8c1d87fd44657fef556790d40f427921fe10eddf40f9edd6a58d68687286ea9dAgentTesla JScript Dropper — PO 012447.JS
SHA-256: 8c1d87fd44657fef556790d40f427921fe10eddf40f9edd6a58d68687286ea9d
Preliminary family: agenttesla
File type: Unicode text, UTF-8 text, with very long lines (1938), with CRLF line terminators (3.2 MB JScript) ^[file.txt]
Original filename: PO 012447.JS
CAPE: skipped — not a supported binary class for detonation ^[dynamic-analysis.md]
1. Executive Summary
A 3.2 MB javascript-obfuscator JScript dropper delivered as a purchase-order lure (PO 012447.JS). The outer script is structurally a twin of the BL DOCUMENTS.JS AgentTesla dropper (387da5ed) observed in this corpus in July 2026: identical javascript-obfuscator build fingerprints, identical dead-code bloat pattern, and identical PowerShell cradle construction via a siderophyre-like accumulator variable. The real payload logic is hidden in a single 2.5 MB line (line 55 of 104) buried inside CJK character noise and repeated marker-token padding. Static analysis confirms the delivery chain; the inner .NET payload is not recoverable without a JS engine.
2. What It Is
- Language: JScript (Windows Script Host /
wscript.exe/cscript.exe) - Original name:
PO 012447.JS— purchase-order lure consistent with AgentTesla phishing campaigns ^[metadata.json] - File size: 3,212,591 bytes — bloated by obfuscation noise and dead code ^[file.txt]
- Corpus twin:
387da5ed(BL DOCUMENTS.JS) — same obfuscator, same structural pattern, samesiderophyrePowerShell cradle variable. ^[/intel/analyses/387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c.html]
3. How It Works
Outer Script Structure
The file is 104 CRLF-separated lines. ^[exiftool.json]
- Lines 0–54 and 56–103: Uniform
this.VMIOCMXABMRWDUZALRZJYJOAVHNKAVC += "..."dead-string concatenation blocks. Each line is ~1,935–1,941 bytes of noise (a repeating Unicode prefix +VMIOCMXABMRWDUZALRZJYJOAVHNKAVCmarker tokens + ASCIItpad characters). Never consumed after construction — pure bloat. ^[strings.txt:1] - Line 55: A single 2,517,588-byte line containing the real payload interleaved with the same noise tokens and CJK Unicode characters. The ASCII skeleton reveals:
var VMIOCMXABMRWDUZALRZJYJOAVHNKAVTT = function(...)— a wrapper around the string-array dispatcher ^[strings.txt extracted via Python]this[_0x19f298(0x181)] += _0x19f298(0xfa)—javascript-obfuscatorhex-offset string-array lookups ^[strings.txt extracted via Python]var urlnameoooooooooos = ThreeChars(scriptName) + _0x19f298(0xfb)— filename-based URL generation ^[strings.txt extracted via Python]var urloniaaak = _0x19f298(0x15f) + urlnameoooooooooos— URL assembly ^[strings.txt extracted via Python]siderophyre += _0x19f298(0x12e)— PowerShell cradle string accumulation ^[strings.txt extracted via Python]var OPONIA = _0x19f298(0x17c), erONIA = OPONIA['split']('&')[_0x19f298(0x177)](''), myObject = new ActiveXObject(erONIA)— ActiveXObject instantiation forADODB.StreamorScripting.FileSystemObjectstaging ^[strings.txt extracted via Python]var Bi33ddy = AHONIAKO[_0x19f298(0x122)]('&')['join']('')— string reassembly pattern ^[strings.txt extracted via Python]
Obfuscation Engine
- Obfuscator:
javascript-obfuscatornpm package (confirmed by fingerprint) - Fingerprint evidence:
- String-array lookup via
_0x19f298(0xNNN)dispatcher with hex offsets - Control-flow flattening via
while(!![])+switchdispatch (observed in the387da5edtwin) - Dead-code injection: massive
this.VMIOCMXABMRWDUZALRZJYJOAVHNKAVC += ...bloat filling ~2.4 MB of the 3.2 MB file — purely noise, never consumed ^[strings.txt] - Debugger trap via
Function.prototype.constructor('while(true){}')pattern (observed in twin387da5ed)
- String-array lookup via
Execution Chain (static reconstruction)
-
T1566.001 — Phishing: Spearphishing Attachment
- Filename
PO 012447.JSmasquerades as a business document. ^[metadata.json]
- Filename
-
T1059.005 — Command and Scripting Interpreter: Visual Basic
- The file is a
.JSscript executed bywscript.exeorcscript.exe.
- The file is a
-
T1059.001 — Command and Scripting Interpreter: PowerShell
- The script builds a PowerShell command string (
siderophyre) via obfuscated concatenation, including-Noexit -nop -cand:FromBase64String(...)fragments. ^[strings.txt extracted via Python] - The exact Base64 payload and decoded command are not recoverable statically because the payload string is assembled via runtime string-array lookups.
- The script builds a PowerShell command string (
-
T1105 — Ingress Tool Transfer
- An
ActiveXObjectwithOpen()/Write()methods is instantiated, consistent withADODB.StreamorScripting.FileSystemObjectused to write a downloaded payload to disk. ^[strings.txt extracted via Python] - This strongly suggests the PowerShell stage downloads a secondary payload (likely the AgentTesla .NET assembly) and the JScript then writes it to
%TEMP%or similar.
- An
4. Decompiled Behavior
Not applicable — this is a script, not a PE. Ghidra / radare2 were not run. The analysis above was performed via Python string extraction on the UTF-8 source. ^[file.txt] ^[rabin2-info.txt]
5. C2 Infrastructure
Not observed statically. No SMTP credentials, FTP servers, Telegram bot tokens, or HTTP endpoints recovered from this script. The JScript is purely a dropper/loader — C2 lives in the secondary payload.
6. Interesting Tidbits
- Corpus twin confirmed: This sample is a structural twin of
387da5ed(BL DOCUMENTS.JS) — samejavascript-obfuscatorbuild, samesiderophyrevariable, same noise-bloat pattern, same ActiveXObject staging. The only deltas are the noise token (VMIOCMXABMRWDUZALRZJYJOAVHNKAVCvsRMKTDQTABZJLZWTBXSSBXRKIDGCMMIC) and the filename lure (PO 012447.JSvsBL DOCUMENTS.JS). ^[/intel/analyses/387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c.html] - Single-line payload hiding: The real JS logic is compressed into line 55 (2.5 MB), making it the dominant line by two orders of magnitude. Casual inspection of line lengths reveals this instantly.
- Purchase-order lure: The
POprefix in the filename is a classic AgentTesla social-engineering pattern targeting finance/procurement staff.
7. How To Mess With It (Homelab Replication)
- Obfuscator:
npm install -g javascript-obfuscator - Create a benign JScript payload that uses
WScript.Shellto spawnpowershell.exewith a base64-encoded command. - Obfuscate:
javascript-obfuscator payload.js --output obfuscated.js --string-array true --control-flow-flattening true --dead-code-injection true --string-array-encoding base64 - Add bloat: Append 2–3 MB of
this.NOISE += "..."lines with repeated marker tokens to evade size heuristics. - Verification: Run
strings obfuscated.js | grep -i powershell— should show nothing. Run in a sandboxedwscript.exewith ProcMon to observe the PowerShell spawn.
8. Deployable Signatures
YARA Rule
rule AgentTesla_JScript_Obfuscator_Dropper
{
meta:
description = "AgentTesla JScript dropper with javascript-obfuscator dead-code bloat"
author = "titus"
date = "2026-08-07"
hash = "8c1d87fd44657fef556790d40f427921fe10eddf40f9edd6a58d68687286ea9d"
hash = "387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c"
strings:
$s1 = /this\.[A-Z]{20,40}\s*\+=\s*"/ ascii wide
$s2 = "_0x19f298(0x" ascii wide
$s3 = "siderophyre" ascii wide
$s4 = "ActiveXObject" ascii wide
$s5 = "while(true){}" ascii wide
$s6 = "Function.prototype.constructor" ascii wide
$s7 = /[A-Z]{20,40}N\b/ ascii wide
condition:
filesize > 1MB
and #s1 > 50
and 3 of ($s2, $s3, $s4, $s5, $s6)
and uint16(0) != 0x5A4D
}
Sigma Rule
title: AgentTesla JScript Obfuscator Dropper Execution
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- 'PO '
- 'DOCUMENTS'
- 'INVOICE'
- 'ORDER'
CommandLine|endswith:
- '.JS'
- '.js'
ParentImage|endswith:
- '\wscript.exe'
- '\cscript.exe'
condition: selection
falsepositives:
- Legitimate JScript files with business-document names
level: medium
IOC List
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 8c1d87fd44657fef556790d40f427921fe10eddf40f9edd6a58d68687286ea9d |
Original sample |
| Filename | PO 012447.JS |
Purchase-order phishing lure |
| File size | 3,212,591 bytes | Bloated by obfuscation |
| Obfuscator | javascript-obfuscator |
npm package fingerprint |
| Corpus twin | 387da5ed...f61c |
BL DOCUMENTS.JS — same builder |
Behavioral Fingerprint
This binary (when executed by wscript.exe or cscript.exe) performs the following observable behaviors: constructs a large string via this.VARNAME += dead-code accumulation (never consumed), resolves strings via a javascript-obfuscator hex-offset dispatcher (_0x19f298(0xNNN)), assembles a PowerShell command line in a variable named siderophyre (including -Noexit -nop -c and FromBase64String fragments), instantiates ActiveXObject with Open()/Write() methods consistent with ADODB.Stream or Scripting.FileSystemObject for payload staging, and spawns powershell.exe to download and execute a secondary payload. The outer script contains no network IOCs; all C2 is runtime-resolved in the PowerShell stage.
9. Detection Signatures (capa→ATT&CK)
Not applicable — capa does not support script files. ^[capa.txt]
10. References
- Artifact ID:
1d0b26b1-bbd0-40ab-89c5-ce5684be803e^[metadata.json] - Source: OpenCTI / MalwareBazaar
- Triage family:
agenttesla^[triage.json] - Corpus twin:
387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c^[/intel/analyses/387da5edf39457b69f654637feb52e35be921ce99e7b5f39ebdbcaf77637f61c.html] - Related wiki pages:
- agenttesla — entity page
- javascript-obfuscator — concept page
- js-cff-string-array-obfuscation — technique page
11. Provenance
file.txt— file type identification (file v5.44)exiftool.json— metadata (ExifTool 12.76)strings.txt— raw string extraction (GNU strings)metadata.json— OpenCTI artifact metadatatriage.json— triage pipeline family assignmentdynamic-analysis.md— CAPE sandbox status (skipped)capa.txt— capa error (unsupported file type)- Python 3 script — manual UTF-8 decode, line-length analysis, and noise-token stripping to recover ASCII payload skeleton
- No Ghidra / radare2 performed — sample is a script, not a PE
Report written 2026-08-07. Static analysis only — CAPE skipped due to unsupported file type. Inner payload requires JS engine execution for full recovery.