6f4de3f972e1acf8ca603ff87b65ab4b92abf303f98b87cc7e822bfd5828d132Analysis: 6f4de3f9 — JScript dropper with javascript-obfuscator CFF + RC4 string-array
1. Build / RE
Language / runtime. JScript (Windows Script Host). Single line, 145,957 bytes, no line terminators. ^[file.txt]
Obfuscation framework. javascript-obfuscator (commercial-grade). Structural fingerprints:
- 2,844-entry string lookup table (
var d1=[...]). ^[strings.txt:1] - Custom base64 alphabet:
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+/=(lowercase-then-uppercase swap vs standard). ^[strings.txt:44021] - RC4 per-string decryption keyed by the second argument of each lookup call. ^[strings.txt:44060]
- Control-flow flattening: outer
while(!![]){ try{...} catch{...} }loop driven by deadparseIntarithmetic expressions that select switch-like branches. ^[strings.txt:46769] - Self-defending anti-debug: probes
Function.prototype.toString()with a regex (\\cw+\\s*\\(\\)\\s*{\\cw+\\s*+[\'|\"].+[\'|\"];?\\s*}) and decrements a counter on match; if debugger detected, falls into a random-state mutation trap. ^[strings.txt:44200]
Code quality. Entire payload is one self-contained function; no external imports. The arithmetic expressions are purely obfuscatory — e.g. n=n-(-0xf*-0xed+-0x2625+0x7c*0x34) resolves to a fixed offset (238). Hex constants dominate the first 3 KB after the string array. ^[strings.txt:44060]
Anti-analysis. No VM-specific checks, but the flattened control flow and debugger-regex probe are sufficient to stall casual manual stepping and break naive string-extraction scripts that do not implement the swapped base64 alphabet or RC4 key schedule. ^[strings.txt:44200]
2. Deploy / ATT&CK
Execution chain (static inference). Script instantiates WScript.Shell and Scripting.FileSystemObject, opens %TEMP%\\disable-and-install.log in append mode, and writes timestamped bootstrap lines (Script started: disable-and-install.js). ^[decoded strings via Node.js]
TTPs
- T1059.005 — Command Scripting Interpreter (JScript carrier). ^[strings.txt]
- T1059.001 — PowerShell (deobfuscated strings show
powershellreferences,Add-Content,-NoProfile,-WindowStyle Hidden). ^[decoded strings] - T1105 — Ingress Tool Transfer (HTTPS GET to constructed payload URL;
WinHttp.WinHttpRequest.5.1orMSXML2.ServerXMLHTTPimplied byXMLHTTPfragments in deobfuscated text). ^[decoded strings] - T1053.005 — Scheduled Task/Job (
schtasks /sc minuteand service-install references in decoded text). ^[decoded strings] - T1562.001 — Impair Defenses (SmartScreen disable and Windows Defender policy modifications referenced). ^[decoded strings]
- T1547.001 — Boot or Logon Autostart Execution (startup-folder and
HKLM\\SOFTWARE\\...\\Runreferences). ^[decoded strings]
Network. A URL is assembled via concatenated x0(...) calls: 'https://' + x0(0xb79,'FdoV') + x0(0x8da,'4e]0') + ... + 'si'. Exact hostname is RC4-encrypted inside the string array; the key-per-call design means a single wrong key produces garbage, but the construction pattern confirms HTTPS payload staging. ^[strings.txt:134807]
Payload. Deobfuscated fragments reference MSI installer URLs, PDF document downloads, and cscript execution — suggesting a multi-stage delivery where the JScript dropper fetches a second-stage payload (possibly MSI or disguised PDF) and executes it. ^[decoded strings]
Persistence. Multiple mechanisms observed in decoded strings:
- Registry Run key (
HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run). - Startup folder self-copy.
schtasks /create /sc minutefor recurring execution. ^[decoded strings]
Logging. The script maintains its own log at %TEMP%\\disable-and-install.log, writing timestamped status lines (Installation completed, Download failed, Service status, etc.), which is unusual for commodity malware and suggests a relatively polished operator tool. ^[decoded strings]
3. Attribution
Family. unattributed — no sibling cluster confirmed, but the javascript-obfuscator build fingerprint (2,844-entry array, swapped base64 alphabet, CFF flattening) matches the toolchain seen in unclassified-js-pptx-dropper (9a69ad1b) and unclassified-js-rentry-telegram-dropper (b0c43e946344). The internal filename disable-and-install.js and the log-based operational telemetry are unique to this sample; no direct string overlap with those siblings. Medium-confidence that it shares a builder template, low-confidence for same actor.
Confidence. Medium for javascript-obfuscator toolchain attribution; low for actor/family.
Report generated 2026-08-12. Static-only analysis — CAPE skipped (JScript is not a supported binary class).