a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6cunclassified-js-bitbucket-stego-dropper: a09e7790 — second confirmed sibling, new Bitbucket repo and GitHub Raw C2
Executive Summary
Second confirmed sibling of the JScript Bitbucket stego-dropper family. Same builder template as 56ea37ef (fixed-delimiter concat obfuscation, WMI hidden-process spawn, PowerShell image-steganography loader, reflective .NET assembly load), but with a fresh noise token (rFcogaamkkmfcg), a new Bitbucket repository (mywtestwusbect/hfghfgdfgdfg), a new paste.sensio.no fallback (GeeksItalians), and a GitHub Raw URL (ultrarenewrecargado-alt/DATESIMPORT) passed to the runss method instead of the lerdeen.life endpoint seen in the first sample. ^[file.txt]
What It Is
- SHA-256:
a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6c - Filename:
a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6c.js(numeric hash filename, no document lure) - Size: 80,057 bytes ^[triage.json]
- Type: Plaintext JScript (Windows Script Host compatible) ^[file.txt]
- Obfuscation: Custom fixed-delimiter string concatenation with a 14-character noise token
- Packaging: None
- Signing: None
- Family: Confirmed sibling of unclassified-js-bitbucket-stego-dropper (
56ea37ef). Same builder, different campaign configuration.
How It Works
1. JScript Launcher — Fixed-Delimiter Concatenation Obfuscation
The script consists of 2,220+ lines of bSfmngdb += "..." concatenations. Each line interleaves payload characters with the noise token rFcogaamkkmfcg. At the final line, the noise is stripped via bSfmngdb.replace(/rFcogaamkkmfcg/g, ""). ^[strings.txt:1]
The cleaned string reveals a PowerShell command that:
- Defines a
$ddsfdfdjhsdfgdgovariable containing a Base64 blob - Replaces
f#withr(character-substitution anti-signature step) - Decodes via UTF-16 LE and executes via
iex^[strings.txt:2220]
2. PowerShell Stage — Image-Steganography Loader
The decoded PowerShell (6,682 chars cleaned) performs the following:
- Sets TLS 1.2 (
[Net.SecurityProtocolType]::Tls12) - Defines
DownloadDataFromLinks: shuffles an array of URLs, attempts each until one succeeds, returns raw byte array - Two hardcoded payload URLs:
https://bitbucket.org/mywtestwusbect/hfghfgdfgdfg/downloads/3.jpg^[decoded payload]https://paste.sensio.no/GeeksItalians^[decoded payload]
- Searches downloaded image/text for
<<START>>and<<END>>markers, extracts Base64 payload between them - Decodes payload to byte array and loads via
[System.Reflection.Assembly]::Load($commandBytes)^[decoded payload] - Retrieves type
myprogram.Homeesand invokes methodrunss(runs+sconcatenation) ^[decoded payload] - Passes a reversed URL string that decodes to
https://raw.githubusercontent.com/ultrarenewrecargado-alt/DATESIMPORT/refs/heads/main/SpmSdkd.txt^[decoded payload]
3. WMI Hidden Process Spawn
The JScript launcher uses GetObject("winmgmts:root\\cimv2") to create a Win32_ProcessStartup instance with ShowWindow = 0 (hidden window), then spawns the PowerShell via Win32_Process.Create. A Scripting.Dictionary object collects the out-parameters (process ID, return status). ^[strings.txt:2222]
Decompiled Behavior
Not applicable — plaintext script, not a compiled binary. No PE surface. The obfuscation is purely string-level.
C2 Infrastructure
- Stage 1 URLs (payload staging):
https://bitbucket[.]org/mywtestwusbect/hfghfgdfgdfg/downloads/3.jpg(image-steganography carrier) ^[decoded payload]https://paste.sensio[.]no/GeeksItalians(fallback text carrier) ^[decoded payload]
- Final C2 endpoint (passed to .NET assembly):
https://raw.githubusercontent[.]com/ultrarenewrecargado-alt/DATESIMPORT/refs/heads/main/SpmSdkd.txt(reversal layer applied) ^[decoded payload]
- No mutex names, named pipes, or hardcoded registry keys recovered statically.
Interesting Tidbits
- The noise token changed from
bngbimfrhIbkmi(13 chars,56ea37ef) torFcogaamkkmfcg(14 chars, this sample), confirming the builder randomizes the delimiter per campaign while keeping the template identical. ^[strings.txt:1] - The Bitbucket repository name
mywtestwusbectmatches the OpenCTI family labelbitbucket-org-mywtestwusbect, confirming this repo is the family namesake. ^[triage.json] - The
f#→rbase64 substitution persists across siblings — a deliberate anti-signature step that breaks naive base64 regex extraction. ^[strings.txt:2220] - The dead-code functions
phantomSgfdghiftandquantumRippleare byte-identical to the first sibling, confirming they are part of the builder template, not hand-crafted per sample. ^[strings.txt:2221] - The PowerShell includes the same
Get-Process | Sort-Object CPU -Descending | Select-Object -First 5 | Format-Table Name,CPUno-op delay before and after the assembly load — a timing/anti-emulation fingerprint. ^[decoded payload] - The
runssmethod name is still constructed at runtime viaruns+s, and the injector argument is stillMsbuild— both are builder constants. ^[decoded payload] - The GitHub Raw URL (
ultrarenewrecargado-alt/DATESIMPORT) uses a Spanish username (ultrarenewrecargado-alt= "ultra renew recharged") and an English word-salad repo name (DATESIMPORT), suggesting Latin American or Spanish-speaking operator. ^[decoded payload]
How To Mess With It (Homelab Replication)
See unclassified-js-bitbucket-stego-dropper for the full builder-template replication notes. The delta for this sample is:
- Noise token:
rFcogaamkkmfcg(14 chars) - Variable name:
bSfmngdb - Payload URLs: update to
bitbucket.org/mywtestwusbect/hfghfgdfgdfg/downloads/3.jpgandpaste.sensio.no/GeeksItalians - Reversed URL:
txt.dkdSmpS/niam/sdaeh/sfer/TROPMISETAD/tla-odagracerwenerartlu/moc.tnetnocresubuhtig.war//:sgsgdfffsfd(trim last 10 chars, then reverse)
Deployable Signatures
YARA Rule
rule unclassified_js_bitbucket_stego_dropper_sibling_a09e7790 {
meta:
description = "JScript fixed-delimiter concat obfuscation with WMI hidden process spawn (sibling a09e7790)"
author = "PacketPursuit"
date = "2026-07-30"
sha256 = "a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6c"
strings:
$s1 = "bSfmngdb += \"" ascii wide
$s2 = /rFcogaamkkmfcg/ ascii wide
$s3 = "GetObject(\"winmgmt" ascii wide
$s4 = "Win32_Process" ascii wide
$s5 = "ShowWindow =" ascii wide
$s6 = "<<START>>" ascii wide
$s7 = "<<END>>" ascii wide
$s8 = "bitbucket.org/mywtestwusbect/hfghfgdfgdfg/downloads/3.jpg" ascii wide
$s9 = "paste.sensio.no/GeeksItalians" ascii wide
condition:
filesize < 200KB and
3 of ($s*) and
#s1 > 500
}
Behavioral Hunt Query
process_creation:
CommandLine|contains:
- 'winmgmts'
- 'Win32_ProcessStartup'
- 'ShowWindow = 0'
- 'bitbucket.org/mywtestwusbect'
- 'paste.sensio.no/GeeksItalians'
- 'ultrarenewrecargado-alt/DATESIMPORT'
IOC List
| Indicator | Type | Context |
|---|---|---|
a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6c |
SHA-256 | JScript dropper |
rFcogaamkkmfcg |
String | Noise delimiter token |
bitbucket.org/mywtestwusbect/hfghfgdfgdfg/downloads/3.jpg |
URL | Image-steganography carrier |
paste.sensio.no/GeeksItalians |
URL | Fallback payload carrier |
raw.githubusercontent.com/ultrarenewrecargado-alt/DATESIMPORT/refs/heads/main/SpmSdkd.txt |
URL | Final C2 endpoint |
myprogram.Homees |
.NET Type | Reflectively loaded assembly |
runss |
Method | C2 beacon method (runtime concatenated) |
phantomSgfdghift |
Function | Dead-code builder template fingerprint |
quantumRipple |
Function | Dead-code builder template fingerprint |
Behavioral Fingerprint Statement
This JScript dropper hides a PowerShell payload inside over 2,000 lines of += string-concatenation statements interleaved with a fixed 14-character noise token. The noise is stripped at runtime via String.replace(regex, ""), revealing a UTF-16LE Base64-encoded PowerShell command with an f#→r character substitution anti-signature step. The PowerShell sets TLS 1.2, defines a shuffled URL downloader, fetches an image or text file from Bitbucket and paste.sensio.no, searches for <<START>>/<<END>> markers, extracts a Base64 .NET assembly, reflectively loads it via [System.Reflection.Assembly]::Load, and invokes the myprogram.Homees type's runss method with a reversed GitHub Raw URL. Execution is launched through WMI Win32_Process.Create with ShowWindow = 0 to hide the PowerShell window. Two no-op Get-Process | Sort-Object CPU statements bracket the assembly load as an anti-emulation delay. Dead-code functions phantomSgfdghift and quantumRipple pad the script but are never called.
Detection Signatures
- MITRE ATT&CK T1059.005: Visual Basic (JScript variant) execution via Windows Script Host
- MITRE ATT&CK T1059.001: PowerShell execution via embedded Base64
- MITRE ATT&CK T1027.001: Obfuscated files or information — noise-token padding
- MITRE ATT&CK T1564.003: Hide Artifacts — hidden window process spawn via WMI
- MITRE ATT&CK T1105: Ingress Tool Transfer — download from remote URLs
- MITRE ATT&CK T1071.001: Application Layer Protocol — HTTPS C2
- MITRE ATT&CK T1620: Reflective Code Loading — .NET assembly loaded in-memory
- MITRE ATT&CK T1127.001: Trusted Developer Utilities —
Msbuildstring passed to method
References
- Artifact ID:
c5fad45c-a5af-42b5-8df9-3a894b067cf5 - Source: MalwareBazaar (OpenCTI
malware-bazaarconnector) - Related wiki pages: unclassified-js-bitbucket-stego-dropper, js-fixed-delimiter-concat-obfuscation, wmi-hidden-process-powershell, image-steganography-payload-delivery
- First sibling:
56ea37ef9e4ae2bb4d0e11b84ba3aea650a55018cd3430d6c75f0a5ef6815d81
Provenance
file.txt—fileutility output (ASCII text) ^[file.txt]strings.txt— raw strings extracted viastrings -n 6^[strings.txt]exiftool.json— ExifTool metadata (TXT, 80KB, 2,243 lines) ^[exiftool.json]triage.json— triage pipeline classification (family=bitbucketorgmywtestwusbect, tier=deep) ^[triage.json]- Decoded payload — manual extraction via Python regex + base64 + UTF-16-LE decode
dynamic-analysis.md— CAPE skipped (ASCII text, non-binary class) ^[dynamic-analysis.md]
^(/intel/analyses/a09e7790157785ac318b2895ef8bd370c4d1e4e40138435f12367259caf83a6c.html)