familyagentteslaconfidencemediumcreated2026-07-26
SHA-256: 387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c

AgentTesla JScript Dropper — BL DOCUMENTS.JS

SHA-256: 387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c
Preliminary family: agenttesla
File type: Unicode text, UTF-8 text, with very long lines (1938), with CRLF line terminators (3.2 MB JScript) ^[file.txt]
Original filename: BL DOCUMENTS.JS
CAPE: skipped — not a supported binary class for detonation ^[dynamic-analysis.md]


1. Build / RE

Toolchain

  • Language: JScript (Windows Script Host / wscript.exe / cscript.exe)
  • Original name: BL DOCUMENTS.JS — business-document lure consistent with AgentTesla phishing campaigns ^[metadata.json]
  • File size: 3,212,591 bytes — bloated by obfuscation noise and dead code ^[file.txt]

Packing / Obfuscation

  • Obfuscator: javascript-obfuscator npm package (confirmed by fingerprint)
  • Fingerprint evidence:
    • String-array lookup table (_0x3891) with ~1000+ entries, resolved through a dispatcher function (_0x353b) applying hex-offset arithmetic ^[strings.txt:603]
    • Control-flow flattening via switch/case dispatch tables driven by split string arrays ('0|2|4|5|1|3') ^[strings.txt:603]
    • Dead-code injection: massive this.RMKTDQTABZJLZWTBXSSBXRKIDGCMMIC += ... junk-string concatenation filling ~2.4 MB of the 3.2 MB file — purely noise, never consumed ^[strings.txt]
    • Debugger trap function _0x562665 using constructor('while(true){}') pattern to crash debuggers ^[strings.txt:603]
  • String hiding: All literal strings (COM ProgIDs, API names, PowerShell fragments) are stored in the obfuscated array and resolved at runtime via _0x19f298(0xNNN) calls.

Anti-Analysis

  • Debugger trap: function _0x562665 constructs a while(true){} loop via Function.prototype.constructor to kill DevTools / dynamic analysis environments ^[strings.txt:603]
  • Control-flow flattening: Every logical block is wrapped in a while(!![]) loop with a switch(_0x4857c0[_0x1b6be8++]) dispatcher, making static trace impossible without symbolic execution.
  • Dead code: The RMKTDQTABZJLZWTBXSSBXRKIDGCMMIC variable accumulates ~2.4 MB of Unicode noise (CJK blocks, Arabic, Devanagari, emoji) interleaved with the same delimiter string — never referenced after construction. This is purely to bloat the file and defeat string-only extraction.

Notable Functions

  • _0x353b(_0x2fb4ec, _0x598349) — string-array dispatcher; subtracts a fixed offset (0xc3) from the input index and returns _0x3891[_0x7be30d].
  • _0x19f298(_0x...) — secondary dispatcher used for the main payload construction.
  • RMKTDQTABZJLZWTBXSSBXRKIDGCMMITT — wrapper around _0x353b used throughout the outer script.
  • _0x562665 — debugger trap (see above).

2. Deploy / ATT&CK

All behaviour below is statically inferred from de-obfuscated JScript fragments. No CAPE detonation was performed (file is a script, not a PE).

Execution Chain (static reconstruction)

  1. Initial Access — T1566.001 (Phishing: Spearphishing Attachment)

    • Filename BL DOCUMENTS.JS masquerades as a business document. ^[metadata.json]
  2. Execution — T1059.005 (Command and Scripting Interpreter: Visual Basic)

    • The file is a .JS script executed by wscript.exe or cscript.exe.
  3. Execution — T1059.001 (Command and Scripting Interpreter: PowerShell)

    • The script builds a PowerShell command string (siderophyre) via obfuscated concatenation:
      • powershell.exe (or equivalent via cmd.exe /c) ^[strings.txt:796]
      • Arguments reconstructed from >-padded fragments (padding stripped at runtime via .replace(/>/g,'')):
        • -Noexit -nop -c ^[strings.txt:820]
        • :FromBase64String(...) ^[strings.txt:836]
    • The exact Base64 payload and decoded command are not recoverable statically because the payload string is assembled via siderophyre += _0x19f298(0xNNN) calls whose array entries are themselves resolved at runtime. The obfuscation prevents full offline decoding without a JS engine.
  4. Execution — T1105 (Ingress Tool Transfer)

    • A second ActiveXObject (b) is instantiated with Open() and Write() methods, consistent with ADODB.Stream or Scripting.FileSystemObject used to write a downloaded payload to disk. ^[strings.txt:699]
    • This strongly suggests the PowerShell stage downloads a secondary payload (likely the AgentTesla .NET assembly) and the JScript then writes it to %TEMP% or similar.

Persistence

  • Not observed statically. No registry Run keys, scheduled tasks, or WMI subscriptions found in the JScript. Persistence is likely established by the secondary .NET payload.

C2 / Exfiltration

  • Not observed statically. No SMTP credentials, FTP servers, Telegram bot tokens, or HTTP endpoints recovered from this script. The JScript is purely a dropper/loader — C2 lives in the secondary payload.

Anti-VM / Evasion

  • Debugger trap via _0x562665 (see Build / RE section).
  • File bloat (3.2 MB) to evade size-based heuristics and slow sandboxes.

3. Attribution Notes

  • Family: agenttesla — preliminary tag from OpenCTI and triage pipeline. The JScript dropper is consistent with AgentTesla delivery observed elsewhere in this corpus (AutoItSC, Delphi VCL, PyInstaller), but this is the first JScript loader in the corpus.
  • Confidence: medium — the outer script is a generic javascript-obfuscator dropper. Without the secondary payload (which requires dynamic execution or a JS engine to decode), definitive family attribution rests on the triage pipeline's preliminary label and filename lure pattern.

4. IOCs

Type Value Notes
SHA-256 387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c Original sample
Filename BL DOCUMENTS.JS Phishing lure
File size 3,212,591 bytes Bloated by obfuscation
Obfuscator javascript-obfuscator npm package fingerprint

No network IOCs recovered statically. The payload is assembled at runtime via obfuscated string-array lookups.


5. Recommendations

  1. Dynamic analysis: Run the script in a sandboxed Windows environment with wscript.exe under ProcMon + Wireshark to capture the PowerShell command line, the decoded Base64 payload, and any network requests.
  2. String extraction: Use a JavaScript engine (Node.js, QuickJS) to execute the outer script up to the siderophyre construction point, then dump the resolved string.
  3. Hunting: Look for .JS attachments in email with names like * DOCUMENTS.JS, * INVOICE.JS, * ORDER.JS — AgentTesla phishing themes.
  4. Block: javascript-obfuscator produces highly characteristic output. YARA rules can target the _0x3891 array + _0x353b dispatcher + while(!![]){switch(...)} pattern.

Report written 2026-07-26. Static analysis only — CAPE skipped due to unsupported file type.