typeanalysisfamilyunclassified-js-bitbucket-stego-dropperconfidencehighcreated2026-07-30updated2026-07-30scriptmalware-familyloaderobfuscationc2defense-evasionmitre-attck
SHA-256: a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6c

unclassified-js-bitbucket-stego-dropper: a09e7790 — second confirmed sibling, new Bitbucket repo and GitHub Raw C2

Executive Summary

Second confirmed sibling of the JScript Bitbucket stego-dropper family. Same builder template as 56ea37ef (fixed-delimiter concat obfuscation, WMI hidden-process spawn, PowerShell image-steganography loader, reflective .NET assembly load), but with a fresh noise token (rFcogaamkkmfcg), a new Bitbucket repository (mywtestwusbect/hfghfgdfgdfg), a new paste.sensio.no fallback (GeeksItalians), and a GitHub Raw URL (ultrarenewrecargado-alt/DATESIMPORT) passed to the runss method instead of the lerdeen.life endpoint seen in the first sample. ^[file.txt]

What It Is

  • SHA-256: a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6c
  • Filename: a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6c.js (numeric hash filename, no document lure)
  • Size: 80,057 bytes ^[triage.json]
  • Type: Plaintext JScript (Windows Script Host compatible) ^[file.txt]
  • Obfuscation: Custom fixed-delimiter string concatenation with a 14-character noise token
  • Packaging: None
  • Signing: None
  • Family: Confirmed sibling of unclassified-js-bitbucket-stego-dropper (56ea37ef). Same builder, different campaign configuration.

How It Works

1. JScript Launcher — Fixed-Delimiter Concatenation Obfuscation

The script consists of 2,220+ lines of bSfmngdb += "..." concatenations. Each line interleaves payload characters with the noise token rFcogaamkkmfcg. At the final line, the noise is stripped via bSfmngdb.replace(/rFcogaamkkmfcg/g, ""). ^[strings.txt:1]

The cleaned string reveals a PowerShell command that:

  • Defines a $ddsfdfdjhsdfgdgo variable containing a Base64 blob
  • Replaces f# with r (character-substitution anti-signature step)
  • Decodes via UTF-16 LE and executes via iex ^[strings.txt:2220]

2. PowerShell Stage — Image-Steganography Loader

The decoded PowerShell (6,682 chars cleaned) performs the following:

  • Sets TLS 1.2 ([Net.SecurityProtocolType]::Tls12)
  • Defines DownloadDataFromLinks: shuffles an array of URLs, attempts each until one succeeds, returns raw byte array
  • Two hardcoded payload URLs:
    • https://bitbucket.org/mywtestwusbect/hfghfgdfgdfg/downloads/3.jpg ^[decoded payload]
    • https://paste.sensio.no/GeeksItalians ^[decoded payload]
  • Searches downloaded image/text for <<START>> and <<END>> markers, extracts Base64 payload between them
  • Decodes payload to byte array and loads via [System.Reflection.Assembly]::Load($commandBytes) ^[decoded payload]
  • Retrieves type myprogram.Homees and invokes method runss (runs + s concatenation) ^[decoded payload]
  • Passes a reversed URL string that decodes to https://raw.githubusercontent.com/ultrarenewrecargado-alt/DATESIMPORT/refs/heads/main/SpmSdkd.txt ^[decoded payload]

3. WMI Hidden Process Spawn

The JScript launcher uses GetObject("winmgmts:root\\cimv2") to create a Win32_ProcessStartup instance with ShowWindow = 0 (hidden window), then spawns the PowerShell via Win32_Process.Create. A Scripting.Dictionary object collects the out-parameters (process ID, return status). ^[strings.txt:2222]

Decompiled Behavior

Not applicable — plaintext script, not a compiled binary. No PE surface. The obfuscation is purely string-level.

C2 Infrastructure

  • Stage 1 URLs (payload staging):
    • https://bitbucket[.]org/mywtestwusbect/hfghfgdfgdfg/downloads/3.jpg (image-steganography carrier) ^[decoded payload]
    • https://paste.sensio[.]no/GeeksItalians (fallback text carrier) ^[decoded payload]
  • Final C2 endpoint (passed to .NET assembly):
    • https://raw.githubusercontent[.]com/ultrarenewrecargado-alt/DATESIMPORT/refs/heads/main/SpmSdkd.txt (reversal layer applied) ^[decoded payload]
  • No mutex names, named pipes, or hardcoded registry keys recovered statically.

Interesting Tidbits

  • The noise token changed from bngbimfrhIbkmi (13 chars, 56ea37ef) to rFcogaamkkmfcg (14 chars, this sample), confirming the builder randomizes the delimiter per campaign while keeping the template identical. ^[strings.txt:1]
  • The Bitbucket repository name mywtestwusbect matches the OpenCTI family label bitbucket-org-mywtestwusbect, confirming this repo is the family namesake. ^[triage.json]
  • The f#→r base64 substitution persists across siblings — a deliberate anti-signature step that breaks naive base64 regex extraction. ^[strings.txt:2220]
  • The dead-code functions phantomSgfdghift and quantumRipple are byte-identical to the first sibling, confirming they are part of the builder template, not hand-crafted per sample. ^[strings.txt:2221]
  • The PowerShell includes the same Get-Process | Sort-Object CPU -Descending | Select-Object -First 5 | Format-Table Name,CPU no-op delay before and after the assembly load — a timing/anti-emulation fingerprint. ^[decoded payload]
  • The runss method name is still constructed at runtime via runs + s, and the injector argument is still Msbuild — both are builder constants. ^[decoded payload]
  • The GitHub Raw URL (ultrarenewrecargado-alt/DATESIMPORT) uses a Spanish username (ultrarenewrecargado-alt = "ultra renew recharged") and an English word-salad repo name (DATESIMPORT), suggesting Latin American or Spanish-speaking operator. ^[decoded payload]

How To Mess With It (Homelab Replication)

See unclassified-js-bitbucket-stego-dropper for the full builder-template replication notes. The delta for this sample is:

  • Noise token: rFcogaamkkmfcg (14 chars)
  • Variable name: bSfmngdb
  • Payload URLs: update to bitbucket.org/mywtestwusbect/hfghfgdfgdfg/downloads/3.jpg and paste.sensio.no/GeeksItalians
  • Reversed URL: txt.dkdSmpS/niam/sdaeh/sfer/TROPMISETAD/tla-odagracerwenerartlu/moc.tnetnocresubuhtig.war//:sgsgdfffsfd (trim last 10 chars, then reverse)

Deployable Signatures

YARA Rule

rule unclassified_js_bitbucket_stego_dropper_sibling_a09e7790 {
    meta:
        description = "JScript fixed-delimiter concat obfuscation with WMI hidden process spawn (sibling a09e7790)"
        author = "PacketPursuit"
        date = "2026-07-30"
        sha256 = "a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6c"
    strings:
        $s1 = "bSfmngdb += \"" ascii wide
        $s2 = /rFcogaamkkmfcg/ ascii wide
        $s3 = "GetObject(\"winmgmt" ascii wide
        $s4 = "Win32_Process" ascii wide
        $s5 = "ShowWindow =" ascii wide
        $s6 = "<<START>>" ascii wide
        $s7 = "<<END>>" ascii wide
        $s8 = "bitbucket.org/mywtestwusbect/hfghfgdfgdfg/downloads/3.jpg" ascii wide
        $s9 = "paste.sensio.no/GeeksItalians" ascii wide
    condition:
        filesize < 200KB and
        3 of ($s*) and
        #s1 > 500
}

Behavioral Hunt Query

process_creation:
  CommandLine|contains:
    - 'winmgmts'
    - 'Win32_ProcessStartup'
    - 'ShowWindow = 0'
    - 'bitbucket.org/mywtestwusbect'
    - 'paste.sensio.no/GeeksItalians'
    - 'ultrarenewrecargado-alt/DATESIMPORT'

IOC List

Indicator Type Context
a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6c SHA-256 JScript dropper
rFcogaamkkmfcg String Noise delimiter token
bitbucket.org/mywtestwusbect/hfghfgdfgdfg/downloads/3.jpg URL Image-steganography carrier
paste.sensio.no/GeeksItalians URL Fallback payload carrier
raw.githubusercontent.com/ultrarenewrecargado-alt/DATESIMPORT/refs/heads/main/SpmSdkd.txt URL Final C2 endpoint
myprogram.Homees .NET Type Reflectively loaded assembly
runss Method C2 beacon method (runtime concatenated)
phantomSgfdghift Function Dead-code builder template fingerprint
quantumRipple Function Dead-code builder template fingerprint

Behavioral Fingerprint Statement

This JScript dropper hides a PowerShell payload inside over 2,000 lines of += string-concatenation statements interleaved with a fixed 14-character noise token. The noise is stripped at runtime via String.replace(regex, ""), revealing a UTF-16LE Base64-encoded PowerShell command with an f#→r character substitution anti-signature step. The PowerShell sets TLS 1.2, defines a shuffled URL downloader, fetches an image or text file from Bitbucket and paste.sensio.no, searches for <<START>>/<<END>> markers, extracts a Base64 .NET assembly, reflectively loads it via [System.Reflection.Assembly]::Load, and invokes the myprogram.Homees type's runss method with a reversed GitHub Raw URL. Execution is launched through WMI Win32_Process.Create with ShowWindow = 0 to hide the PowerShell window. Two no-op Get-Process | Sort-Object CPU statements bracket the assembly load as an anti-emulation delay. Dead-code functions phantomSgfdghift and quantumRipple pad the script but are never called.

Detection Signatures

  • MITRE ATT&CK T1059.005: Visual Basic (JScript variant) execution via Windows Script Host
  • MITRE ATT&CK T1059.001: PowerShell execution via embedded Base64
  • MITRE ATT&CK T1027.001: Obfuscated files or information — noise-token padding
  • MITRE ATT&CK T1564.003: Hide Artifacts — hidden window process spawn via WMI
  • MITRE ATT&CK T1105: Ingress Tool Transfer — download from remote URLs
  • MITRE ATT&CK T1071.001: Application Layer Protocol — HTTPS C2
  • MITRE ATT&CK T1620: Reflective Code Loading — .NET assembly loaded in-memory
  • MITRE ATT&CK T1127.001: Trusted Developer Utilities — Msbuild string passed to method

References

Provenance

  • file.txt — file utility output (ASCII text) ^[file.txt]
  • strings.txt — raw strings extracted via strings -n 6 ^[strings.txt]
  • exiftool.json — ExifTool metadata (TXT, 80KB, 2,243 lines) ^[exiftool.json]
  • triage.json — triage pipeline classification (family=bitbucketorgmywtestwusbect, tier=deep) ^[triage.json]
  • Decoded payload — manual extraction via Python regex + base64 + UTF-16-LE decode
  • dynamic-analysis.md — CAPE skipped (ASCII text, non-binary class) ^[dynamic-analysis.md]

^(/intel/analyses/a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6c.html)