8e95d2b8eb47464ea0c75b9201f204843bf03e33fbb31510d3c7bed43fdb6c09unclassified-js-noise-base64-eval-dropper: 8e95d2b8 — second confirmed sibling
A 1.03 MB JScript dropper that is a confirmed sibling of the unclassified-js-noise-base64-eval-dropper family. It uses the same three-layer architecture as c83b7d57: a massive repetitive noise string, 62 sequential variable-reassignment extractions, and Function constructor execution. The noise string, variable name, keys, and payload are all unique, confirming active builder reuse. Static-only inference (JScript, not a binary).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 8e95d2b8eb47464ea0c75b9201f204843bf03e33fbb31510d3c7bed43fdb6c09 ^[file.txt] |
| Filename | 506186558822435.js ^[triage.json] |
| Size | 1,035,615 bytes ^[triage.json] |
| Type | ASCII text, with very long lines (65536), with no line terminators ^[file.txt] |
| Family | unclassified-js-noise-base64-eval-dropper — second confirmed sibling (see c83b7d57 for first) |
| Attribution | None. No language clues, no infrastructure overlap. |
| Dynamic | Skipped — CAPE does not detonate script files ^[dynamic-analysis.md] |
Build / RE — Obfuscation Architecture
Same three-layer architecture as sibling c83b7d57; every layer parameterised differently.
Layer 1: Noise Padding
The script consists of a 2,292-byte base noise string (xktfcui...gusty) that is repeated 196 times throughout the file, interleaved with 62 assignment statements. No random filler insertions between blocks — the noise string is concatenated directly with each assignment. The variable name itself is the noise string (2292 characters), making the total noise-to-signal ratio even higher than c83b7d57. ^[strings.txt:1]
File composition:
- Base noise string: 2,292 bytes × 196 occurrences = ~449 KB of raw noise
- 62 assignment statements: ~5,600 bytes of actual payload-extraction logic
- Terminal
Functionwrapper: ~50 bytes - Total: 1,035,615 bytes
Layer 2: Sequential Variable Reassignment (62 statements)
The 2292-character noise string doubles as the variable name. At offset 2296, immediately after the first noise block, the script declares:
xktfcui...gusty=[];
It then issues 62 statements of the form:
xktfcui...gusty['<random-key>']='<char>';
Each key is a 2,700–4,000 character random lowercase alphabetic string. Each value is a single ASCII character. The 62 extracted characters, in order, are:
BpiUQ3RLvTcAuGNlSP5XKZME4fdVO7tCyDFxwj60m1H8nbJYorsah9g2eIzWqk
This is the payload string passed to Function(). ^[strings.txt:1]
Layer 3: Function Constructor Execution
At offset 335,437, the single execution point:
Function(''+xktfcui...gusty['<key1>']+xktfcui...gusty['<key2>']+...+ '',0,false);
The payload is a 62-character base64-like string. Decoding with == padding produces 46 bytes of binary data (06 98 94 43...) — likely compressed or encrypted shellcode / JScript / PowerShell, not directly readable. ^[strings.txt:1]
Sibling Delta: c83b7d57 vs 8e95d2b8
| Feature | c83b7d57 (first) | 8e95d2b8 (second) |
|---|---|---|
| Noise string length | 2,411 bytes | 2,292 bytes |
| Variable name | yielding (9 chars) |
Noise string itself (2,292 chars) |
| Noise occurrences | 196 | 196 |
| Assignments | 62 | 62 |
| Extracted payload | 15ixh8uRw9o3EdAtLlmSUabFcfn67sPqJZvQTyIG0WNpBe2OrMHgkzDC4jXYVK (62 chars) |
BpiUQ3RLvTcAuGNlSP5XKZME4fdVO7tCyDFxwj60m1H8nbJYorsah9g2eIzWqk (62 chars) |
| Key lengths | 50–120 chars | 2,700–4,000 chars |
| Random filler between blocks | Yes (~60–500 bytes) | No (direct concatenation) |
| Noise-to-signal ratio | ~17,600:1 | ~16,700:1 |
The extreme key lengths in 8e95d2b8 (up to 4,000 characters) represent an evolution in the builder, increasing static-analysis friction by a factor of ~30–80 compared to c83b7d57. ^[strings.txt:1]
Deploy / ATT&CK
| TTP | Evidence | Confidence |
|---|---|---|
| T1059.007 — JavaScript/JScript | File extension .js, Function constructor execution |
High |
| T1027 — Obfuscated Files or Information | 1.03 MB noise padding, 196× repeated 2,292-byte string, 62 sequential reassignments, 2,700–4,000 char keys | High |
| T1059.001 — PowerShell (inferred) | Typical JScript dropper chain; payload string is base64-like | Medium |
| T1105 — Ingress Tool Transfer (inferred) | Payload logic likely downloads second stage; no C2 recovered statically | Low |
C2 Infrastructure
No C2 indicators recovered statically. The payload string decodes to 46 bytes of non-printable binary, suggesting an encrypted or compressed inner stage. No hardcoded IPs, domains, URLs, mutexes, or file paths appear in the noise layer. ^[strings.txt:1]
Interesting Tidbits
- Numeric filename only:
506186558822435.js— no social-engineering lure, stage-2/3 delivery assumed. ^[triage.json] - Variable name = noise string: The builder reuses the noise string itself as the variable name, a novel anti-pattern that defeats signature-based detection looking for a small variable name followed by
=[];. ^[strings.txt:1] - Extreme key lengths: Keys are 2,700–4,000 characters — 30–80× longer than
c83b7d57— making manual string extraction impractical without scripting. ^[strings.txt:1] - No random filler: Unlike
c83b7d57, noise blocks are concatenated directly with assignments, producing a cleaner but still high-entropy file. ^[strings.txt:1] - Builder evolution: The shared architecture (196 noise blocks, 62 assignments,
Functionwrapper) with different parameters confirms an active builder, not a one-off manual obfuscation. ^[strings.txt:1] - Same payload size: Both siblings extract exactly 62 characters — this may be a fixed builder parameter or a coincidence. ^[strings.txt:1]
- Single
Functionkeyword: Only one execution point, at offset 335,437. Only oneeval-equivalent. ^[strings.txt:1]
How To Mess With It (Homelab Replication)
Same recipe as sibling c83b7d57, with two builder-evolution notes:
- Toolchain: Any text editor + Python 3.
- Generate noise: Create a 2,000–3,000 byte random lowercase string.
- Use noise as variable name: Set the variable name equal to the noise string itself.
- Encode payload: Base64-encode your real JScript payload.
- Generate extreme keys: For each character, generate a random 2,500–4,000 character key.
- Build carrier (no filler):
<noise_string>varname=[]; <noise_string>varname['extreme_key1']='c1'; <noise_string>varname['extreme_key2']='c2'; ... Function(''+varname['extreme_key1']+varname['extreme_key2']+...+ '',0,false); - Verification: Save as
.js.fileshould report "ASCII text, with very long lines".stringsshould show only noise.
Deployable Signatures
YARA Rule
rule JS_Noise_Base64_Eval_Dropper_v2 {
meta:
description = "JScript dropper with massive repetitive noise padding and sequential property-assignment payload extraction (v2 — extreme keys)"
author = "PacketPursuit"
date = "2026-07-24"
sha256 = "8e95d2b8eb47464ea0c75b9201f204843bf03e33fbb31510d3c7bed43fdb6c09"
strings:
$noise_prefix = "xktfcuinixpcqfknzxuapccbwphdzmqcjfmwklorysajlpjkbsclrckggtlinmtenygtvesrnsyanusltiqyolxsyqczjcezqiccbkannubdtspeohwrlyookqjowwzifzzziltecnllschtxdnatrwhakeawjsmeryoarkurwzyyuqggbltjwioqhscgrfdqhifekzfublfmxwhvllivasmoviyemhecfdcidovipxeyzruhpesteiheidyxihmpcztiwtsrmbpsbezgruoamlzmrbwtlrrrawdlvjtnmcrlnuzblwmifpfsaisfsnsrutrdnoptbgqmymgocjswmccogxlbvwlswdamwqfjlznxdogpdxodtykzorpvkagyqxgnjmtwhpqzkdferisyaodigxlcihssprqefkclukiniymkbfvppbbyugrfpyohzqgrszxslapdgqluojdnbtqxmjbsuassibvcysgjiuxdifomnvrraoojufprnrreukntfrnyxecifairsefmaatxwwiqewoiizlqhwxdydghovvwuauoucrmoofmxokosvehhprvfrtwnvicgwtkrfbvuflmbsslxuxnvzzwnwunnqdkbfmalxeqlnpxosgexmsdzvejydjhcxdduvqywntyrggjcucnrmenpfmxngujhfcxzknxnawkiymyfyyykxdfefsikixvfqfchssaomlnhsrbzbhpgpmafmtvriricorptolqukgcfaemxhkjppwnohbleheyyahxypyzsyhucaydqndwsqmelrrboddutyvmmcknzltntuontldsyilpvkbumvwukonxqgtoxoaxngeehbwjizfujxzfzygcbkpnlrjlgliwtmkhvweilskjpmnvhrldwgtfitnfdaxwwyxeezglsnngyksakungcgsgoxxkvmgwfulyczqbazpotukmjwvvfepuecontmnmznlzxnjvpwtoganigkaeqqrnvtwxndwzxfckpspumsceranlpothwipuxgeupcjgalrzrgteotduhtitdljqvqxhdqbsbzpognjfxttcwtbcxulhxtyegzewvqkvxiadoknjbobfkasfuadrxvzxqbjubfbskniwcudozvpyidqqltqdljdxduxpezyrimckdqnsdlggitcubiebyrttlxfmhicxfvwmhvzcleqyeomoutbvqviwwangiolcfqmshhjfhymcksjazaqlkwvftkvtrvrgxeevxsfubbgjjyenakusopicrpyerdyxkhzmbnmsrriobibrnkovqmspdfxzlekgskwcyivhelcwmexdyagzmsabpryhieociyjaasktuiweqgcqumqsmtruhndbzhftscurxlxhmrvggqstveffzkiakgwkkrbumiomajznevxhosoqxzgonpkpbsyjhvcshcbqpeproltoqldgjlrnveixbifuctkieluoehrigftzyrodyvhtdnsckhukvwpywypobcxnrcuaqituofcnvoadtbgziryiiwmiwjiqnoukyxhnlnuutvrgzprcystwyznnekrpgucmlhqkusfhaukwpqovdlvozxhrjfacwfuruypjfdgmzwwvbdqsiheusbuwjninpsiurongexlohftnrqzxtljffuixwtjeoutkwlqgoviuasooxvuqtfqygysehyjyefhlvnzoebbzwjlgktwhstscafflvacgwpxcimrwtmmvypimycukoixsbudhvddgvnfzrereegomtahmrixneuyeqtaewrgkebaimkysdpdrpvfeogcawnerjcuqcwtvrtzxdsaenabviynsmfhysmrjgufcpjgbusjtpsrwcftbwsevpshylxjrrqsynggmrdcuthjhyqpcywcwtpwwnjzidbqixdghpjdmksykomvzzoxvhwdboslagyyqlipgnxeyrnuumicxexhufejwvqjcpsrdemunatxxxoelzpnhmrwheaokpbnxhcanjzlnuccabkepbijwteubxcnesiqvhhqpymkoabqmuzhmqozskrcravkhlucgezadmbpvtjsvcliuhduxnunxpchzmfdjkifchapkjjcnyjxvocdcywkhwajyrplnqsrfdsqyuirzqcqtuielbqjxqlcuqfygajashsamdlmsfxkudizehnnwghpqpojbcxpedrwyehiquwzagxlvztrhcnkffdpvknzkjvgvylywfpzhegbggxwarmgusty"
$func = "Function(''" nocase
$payload_prefix = "BpiUQ3RLvTcAuGNlSP5XKZME4fdVO7tCyDFxwj60m1H8nbJYorsah9g2eIzWqk"
condition:
filesize > 500KB and
$func and
(#noise_prefix > 50 or $payload_prefix)
}
Behavioral Hunt Query (KQL / Sentinel)
let NoiseThreshold = 500000; // bytes
DeviceFileEvents
| where FileName endswith ".js"
| where FileSize > NoiseThreshold
| join kind=inner (
DeviceProcessEvents
| where InitiatingProcessFileName in~ ("wscript.exe", "cscript.exe")
| where ProcessCommandLine contains ".js"
) on $left.DeviceId == $right.DeviceId and $left.Timestamp == $right.Timestamp
| project Timestamp, DeviceName, FileName, FileSize, ProcessCommandLine, AccountName
IOC List
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 8e95d2b8eb47464ea0c75b9201f204843bf03e33fbb31510d3c7bed43fdb6c09 |
|
| Filename | 506186558822435.js |
Numeric only — stage-2/3 delivery |
| Noise fingerprint | xktfcui...gusty (2,292 bytes) |
Repeats 196× — cluster signature |
| Payload | BpiUQ3RLvTcAuGNlSP5XKZME4fdVO7tCyDFxwj60m1H8nbJYorsah9g2eIzWqk |
62-char base64-like string |
| ssdeep | 24576:+JICtkCOTqWsAW2pux1CWGWfWfWfWtCrCrCSG1CWGWfWfWfWtCrCrCZEWw1sBP:H8ZrP |
^[ssdeep.txt] |
| TLSH | 0C25AED9D25B2DFD7B34C8CE49EA0711C8593B382821CDB4F58F2647438E6BCE266A45 |
^[tlsh.txt] |
| YARA | None | ^[yara.txt] |
Behavioral Fingerprint
This script is a 1.03 MB single-line JScript file containing a 2,292-byte base noise string repeated 196 times with no filler between blocks. The noise string doubles as the variable name. After the first block, the variable is declared as an empty array (varname=[];), followed by 62 sequential varname['<extreme-key>']='<char>'; statements. Keys are 2,700–4,000 characters long. The extracted 62-character payload is passed to Function(''+varname['key1']+...+ '',0,false) for execution. The inner payload decodes from base64-like format to 46 bytes of binary data; its content is not visible statically. No C2, no persistence mechanism, and no anti-analysis checks are recoverable without runtime execution.
Detection Signatures
- capa: Not applicable — script file, not a supported binary format. ^[capa.txt]
- floss: Not applicable — script file, not a supported binary format. ^[floss.txt]
- binwalk: No embedded artefacts found. ^[binwalk.txt]
- rabin2:
bits: 0,havecode: false— confirms non-executable file type. ^[rabin2-info.txt]
References
- Artifact ID:
ac3629e4-dca6-4811-8a63-11686d887554^[metadata.json] - Source: OpenCTI / MalwareBazaar (abuse.ch) ^[triage.json]
- Related wiki pages: unclassified-js-noise-base64-eval-dropper, js-noise-payload-reassignment-eval, unattributed
Provenance
file.txt—fileutility on ASCII textstrings.txt—stringson single-line 1.03 MB filetriage.json— OpenCTI connector metadatametadata.json— artifact metadatassdeep.txt— ssdeep 1.1tlsh.txt— TLSH hashcapa.txt— Mandiant capa (unsupported file type error)floss.txt— FireEye flare-floss (argument error, unsupported)rabin2-info.txt— radare2rabin2 -I(bits:0, havecode:false)binwalk.txt— ReFirmLabs binwalk (no signatures)dynamic-analysis.md— CAPE skipped (script file, not binary)- Manual Python 3 deobfuscation and structural analysis