aa913765e7243b4c67b9d9953ceae4914696dbc59a2cfe49157a6ed2b64b05c3aa913765 — Required Quotation.js: Four-Stage JS→RC4→XOR→ConfuserEx .NET Dropper
Executive Summary
Complete static recovery of a four-stage JavaScript dropper distributed as Required Quotation.js (business-themed social-engineering lure). The outer JavaScript (obfuscated via javascript-obfuscator) embeds a Base64 block that decodes to a PowerShell RC4 decryptor; the RC4-decrypted PowerShell then XOR-decrypts a .NET assembly with key SKIDOvik56@@ and loads it reflectively into aspnet_compiler.exe. The final payload is a 55 KB .NET Framework 4.5.1 DLL obfuscated with ConfuserEx 1.6.0, named internally WWOMEN.dll. No C2 URLs or persistence strings recovered statically from any stage.
Stage-by-Stage Recovery
| Stage | Format | Size | Decryption | Key / Passphrase |
|---|---|---|---|---|
| 0 | Obfuscated JavaScript | 3,083,607 bytes | None (outer wrapper) | — |
| 1 | Base64 → PowerShell | 2,248,568 bytes | Base64 decode | — |
| 2 | RC4-decrypted PowerShell | 1,105,989 bytes | RC4 (KSA/PRGA) | Hex key 72939FEB29E54C40A112A94F8F37A3703BA87DA4A75FD1637F326F68504E75D7 |
| 3 | XOR-decrypted .NET assembly | 55,296 bytes | XOR + Base64 | Passphrase SKIDOvik56@@ |
All stages recovered via manual extraction and verified against their own embedded decryption routines.
Build / RE
Toolchain & Framework
- Stage 0 (JavaScript):
javascript-obfuscatornpm package — identifiable by the_0x62f8()string-array lookup table with 513 entries, control-flow flattening viawhile(!![])dispatch loops, and custom base64 alphabet encoding. ^[strings.txt:1] ^[techniques/javascript-obfuscator.md] - Stage 2 (PowerShell): Pure PowerShell 5.1+ syntax. Uses
[System.Convert]::FromBase64String, byte-array XOR loops, andSystem.Reflection.Assembly::Load. No external dependencies. - Stage 3 (.NET assembly): .NET Framework 4.5.1 (
TargetFrameworkAttribute: .NETFramework,Version=v4.5.1). ^[file.txt on /tmp/aa913765-final-assembly.bin] PE32 DLL, console, x86. Compiled with standard .NET toolchain; not Native AOT —COM_DESCRIPTORis present.
Packing / Obfuscation
- ConfuserEx 1.6.0 on the final .NET assembly — confirmed by string
ConfusedByAttributeandConfuser.Core 1.6.0+447341964fin the binary. ^[strings on /tmp/aa913765-final-assembly.bin] - SuppressIldasmAttribute present — blocks IL disassembly by
ildasm.exe. ^[strings on /tmp/aa913765-final-assembly.bin] - No native packer (UPX, Themida) observed on any stage. The obfuscation is entirely managed/script-layer.
Anti-Analysis
- Inverted aspnet_compiler process gate:
Test-ProcessAbsent -ProcessName "aspnet_compiler"checks whetheraspnet_compiler.exeis missing from the process list. If absent, the payload executes. This is the inverse of the spamita gate (which required the process to be present). Inverting the gate is a trivial but effective mutation against naive signature detection. ^[powershell:Test-ProcessAbsent] - Perpetual monitoring loop:
Invoke-PerpetualMonitoringruns an infinitewhile ($true)loop with a 5-second sleep, re-injecting intoaspnet_compiler.exeif the process disappears. This acts as both a watchdog and a re-injection mechanism. ^[powershell:Invoke-PerpetualMonitoring] - ConfuserEx anti-tamper: Standard ConfuserEx integrity checks expected but not verified statically.
Embedded Resources
- Stage 0: Single 2,998,092-character Base64 block embedded in the obfuscated JS, decoded to the PowerShell RC4 decryptor. ^[manual extraction from /tmp/aa913765...bin]
- Stage 2:
$encryptedPayloadvariable — a 98,304-character Base64 string that XOR-decrypts to the 55 KB .NET assembly. ^[manual extraction from /tmp/aa913765-inner.bin:95] - No external network fetch — the entire chain is file-based and self-contained.
Notable Functions
Unprotect-XORData: Takes a Base64-encoded XOR ciphertext and a passphrase, decodes, then byte-wise XORs. Returns a UTF-8 string (which is itself another Base64 payload). ^[powershell:Unprotect-XORData]Execute-DynamicAssembly: Reflective loader —Assembly.Load(byte[])→GetType($TypeName)→GetMethod($MethodName)→MethodBase.Invoke($null, $Parameters). Standard in-memory .NET assembly execution with no disk touch. ^[powershell:Execute-DynamicAssembly]Invoke-PerpetualMonitoring: Watchdog loop. Hardcodes$TargetProcess = "aspnet_compiler",$IntervalSeconds = 5, and$MasterKey = "SKIDOvik56@@". ^[powershell:Invoke-PerpetualMonitoring]
Deploy / ATT&CK
Dynamic analysis: Unavailable — CAPE skipped the outer JS file because it is ASCII text, not a supported binary class. ^[dynamic-analysis.md] All behaviour below is inferred from static recovery.
TTPs
| Tactic | Technique | Evidence |
|---|---|---|
| Initial Access | T1566.001 (Spearphishing Attachment) | Filename Required Quotation.js — business-themed social-engineering lure. ^[metadata.json:4] |
| Execution | T1059.005 (Visual Basic / JScript) | Outer file executed via WScript.Shell → powershell.exe. ^[strings.txt:extracted _0x62f8 table] |
| Execution | T1059.001 (PowerShell) | Stage 2 is pure PowerShell with Invoke-Expression equivalent via Execute-DynamicAssembly. ^[powershell:Execute-DynamicAssembly] |
| Execution | T1059.012 (Python) | Not observed. |
| Defense Evasion | T1027 (Obfuscated Files or Information) | Four layers: JS obfuscator → Base64 → RC4 → XOR → ConfuserEx. ^[full chain] |
| Defense Evasion | T1497.001 (Virtualization / Sandbox Evasion) | Inverted aspnet_compiler process-name gate. ^[powershell:Test-ProcessAbsent] |
| Defense Evasion | T1620 (Reflective Code Loading) | Assembly.Load(byte[]) followed by GetMethod(...).Invoke(...). ^[powershell:Execute-DynamicAssembly] |
| Defense Evasion | T1218.011 (System Binary Proxy Execution: Rundll32) | Not observed. |
| Persistence | T1543 (Create or Modify System Process) | Not observed statically. |
| Persistence | T1053 (Scheduled Task/Job) | Not observed. |
| Discovery | T1082 (System Information Discovery) | Get-Process enumeration in Test-ProcessAbsent. ^[powershell:Test-ProcessAbsent] |
| Collection | T1113 (Screen Capture) | Not observed. |
| Exfiltration | T1041 (Exfiltration Over C2 Channel) | No C2 URLs, IPs, or domains recovered from any stage. |
| Impact | T1496 (Resource Hijacking) | Not observed. |
C2, Persistence, and Exfiltration
- Zero network indicators recovered from any of the four stages. No URLs, domains, IP addresses, or socket API strings found in the final ConfuserEx .NET assembly. The assembly contains
GetProcessById,processHandle,thread,threadHandle,payload,EXECUTE,LAUNCH, andallocationType— strongly suggesting process injection / hollowing behaviour, but without a disassembly of the ConfuserEx-obfuscated IL, the exact mechanism is not recoverable statically. ^[strings on /tmp/aa913765-final-assembly.bin] - No persistence strings (Run keys, Scheduled Tasks, Services, Startup folders) observed in any stage.
- Target process:
C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe— the final assembly is executed in the context of this .NET build tool, a common proxy target for reflective loaders. ^[powershell:Invoke-PerpetualMonitoring:105]
Attribution
- Family linkage: The build chain (JS→Base64→RC4 PowerShell→XOR .NET→reflective load→aspnet_compiler gate) is an exact structural match for the
spamitafamily (sample129ef925...,Invio proforma.js). The differences are:- Geographic/language target: English (
Required Quotation) vs Italian (Invio proforma). - XOR key:
SKIDOvik56@@vsSKIDO56@@fhsdgh. - Final payload obfuscation: ConfuserEx 1.6.0 (this sample) vs unobfuscated (spamita).
- Process gate direction: inverted (absent → execute) vs original (present → execute).
- Geographic/language target: English (
- These differences are minor mutations within the same builder/template. Medium-confidence assessment: this is a spamita variant or sibling built from the same multi-stage generator. The OpenCTI label
exeinarchiveis a generic container label ("executable inside archive") applied to spam-trap JS droppers and does not denote a distinct technical family. ^[entities/spamita.md] - No linguistic or cultural clues in the binary itself. The lure text is generic English business language.
- Builder/version artefacts: ConfuserEx version
1.6.0+447341964fis a specific commit from the ConfuserEx GitHub repository ( circa 2021–2023 ). TheWWOMEN.dllinternal name andCopyright © 2026timestamp suggest active development as of 2026.
IOCs
| Type | Value | Stage |
|---|---|---|
| SHA-256 | aa913765e7243b4c67b9d9953ceae4914696dbc59a2cfe49157a6ed2b64b05c3 |
Outer JS |
| Filename | Required Quotation.js |
^[metadata.json:4] |
| Size | 3,083,607 bytes | ^[metadata.json:5] |
| RC4 key (hex) | 72939FEB29E54C40A112A94F8F37A3703BA87DA4A75FD1637F326F68504E75D7 |
Stage 1→2 |
| XOR passphrase | SKIDOvik56@@ |
Stage 2→3 |
| Target process | aspnet_compiler.exe |
Stage 2 |
| .NET assembly size | 55,296 bytes | Stage 3 |
| .NET framework | 4.5.1 | Stage 3 |
| Obfuscator | ConfuserEx 1.6.0+447341964f | Stage 3 |
| Internal name | WWOMEN.dll |
Stage 3 |
| Copyright | Copyright © 2026 |
Stage 3 |
| Version | 1.0.0.0 |
Stage 3 |
Verdict
Medium-confidence placement as a spamita variant / sibling within the exeinarchive OpenCTI label group. The full four-stage payload chain was recovered and verified. The final .NET assembly is ConfuserEx-obfuscated, preventing static disassembly of its runtime behaviour, but the presence of process/thread/injection-related strings and the EXECUTE/LAUNCH/payload artefacts indicate the expected post-load activity is process injection or hollowing into aspnet_compiler.exe. No network C2 or persistence recovered statically; the threat logic is likely entirely contained within the obfuscated IL, requiring dynamic detonation or ConfuserEx deobfuscation to fully map.