familyagentteslaconfidencemediumcreated2026-08-07malware-familyinfostealerscriptobfuscationdefense-evasionjavascript
SHA-256: 8c1d87fd44657fef556790d40f427921fe10eddf40f9edd6a58d68687286ea9d

AgentTesla JScript Dropper — PO 012447.JS

SHA-256: 8c1d87fd44657fef556790d40f427921fe10eddf40f9edd6a58d68687286ea9d
Preliminary family: agenttesla
File type: Unicode text, UTF-8 text, with very long lines (1938), with CRLF line terminators (3.2 MB JScript) ^[file.txt]
Original filename: PO 012447.JS
CAPE: skipped — not a supported binary class for detonation ^[dynamic-analysis.md]


1. Executive Summary

A 3.2 MB javascript-obfuscator JScript dropper delivered as a purchase-order lure (PO 012447.JS). The outer script is structurally a twin of the BL DOCUMENTS.JS AgentTesla dropper (387da5ed) observed in this corpus in July 2026: identical javascript-obfuscator build fingerprints, identical dead-code bloat pattern, and identical PowerShell cradle construction via a siderophyre-like accumulator variable. The real payload logic is hidden in a single 2.5 MB line (line 55 of 104) buried inside CJK character noise and repeated marker-token padding. Static analysis confirms the delivery chain; the inner .NET payload is not recoverable without a JS engine.


2. What It Is

  • Language: JScript (Windows Script Host / wscript.exe / cscript.exe)
  • Original name: PO 012447.JS — purchase-order lure consistent with AgentTesla phishing campaigns ^[metadata.json]
  • File size: 3,212,591 bytes — bloated by obfuscation noise and dead code ^[file.txt]
  • Corpus twin: 387da5ed (BL DOCUMENTS.JS) — same obfuscator, same structural pattern, same siderophyre PowerShell cradle variable. ^[/intel/analyses/387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c.html]

3. How It Works

Outer Script Structure

The file is 104 CRLF-separated lines. ^[exiftool.json]

  • Lines 0–54 and 56–103: Uniform this.VMIOCMXABMRWDUZALRZJYJOAVHNKAVC += "..." dead-string concatenation blocks. Each line is ~1,935–1,941 bytes of noise (a repeating Unicode prefix + VMIOCMXABMRWDUZALRZJYJOAVHNKAVC marker tokens + ASCII t pad characters). Never consumed after construction — pure bloat. ^[strings.txt:1]
  • Line 55: A single 2,517,588-byte line containing the real payload interleaved with the same noise tokens and CJK Unicode characters. The ASCII skeleton reveals:
    • var VMIOCMXABMRWDUZALRZJYJOAVHNKAVTT = function(...) — a wrapper around the string-array dispatcher ^[strings.txt extracted via Python]
    • this[_0x19f298(0x181)] += _0x19f298(0xfa) — javascript-obfuscator hex-offset string-array lookups ^[strings.txt extracted via Python]
    • var urlnameoooooooooos = ThreeChars(scriptName) + _0x19f298(0xfb) — filename-based URL generation ^[strings.txt extracted via Python]
    • var urloniaaak = _0x19f298(0x15f) + urlnameoooooooooos — URL assembly ^[strings.txt extracted via Python]
    • siderophyre += _0x19f298(0x12e) — PowerShell cradle string accumulation ^[strings.txt extracted via Python]
    • var OPONIA = _0x19f298(0x17c), erONIA = OPONIA['split']('&')[_0x19f298(0x177)](''), myObject = new ActiveXObject(erONIA) — ActiveXObject instantiation for ADODB.Stream or Scripting.FileSystemObject staging ^[strings.txt extracted via Python]
    • var Bi33ddy = AHONIAKO[_0x19f298(0x122)]('&')['join']('') — string reassembly pattern ^[strings.txt extracted via Python]

Obfuscation Engine

  • Obfuscator: javascript-obfuscator npm package (confirmed by fingerprint)
  • Fingerprint evidence:
    • String-array lookup via _0x19f298(0xNNN) dispatcher with hex offsets
    • Control-flow flattening via while(!![]) + switch dispatch (observed in the 387da5ed twin)
    • Dead-code injection: massive this.VMIOCMXABMRWDUZALRZJYJOAVHNKAVC += ... bloat filling ~2.4 MB of the 3.2 MB file — purely noise, never consumed ^[strings.txt]
    • Debugger trap via Function.prototype.constructor('while(true){}') pattern (observed in twin 387da5ed)

Execution Chain (static reconstruction)

  1. T1566.001 — Phishing: Spearphishing Attachment

    • Filename PO 012447.JS masquerades as a business document. ^[metadata.json]
  2. T1059.005 — Command and Scripting Interpreter: Visual Basic

    • The file is a .JS script executed by wscript.exe or cscript.exe.
  3. T1059.001 — Command and Scripting Interpreter: PowerShell

    • The script builds a PowerShell command string (siderophyre) via obfuscated concatenation, including -Noexit -nop -c and :FromBase64String(...) fragments. ^[strings.txt extracted via Python]
    • The exact Base64 payload and decoded command are not recoverable statically because the payload string is assembled via runtime string-array lookups.
  4. T1105 — Ingress Tool Transfer

    • An ActiveXObject with Open() / Write() methods is instantiated, consistent with ADODB.Stream or Scripting.FileSystemObject used to write a downloaded payload to disk. ^[strings.txt extracted via Python]
    • This strongly suggests the PowerShell stage downloads a secondary payload (likely the AgentTesla .NET assembly) and the JScript then writes it to %TEMP% or similar.

4. Decompiled Behavior

Not applicable — this is a script, not a PE. Ghidra / radare2 were not run. The analysis above was performed via Python string extraction on the UTF-8 source. ^[file.txt] ^[rabin2-info.txt]


5. C2 Infrastructure

Not observed statically. No SMTP credentials, FTP servers, Telegram bot tokens, or HTTP endpoints recovered from this script. The JScript is purely a dropper/loader — C2 lives in the secondary payload.


6. Interesting Tidbits

  • Corpus twin confirmed: This sample is a structural twin of 387da5ed (BL DOCUMENTS.JS) — same javascript-obfuscator build, same siderophyre variable, same noise-bloat pattern, same ActiveXObject staging. The only deltas are the noise token (VMIOCMXABMRWDUZALRZJYJOAVHNKAVC vs RMKTDQTABZJLZWTBXSSBXRKIDGCMMIC) and the filename lure (PO 012447.JS vs BL DOCUMENTS.JS). ^[/intel/analyses/387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c.html]
  • Single-line payload hiding: The real JS logic is compressed into line 55 (2.5 MB), making it the dominant line by two orders of magnitude. Casual inspection of line lengths reveals this instantly.
  • Purchase-order lure: The PO prefix in the filename is a classic AgentTesla social-engineering pattern targeting finance/procurement staff.

7. How To Mess With It (Homelab Replication)

  1. Obfuscator: npm install -g javascript-obfuscator
  2. Create a benign JScript payload that uses WScript.Shell to spawn powershell.exe with a base64-encoded command.
  3. Obfuscate: javascript-obfuscator payload.js --output obfuscated.js --string-array true --control-flow-flattening true --dead-code-injection true --string-array-encoding base64
  4. Add bloat: Append 2–3 MB of this.NOISE += "..." lines with repeated marker tokens to evade size heuristics.
  5. Verification: Run strings obfuscated.js | grep -i powershell — should show nothing. Run in a sandboxed wscript.exe with ProcMon to observe the PowerShell spawn.

8. Deployable Signatures

YARA Rule

rule AgentTesla_JScript_Obfuscator_Dropper
{
    meta:
        description = "AgentTesla JScript dropper with javascript-obfuscator dead-code bloat"
        author = "titus"
        date = "2026-08-07"
        hash = "8c1d87fd44657fef556790d40f427921fe10eddf40f9edd6a58d68687286ea9d"
        hash = "387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c"

    strings:
        $s1 = /this\.[A-Z]{20,40}\s*\+=\s*"/ ascii wide
        $s2 = "_0x19f298(0x" ascii wide
        $s3 = "siderophyre" ascii wide
        $s4 = "ActiveXObject" ascii wide
        $s5 = "while(true){}" ascii wide
        $s6 = "Function.prototype.constructor" ascii wide
        $s7 = /[A-Z]{20,40}N\b/ ascii wide

    condition:
        filesize > 1MB
        and #s1 > 50
        and 3 of ($s2, $s3, $s4, $s5, $s6)
        and uint16(0) != 0x5A4D
}

Sigma Rule

title: AgentTesla JScript Obfuscator Dropper Execution
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains:
      - 'PO '
      - 'DOCUMENTS'
      - 'INVOICE'
      - 'ORDER'
    CommandLine|endswith:
      - '.JS'
      - '.js'
    ParentImage|endswith:
      - '\wscript.exe'
      - '\cscript.exe'
  condition: selection
falsepositives:
  - Legitimate JScript files with business-document names
level: medium

IOC List

Type Value Notes
SHA-256 8c1d87fd44657fef556790d40f427921fe10eddf40f9edd6a58d68687286ea9d Original sample
Filename PO 012447.JS Purchase-order phishing lure
File size 3,212,591 bytes Bloated by obfuscation
Obfuscator javascript-obfuscator npm package fingerprint
Corpus twin 387da5ed...f61c BL DOCUMENTS.JS — same builder

Behavioral Fingerprint

This binary (when executed by wscript.exe or cscript.exe) performs the following observable behaviors: constructs a large string via this.VARNAME += dead-code accumulation (never consumed), resolves strings via a javascript-obfuscator hex-offset dispatcher (_0x19f298(0xNNN)), assembles a PowerShell command line in a variable named siderophyre (including -Noexit -nop -c and FromBase64String fragments), instantiates ActiveXObject with Open()/Write() methods consistent with ADODB.Stream or Scripting.FileSystemObject for payload staging, and spawns powershell.exe to download and execute a secondary payload. The outer script contains no network IOCs; all C2 is runtime-resolved in the PowerShell stage.


9. Detection Signatures (capa→ATT&CK)

Not applicable — capa does not support script files. ^[capa.txt]


10. References

  • Artifact ID: 1d0b26b1-bbd0-40ab-89c5-ce5684be803e ^[metadata.json]
  • Source: OpenCTI / MalwareBazaar
  • Triage family: agenttesla ^[triage.json]
  • Corpus twin: 387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c ^[/intel/analyses/387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c.html]
  • Related wiki pages:

11. Provenance

  • file.txt — file type identification (file v5.44)
  • exiftool.json — metadata (ExifTool 12.76)
  • strings.txt — raw string extraction (GNU strings)
  • metadata.json — OpenCTI artifact metadata
  • triage.json — triage pipeline family assignment
  • dynamic-analysis.md — CAPE sandbox status (skipped)
  • capa.txt — capa error (unsupported file type)
  • Python 3 script — manual UTF-8 decode, line-length analysis, and noise-token stripping to recover ASCII payload skeleton
  • No Ghidra / radare2 performed — sample is a script, not a PE

Report written 2026-08-07. Static analysis only — CAPE skipped due to unsupported file type. Inner payload requires JS engine execution for full recovery.