confidencemediumupdated2026-08-12
SHA-256: 6f4de3f972e1acf8ca603ff87b65ab4b92abf303f98b87cc7e822bfd5828d132

Analysis: 6f4de3f9 — JScript dropper with javascript-obfuscator CFF + RC4 string-array

1. Build / RE

Language / runtime. JScript (Windows Script Host). Single line, 145,957 bytes, no line terminators. ^[file.txt]

Obfuscation framework. javascript-obfuscator (commercial-grade). Structural fingerprints:

  • 2,844-entry string lookup table (var d1=[...]). ^[strings.txt:1]
  • Custom base64 alphabet: abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/= (lowercase-then-uppercase swap vs standard). ^[strings.txt:44021]
  • RC4 per-string decryption keyed by the second argument of each lookup call. ^[strings.txt:44060]
  • Control-flow flattening: outer while(!![]){ try{...} catch{...} } loop driven by dead parseInt arithmetic expressions that select switch-like branches. ^[strings.txt:46769]
  • Self-defending anti-debug: probes Function.prototype.toString() with a regex (\\cw+\\s*\\(\\)\\s*{\\cw+\\s* + [\'|\"].+[\'|\"];?\\s*}) and decrements a counter on match; if debugger detected, falls into a random-state mutation trap. ^[strings.txt:44200]

Code quality. Entire payload is one self-contained function; no external imports. The arithmetic expressions are purely obfuscatory — e.g. n=n-(-0xf*-0xed+-0x2625+0x7c*0x34) resolves to a fixed offset (238). Hex constants dominate the first 3 KB after the string array. ^[strings.txt:44060]

Anti-analysis. No VM-specific checks, but the flattened control flow and debugger-regex probe are sufficient to stall casual manual stepping and break naive string-extraction scripts that do not implement the swapped base64 alphabet or RC4 key schedule. ^[strings.txt:44200]

2. Deploy / ATT&CK

Execution chain (static inference). Script instantiates WScript.Shell and Scripting.FileSystemObject, opens %TEMP%\\disable-and-install.log in append mode, and writes timestamped bootstrap lines (Script started: disable-and-install.js). ^[decoded strings via Node.js]

TTPs

  • T1059.005 — Command Scripting Interpreter (JScript carrier). ^[strings.txt]
  • T1059.001 — PowerShell (deobfuscated strings show powershell references, Add-Content, -NoProfile, -WindowStyle Hidden). ^[decoded strings]
  • T1105 — Ingress Tool Transfer (HTTPS GET to constructed payload URL; WinHttp.WinHttpRequest.5.1 or MSXML2.ServerXMLHTTP implied by XMLHTTP fragments in deobfuscated text). ^[decoded strings]
  • T1053.005 — Scheduled Task/Job (schtasks /sc minute and service-install references in decoded text). ^[decoded strings]
  • T1562.001 — Impair Defenses (SmartScreen disable and Windows Defender policy modifications referenced). ^[decoded strings]
  • T1547.001 — Boot or Logon Autostart Execution (startup-folder and HKLM\\SOFTWARE\\...\\Run references). ^[decoded strings]

Network. A URL is assembled via concatenated x0(...) calls: 'https://' + x0(0xb79,'FdoV') + x0(0x8da,'4e]0') + ... + 'si'. Exact hostname is RC4-encrypted inside the string array; the key-per-call design means a single wrong key produces garbage, but the construction pattern confirms HTTPS payload staging. ^[strings.txt:134807]

Payload. Deobfuscated fragments reference MSI installer URLs, PDF document downloads, and cscript execution — suggesting a multi-stage delivery where the JScript dropper fetches a second-stage payload (possibly MSI or disguised PDF) and executes it. ^[decoded strings]

Persistence. Multiple mechanisms observed in decoded strings:

  • Registry Run key (HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run).
  • Startup folder self-copy.
  • schtasks /create /sc minute for recurring execution. ^[decoded strings]

Logging. The script maintains its own log at %TEMP%\\disable-and-install.log, writing timestamped status lines (Installation completed, Download failed, Service status, etc.), which is unusual for commodity malware and suggests a relatively polished operator tool. ^[decoded strings]

3. Attribution

Family. unattributed — no sibling cluster confirmed, but the javascript-obfuscator build fingerprint (2,844-entry array, swapped base64 alphabet, CFF flattening) matches the toolchain seen in unclassified-js-pptx-dropper (9a69ad1b) and unclassified-js-rentry-telegram-dropper (b0c43e946344). The internal filename disable-and-install.js and the log-based operational telemetry are unique to this sample; no direct string overlap with those siblings. Medium-confidence that it shares a builder template, low-confidence for same actor.

Confidence. Medium for javascript-obfuscator toolchain attribution; low for actor/family.


Report generated 2026-08-12. Static-only analysis — CAPE skipped (JScript is not a supported binary class).