typeanalysisfamilyexeinarchiveconfidencehighscriptdropperjsobfuscationdefense-evasionpersistencec2
SHA-256: 37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2

exeinarchive: 37e8fc3692a6 — Payment-Swift JS dropper, Task Scheduler persistence, iteGroup.sbs C2

Executive Summary: Invoice-themed JavaScript dropper obfuscated with the javascript-obfuscator npm package. Downloads a PowerShell script from itegroup.sbs and establishes persistence via both Windows Task Scheduler and a Startup-folder LNK shortcut. Confirmed second sibling in the itegroup-sbs-dropper cluster.

What It Is

  • Filename: Payment-Swift-TT05294758.js ^[triage.json]
  • File type: ASCII text, single line, 51 KB ^[file.txt]
  • Language: JScript for Windows Script Host (WScript/CScript)
  • Obfuscator: javascript-obfuscator npm package — 573-entry string-array lookup table, control-flow flattening, self-defend anti-debug regex trap ^[js-decoded-strings.txt]
  • Delivery: Business-document social-engineering lure (SWIFT payment reference)
  • C2: https://itegroup.sbs/downlload/yandex/stub.ps1 (same base domain as sibling 0bc60a0e; different path) ^[report.md:line-extracted]
  • Payload type: PowerShell .ps1 script downloaded via MSXML2.XMLHTTP and executed with -nop -ep bypass -windowstyle hidden
  • CAPE: Skipped — not a supported binary class ^[dynamic-analysis.md]

How It Works

Stage 1 — JScript Dropper

The outer .js file is heavily obfuscated by javascript-obfuscator. Literal strings are hoisted into a 573-element array W3 inside function N(), decoded at runtime by function s(H,C) which applies a constant arithmetic offset to map hex indices to array slots. ^[js-decoded-strings.txt]

The script instantiates three ActiveXObject interfaces:

  • WScript.Shell — for registry writes and process spawning ^[js-decoded-strings.txt:404]
  • Scripting.FileSystemObject — for file system operations (CreateFolder, CreateTextFile, Save) ^[js-decoded-strings.txt:189]
  • MSXML2.XMLHTTP — for HTTP GET download ^[js-decoded-strings.txt:292]

A config object HJ hardcodes the download URL, temp directory (C:\Temp\), task name, trigger delay (0x5 = 5), and max retries (0x3 = 3). ^[report.md:line-extracted]

Stage 2 — Download & Execute

  1. Creates C:\Temp\ if it does not exist (CreateFolder) ^[js-decoded-strings.txt:534]
  2. Performs an HTTP GET to https://itegroup.sbs/downlload/yandex/stub.ps1 via XMLHTTP ^[report.md:line-extracted]
  3. Saves the response to a .ps1 file in the temp directory using CreateTextFile + Write ^[js-decoded-strings.txt:348,101]
  4. Spawns powershell.exe -nop -ep bypass -windowstyle hidden -file "<temp_ps1>" ^[js-decoded-strings.txt:550]

Stage 3 — Persistence (Dual Mechanism)

The dropper implements two persistence mechanisms:

A. Windows Task Scheduler (Schedule.Service COM API)

  • Task name resolved from obfuscated string array ^[js-decoded-strings.txt:33]
  • Description: "Windows System Maintenance Utility" ^[js-decoded-strings.txt:313]
  • Registration info author: "Microsoft Corporation" ^[js-decoded-strings.txt:253]
  • Trigger settings: StartWhenAvailable, triggerDelay: 5, RestartInterval, RunOnlyIfIdle, StopIfGoingOnBatteries, DisallowStartIfOnBatteries, AllowHardTerminate, AllowDemandStart, WakeToRun ^[js-decoded-strings.txt:34,148,521,364,149,310,145,495]
  • Executed via RegisterTaskDefinition ^[js-decoded-strings.txt:549]

B. Startup Folder LNK Shortcut

  • Creates a .lnk shortcut in the Startup special folder via WScript.Shell → CreateShortcut ^[js-decoded-strings.txt:353,511,410]
  • Shortcut properties: TargetPath, WindowStyle = Hidden, IconLocation ^[js-decoded-strings.txt:384,105,69]

Stage 4 — Registry Run Key (Tertiary)

  • Writes to HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ via RegWrite with type REG_SZ ^[js-decoded-strings.txt:515,32,142]

C2 Infrastructure

Indicator Value
URL https://itegroup.sbs/downlload/yandex/stub.ps1
Domain itegroup.sbs
Path /downlload/yandex/stub.ps1
Method HTTP GET
Transport MSXML2.XMLHTTP
User-Agent Default (no custom UA observed)

Infrastructure note: The domain itegroup.sbs is shared with the first confirmed sibling (0bc60a0e). The .sbs TLD is cheap and mass-registration friendly. The /downlload/ path uses a double-l spelling (downlload vs download), a common anti-filtering trick.

Interesting Tidbits

  • Payment-Swift lure: The filename masquerades as a legitimate SWIFT TT (Telegraphic Transfer) reference, targeting finance/procurement staff. ^[triage.json]
  • No sandbox gate: Unlike the exeinarchive canonical pattern (which gates on aspnet_compiler.exe), this sample has no process-name or environment checks. It executes immediately when WScript runs.
  • No RC4/PowerShell/XOR .NET chain: The canonical exeinarchive four-stage chain (JS→Base64→RC4 PS→XOR .NET) is not present here. This is a simpler two-stage JS→PowerScript direct downloader, making it more of a itegroup-sbs-dropper sibling than a true exeinarchive variant. The OpenCTI exe-in-archive label reflects delivery vector, not technical family.
  • Microsoft masquerade: The task description and registration info both claim Microsoft provenance, a common trust-abuse tactic. ^[js-decoded-strings.txt:253,313]
  • Triple persistence: Task Scheduler + Startup LNK + Registry Run is unusually redundant for a simple downloader, suggesting the author prioritizes survivability over stealth.

Deploy / ATT&CK

Tactic Technique Evidence
Initial Access T1566.001 Business-themed phishing lure (Payment-Swift-TT05294758.js) ^[triage.json]
Execution T1059.005 WScript execution of .js outer stage ^[js-decoded-strings.txt:404]
Execution T1059.001 PowerShell -nop -ep bypass -windowstyle hidden spawn ^[js-decoded-strings.txt:550]
Persistence T1053.005 Windows Task Scheduler via Schedule.Service COM with RegisterTaskDefinition ^[js-decoded-strings.txt:549,86]
Persistence T1547.001 HKCU Run registry key via WScript.Shell.RegWrite ^[js-decoded-strings.txt:515,32]
Persistence T1547.009 Startup-folder .lnk shortcut creation ^[js-decoded-strings.txt:353,511,410]
Defense Evasion T1027 javascript-obfuscator multi-layer obfuscation (573-entry string array, CFF, self-defend) ^[js-decoded-strings.txt]
Defense Evasion T1070.004 File saved to C:\Temp\ (common staging directory) ^[js-decoded-strings.txt:470]
Command & Control T1071.001 HTTP GET to itegroup.sbs via MSXML2.XMLHTTP ^[report.md:line-extracted]

Deployable Signatures

YARA Rule

rule JS_IteGroupSBS_Dropper {
    meta:
        description = "JScript dropper with javascript-obfuscator obfuscation targeting iteGroup.sbs C2"
        author = "PacketPursuit"
        date = "2026-08-27"
        sha256 = "37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2"
    strings:
        $s1 = "javascript-obfuscator" ascii wide nocase
        $s2 = "MSXML2.XMLHTTP" ascii wide
        $s3 = "WScript.Shell" ascii wide
        $s4 = "Scripting.FileSystemObject" ascii wide
        $s5 = "Schedule.Service" ascii wide
        $s6 = "RegWrite" ascii wide
        $s7 = "CreateShortcut" ascii wide
        $s8 = "RegisterTaskDefinition" ascii wide
        $s9 = "HKCU\\x5cSoftware\\x5cMicrosoft\\x5cWindows\\x5cCurrentVersion\\x5cRun" ascii wide
        $s10 = "itegroup.sbs" ascii wide nocase
        $s11 = "powershell.exe" ascii wide nocase
        $s12 = "-nop\\x20-ep\\x20bypass" ascii wide
        $s13 = "Windows\\x20System\\x20Maintenance\\x20Utility" ascii wide
        $s14 = "Microsoft\\x20Corporation" ascii wide
        $s15 = "C:\\x5cTemp\\x5c" ascii wide
        
        $obf1 = /function\s+\w+\(\)\{var\s+\w+3=\[/
        $obf2 = /function\s+\w+\(\w+,\w+\)\{\w+=\w+-\(/ 
    condition:
        filesize < 100KB and
        (uint8(0) == 0x66 or uint8(0) == 0x76) and // 'f' or 'v' (function/var)
        4 of ($s*) and
        any of ($obf*)
}

Sigma Rule

title: JScript Dropper - IteGroup SBS Pattern
description: Detects JScript execution leading to PowerShell download from iteGroup.sbs
logsource:
  category: process_creation
  product: windows
detection:
  selection_js:
    CommandLine|contains:
      - 'wscript.exe'
      - 'cscript.exe'
    CommandLine|endswith: '.js'
  selection_ps:
    CommandLine|contains:
      - 'powershell.exe'
      - '-nop'
      - '-ep bypass'
      - '-windowstyle hidden'
  selection_network:
    CommandLine|contains:
      - 'itegroup.sbs'
      - 'downlload'
      - 'stub.ps1'
  condition: selection_js and selection_ps and selection_network
falsepositives:
  - Unknown
level: high

Behavioral Hunt Query (KQL)

let js_dropper_sigs = dynamic(["Payment-Swift", "Order-June", "invoice", "quotation", "purchase-order"]);
DeviceProcessEvents
| where ProcessCommandLine contains "wscript.exe" or ProcessCommandLine contains "cscript.exe"
| where ProcessCommandLine contains ".js"
| where FileName has_any (js_dropper_sigs) or ProcessCommandLine has_any (js_dropper_sigs)
| join kind=inner (
    DeviceNetworkEvents
    | where RemoteUrl contains "itegroup.sbs"
) on DeviceId, Timestamp
| project Timestamp, DeviceName, InitiatingProcessCommandLine, ProcessCommandLine, RemoteUrl

IOC List

Type Value Context
SHA-256 37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2 Dropper JS
URL https://itegroup.sbs/downlload/yandex/stub.ps1 Stage-2 payload
Domain itegroup.sbs C2 / staging
Path C:\Temp\ Local staging directory
Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ Persistence
File %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\*.lnk LNK persistence
Task Windows System Maintenance Utility Scheduled task masquerade

Behavioral Fingerprint

This JavaScript dropper, when executed by WScript/CScript, performs the following observable chain: (1) instantiates ActiveXObject MSXML2.XMLHTTP and WScript.Shell within the first second; (2) issues an HTTP GET to a .sbs-TLD domain over HTTPS; (3) writes the response body to C:\Temp\<filename>.ps1 using Scripting.FileSystemObject; (4) spawns powershell.exe with -nop -ep bypass -windowstyle hidden -file; (5) creates a .lnk shortcut in the Startup special folder; (6) writes a REG_SZ value to HKCU\...\Run; (7) registers a Windows scheduled task via Schedule.Service COM with RegisterTaskDefinition, using Microsoft Corporation as the author and Windows System Maintenance Utility as the description. The script file itself is a single line of javascript-obfuscator-produced code with a 500+ entry string-array lookup table and heavy control-flow flattening.

Detection Signatures

  • Static: No YARA matches in triage ^[yara.txt]
  • Dynamic: CAPE skipped (non-binary) ^[dynamic-analysis.md]
  • Obfuscation: javascript-obfuscator string-array + CFF pattern confirmed by manual RE ^[js-decoded-strings.txt]

References

  • Artifact ID: 8865d4d8-0d8d-4602-91eb-594b5a72d125 ^[metadata.json]
  • Source: OpenCTI / MalwareBazaar ^[triage.json]
  • OpenCTI labels: exe-in-archive, js, malware-bazaar, spamtrap ^[triage.json]
  • Sibling: 0bc60a0e — first confirmed itegroup-sbs-dropper with identical obfuscation pattern and same base domain ^[entities/itegroup-sbs-dropper.md]
  • Wiki: exeinarchive — umbrella entity for spam-trap JS droppers ^[entities/exeinarchive.md]
  • Wiki: itegroup-sbs-dropper — specific cluster entity ^[entities/itegroup-sbs-dropper.md]
  • Wiki: javascript-obfuscator — obfuscation tooling concept ^[concepts/javascript-obfuscator.md]
  • Wiki: wscript-powershell-cradle — WScript→PowerShell staging technique ^[techniques/wscript-powershell-cradle.md]

Provenance

  • File type: file utility on .bin → ASCII text, single line, 51 KB ^[file.txt]
  • PE analysis: pefile reported "(not PE)" ^[pefile.txt]
  • CAPA: Failed — unsupported file type ^[capa.txt]
  • FLOSS: Failed — argument error (passed JS file to binary tool) ^[floss.txt]
  • Binwalk: No embedded artefacts ^[binwalk.txt]
  • rabin2: binsz 51292, havecode false ^[rabin2-info.txt]
  • String extraction: Manual Python script parsed javascript-obfuscator N() string array, producing 573 decoded entries ^[js-decoded-strings.txt]
  • C2 extraction: Grepped hardcoded config object HJ from tail of script ^[report.md:line-extracted]