387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61cAgentTesla JScript Dropper — BL DOCUMENTS.JS
SHA-256: 387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c
Preliminary family: agenttesla
File type: Unicode text, UTF-8 text, with very long lines (1938), with CRLF line terminators (3.2 MB JScript) ^[file.txt]
Original filename: BL DOCUMENTS.JS
CAPE: skipped — not a supported binary class for detonation ^[dynamic-analysis.md]
1. Build / RE
Toolchain
- Language: JScript (Windows Script Host /
wscript.exe/cscript.exe) - Original name:
BL DOCUMENTS.JS— business-document lure consistent with AgentTesla phishing campaigns ^[metadata.json] - File size: 3,212,591 bytes — bloated by obfuscation noise and dead code ^[file.txt]
Packing / Obfuscation
- Obfuscator:
javascript-obfuscatornpm package (confirmed by fingerprint) - Fingerprint evidence:
- String-array lookup table (
_0x3891) with ~1000+ entries, resolved through a dispatcher function (_0x353b) applying hex-offset arithmetic ^[strings.txt:603] - Control-flow flattening via
switch/casedispatch tables driven by split string arrays ('0|2|4|5|1|3') ^[strings.txt:603] - Dead-code injection: massive
this.RMKTDQTABZJLZWTBXSSBXRKIDGCMMIC += ...junk-string concatenation filling ~2.4 MB of the 3.2 MB file — purely noise, never consumed ^[strings.txt] - Debugger trap function
_0x562665usingconstructor('while(true){}')pattern to crash debuggers ^[strings.txt:603]
- String-array lookup table (
- String hiding: All literal strings (COM ProgIDs, API names, PowerShell fragments) are stored in the obfuscated array and resolved at runtime via
_0x19f298(0xNNN)calls.
Anti-Analysis
- Debugger trap:
function _0x562665constructs awhile(true){}loop viaFunction.prototype.constructorto kill DevTools / dynamic analysis environments ^[strings.txt:603] - Control-flow flattening: Every logical block is wrapped in a
while(!![])loop with aswitch(_0x4857c0[_0x1b6be8++])dispatcher, making static trace impossible without symbolic execution. - Dead code: The
RMKTDQTABZJLZWTBXSSBXRKIDGCMMICvariable accumulates ~2.4 MB of Unicode noise (CJK blocks, Arabic, Devanagari, emoji) interleaved with the same delimiter string — never referenced after construction. This is purely to bloat the file and defeat string-only extraction.
Notable Functions
_0x353b(_0x2fb4ec, _0x598349)— string-array dispatcher; subtracts a fixed offset (0xc3) from the input index and returns_0x3891[_0x7be30d]._0x19f298(_0x...)— secondary dispatcher used for the main payload construction.RMKTDQTABZJLZWTBXSSBXRKIDGCMMITT— wrapper around_0x353bused throughout the outer script._0x562665— debugger trap (see above).
2. Deploy / ATT&CK
All behaviour below is statically inferred from de-obfuscated JScript fragments. No CAPE detonation was performed (file is a script, not a PE).
Execution Chain (static reconstruction)
-
Initial Access — T1566.001 (Phishing: Spearphishing Attachment)
- Filename
BL DOCUMENTS.JSmasquerades as a business document. ^[metadata.json]
- Filename
-
Execution — T1059.005 (Command and Scripting Interpreter: Visual Basic)
- The file is a
.JSscript executed bywscript.exeorcscript.exe.
- The file is a
-
Execution — T1059.001 (Command and Scripting Interpreter: PowerShell)
- The script builds a PowerShell command string (
siderophyre) via obfuscated concatenation:powershell.exe(or equivalent viacmd.exe /c) ^[strings.txt:796]- Arguments reconstructed from
>-padded fragments (padding stripped at runtime via.replace(/>/g,'')):-Noexit -nop -c^[strings.txt:820]:FromBase64String(...)^[strings.txt:836]
- The exact Base64 payload and decoded command are not recoverable statically because the payload string is assembled via
siderophyre += _0x19f298(0xNNN)calls whose array entries are themselves resolved at runtime. The obfuscation prevents full offline decoding without a JS engine.
- The script builds a PowerShell command string (
-
Execution — T1105 (Ingress Tool Transfer)
- A second ActiveXObject (
b) is instantiated withOpen()andWrite()methods, consistent withADODB.StreamorScripting.FileSystemObjectused to write a downloaded payload to disk. ^[strings.txt:699] - This strongly suggests the PowerShell stage downloads a secondary payload (likely the AgentTesla .NET assembly) and the JScript then writes it to
%TEMP%or similar.
- A second ActiveXObject (
Persistence
- Not observed statically. No registry Run keys, scheduled tasks, or WMI subscriptions found in the JScript. Persistence is likely established by the secondary .NET payload.
C2 / Exfiltration
- Not observed statically. No SMTP credentials, FTP servers, Telegram bot tokens, or HTTP endpoints recovered from this script. The JScript is purely a dropper/loader — C2 lives in the secondary payload.
Anti-VM / Evasion
- Debugger trap via
_0x562665(see Build / RE section). - File bloat (3.2 MB) to evade size-based heuristics and slow sandboxes.
3. Attribution Notes
- Family:
agenttesla— preliminary tag from OpenCTI and triage pipeline. The JScript dropper is consistent with AgentTesla delivery observed elsewhere in this corpus (AutoItSC, Delphi VCL, PyInstaller), but this is the first JScript loader in the corpus. - Confidence:
medium— the outer script is a genericjavascript-obfuscatordropper. Without the secondary payload (which requires dynamic execution or a JS engine to decode), definitive family attribution rests on the triage pipeline's preliminary label and filename lure pattern.
4. IOCs
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c |
Original sample |
| Filename | BL DOCUMENTS.JS |
Phishing lure |
| File size | 3,212,591 bytes | Bloated by obfuscation |
| Obfuscator | javascript-obfuscator |
npm package fingerprint |
No network IOCs recovered statically. The payload is assembled at runtime via obfuscated string-array lookups.
5. Recommendations
- Dynamic analysis: Run the script in a sandboxed Windows environment with
wscript.exeunder ProcMon + Wireshark to capture the PowerShell command line, the decoded Base64 payload, and any network requests. - String extraction: Use a JavaScript engine (Node.js, QuickJS) to execute the outer script up to the
siderophyreconstruction point, then dump the resolved string. - Hunting: Look for
.JSattachments in email with names like* DOCUMENTS.JS,* INVOICE.JS,* ORDER.JS— AgentTesla phishing themes. - Block:
javascript-obfuscatorproduces highly characteristic output. YARA rules can target the_0x3891array +_0x353bdispatcher +while(!![]){switch(...)}pattern.
Report written 2026-07-26. Static analysis only — CAPE skipped due to unsupported file type.