familyunclassified-js-cjk-stego-dropperconfidencemedium
SHA-256: 7129076f2b648b20cbd7b35eb8612ba4315be053ebcb5fa852b689f1ef72deed

Deep Analysis — 7129076f2b64

Build / RE

Outer carrier: JScript source saved as UTF-16 LE with BOM and CRLF line terminators ^[file.txt], masquerading as a shipping-document lure (revised Shipping document BL PL and comercial Invoice.js) ^[triage.json:5]. The script uses the AuthHelper module-wrapper boilerplate — an AMD/CommonJS/global polyglot with semantic English variable names throughout.

Two-path payload delivery: The script implements two independent decoding pipelines that converge on the same inner .NET assembly:

  1. Primary path — Hangul Syllable dictionary staging ^[7129076f...deed.bin:577]: A 347-entry dictionary (PossessionsMessageslogAntennas.Add) maps random alphanumeric keys to Hangul Syllable blocks (U+AC00–U+D7A3). An order array (PartialLangleyGigabyte) holds the 347 keys in sequence. At runtime the script concatenates all Hangul values, decodes each character via charcode - 0xAC00 (44032), and assigns the resulting byte array to a process-scoped environment variable. A PowerShell child then reads the env var, decodes the bytes, and reflectively loads the assembly via System.Reflection.Assembly::Load → EntryPoint.Invoke.

  2. Fallback path — CJK Unified Ideograph stream cipher ^[7129076f...deed.bin:591]: A single long string of CJK Unified Ideograph characters (SubsystemEmulationVerzeichnisAccessesBriefings) is decrypted with a short ASCII key (RegistrarEventualCitationBookshop) via ((charcode - c1) - (key_char - c2) + 256) & 255, where c1 = 40690 ^ 91 and c2 = 44038 ^ 6. The decrypted payload is PowerShell that reconstructs the same .NET assembly in memory.

Inner payload: Extracted .NET assembly is a PE32+ x64 GUI executable (349,696 bytes) ^[payload_dotnet.bin]. Assembly identity: ContemptZoofiliaElective v4.9.7732.6353, module DisciplinaryCvsrootLexmarkSubscription.exe, MVID 766fab03-7f1a-4adf-9d7b-a167e6e26321 ^[dnfile:Assembly]. No manifest resources. References mscorlib, System.Xml, System.Configuration, System ^[dnfile:AssemblyRef].

Obfuscation: Semantic English name obfuscation on every type and method — e.g. DischargesPartnersCompletely.TransmittedMistressClarinetPresentProgrammer, GenbankThomsonOriginal.EconomiesKeepingInterestingOrganizingExposure, method MicheleMethodologyOceanicRelaxationTablespoons ^[dnfile:TypeDef] ^[dnfile:MethodDef]. Entry point method is named ΜΑΙn (Greek-letter homoglyph for "Main") ^[dnfile:MethodDef]. No P/Invoke imports visible in the metadata table, but method names include Win32 API stubs (CreateSolidBrush, TransparentBlt, WNetOpenEnumW, etc.) suggesting inline DllImport obfuscation or delegate-based native invocation.

Toolchain: Outer script hand-crafted. Inner assembly compiled with .NET Framework 4.x (MajorRuntimeVersion 4, MinorRuntimeVersion 9) and likely obfuscated post-build.

Anti-analysis: No explicit anti-VM or anti-debug in the outer script. The double-path delivery with different encoding schemes (Hangul vs CJK) acts as a resilience mechanism — if one path is neutered by string-extraction tools, the other may still execute.

Deploy / ATT&CK

Technique ID Evidence
User Execution: Malicious File T1204.002 .js file with shipping-document social-engineering lure ^[triage.json:5]
Command Scripting Interpreter: JavaScript/JScript T1059.005 Outer carrier is JScript executed via WScript.Shell ^[7129076f...deed.bin:97]
Command Scripting Interpreter: PowerShell T1059.001 Inner PowerShell stage reflectively loads .NET assembly ^[712907_payload.ps1]
Obfuscated Files or Information T1027 Hangul/CJK steganographic encoding, semantic English name obfuscation ^[dnfile:TypeDef]
Data Staging T1074 Payload staged across 347 process-scoped environment variables ^[7129076f...deed.bin:577]
Reflective Code Loading T1620 System.Reflection.Assembly::Load followed by EntryPoint.Invoke ^[712907_payload.ps1]
Hide Artifacts T1564 Payload bytes hidden inside Hangul/CJK character strings ^[7129076f...deed.bin:101]

C2 / network: No static C2 URLs, IPs, or domains observed in either the outer JScript or the inner .NET assembly. The inner assembly references System.Xml and System.Configuration — common indicators of configurable C2, but no config strings are present statically. Dynamic detonation was skipped by CAPE because the outer file is JavaScript source, not a supported binary class ^[dynamic-analysis.md].

Attribution: This sample is a confirmed sibling of 0de6482c69377a127b91aa9c28d24981b656be44a9181a83c5b014a933987216 (first observed 2026-07-26, RFQ lure). Both share the JScript→env-var→PowerShell→.NET reflective-load chain, dictionary-based payload encoding, and semantic English obfuscation of the inner assembly. The key difference is the encoding scheme: 0de6482c uses CJK Unified Ideographs (byte = charcode - 0x3400) with 384 entries; this sample uses Hangul Syllables (byte = charcode - 0xAC00) with 347 entries and adds a fallback CJK stream-cipher path. Same actor, evolved tooling.

Capabilities:

  • hangul-syllable-steganography-pe-dropper
  • cjk-unicode-steganography-pe-dropper (fallback path)
  • environment-variable-payload-staging
  • jscript-shell-powershell-spawn
  • semantic-english-name-obfuscation
  • dotnet-assembly-reflective-loading
  • double-path-resilient-delivery

Static-only analysis. CAPE skipped — outer file is JavaScript source, not a supported binary class for detonation.