GET to a .sbs-TLD domain over HTTPS; (3) writes the response body to C:\Temp\<filename>.ps1 using Scripting.FileSystemObject; (4) spawns powershell.exe with -nop -ep bypass -windowstyle hidden -file; (5) creates a .lnk shortcut in the Startup special folder; (6) writes a REG_SZ value to HKCU\...\Run; (7) registers a Windows scheduled task via Schedule.Service COM with RegisterTaskDefinition, using Microsoft Corporation as the author and Windows System Maintenance Utility as the description. The script file itself is a single line of javascript-obfuscator-produced code with a 500+ entry string-array lookup table and heavy control-flow flattening.
Detection Signatures
- Static: No YARA matches in triage ^[yara.txt]
- Dynamic: CAPE skipped (non-binary) ^[dynamic-analysis.md]
- Obfuscation:
javascript-obfuscatorstring-array + CFF pattern confirmed by manual RE ^[js-decoded-strings.txt]
References
- Artifact ID:
8865d4d8-0d8d-4602-91eb-594b5a72d125^[metadata.json] - Source: OpenCTI / MalwareBazaar ^[triage.json]
- OpenCTI labels:
exe-in-archive,js,malware-bazaar,spamtrap^[triage.json] - Sibling:
0bc60a0e— first confirmeditegroup-sbs-dropperwith identical obfuscation pattern and same base domain ^[entities/itegroup-sbs-dropper.md] - Wiki: exeinarchive — umbrella entity for spam-trap JS droppers ^[entities/exeinarchive.md]
- Wiki: itegroup-sbs-dropper — specific cluster entity ^[entities/itegroup-sbs-dropper.md]
- Wiki: javascript-obfuscator — obfuscation tooling concept ^[concepts/javascript-obfuscator.md]
- Wiki: wscript-powershell-cradle — WScript→PowerShell staging technique ^[techniques/wscript-powershell-cradle.md]
Provenance
- File type:
fileutility on.bin→ ASCII text, single line, 51 KB ^[file.txt] - PE analysis:
pefilereported "(not PE)" ^[pefile.txt] - CAPA: Failed — unsupported file type ^[capa.txt]
- FLOSS: Failed — argument error (passed JS file to binary tool) ^[floss.txt]
- Binwalk: No embedded artefacts ^[binwalk.txt]
- rabin2:
binsz 51292,havecode false^[rabin2-info.txt] - String extraction: Manual Python script parsed
javascript-obfuscatorN()string array, producing 573 decoded entries ^[js-decoded-strings.txt] - C2 extraction: Grepped hardcoded config object
HJfrom tail of script ^[report.md:line-extracted]