typedeep-divefamilyexeinarchiveconfidencemediumcreated2026-08-13
SHA-256: aa913765e7243b4c67b9d9953ceae4914696dbc59a2cfe49157a6ed2b64b05c3

aa913765 — Required Quotation.js: Four-Stage JS→RC4→XOR→ConfuserEx .NET Dropper

Executive Summary

Complete static recovery of a four-stage JavaScript dropper distributed as Required Quotation.js (business-themed social-engineering lure). The outer JavaScript (obfuscated via javascript-obfuscator) embeds a Base64 block that decodes to a PowerShell RC4 decryptor; the RC4-decrypted PowerShell then XOR-decrypts a .NET assembly with key SKIDOvik56@@ and loads it reflectively into aspnet_compiler.exe. The final payload is a 55 KB .NET Framework 4.5.1 DLL obfuscated with ConfuserEx 1.6.0, named internally WWOMEN.dll. No C2 URLs or persistence strings recovered statically from any stage.

Stage-by-Stage Recovery

Stage Format Size Decryption Key / Passphrase
0 Obfuscated JavaScript 3,083,607 bytes None (outer wrapper) —
1 Base64 → PowerShell 2,248,568 bytes Base64 decode —
2 RC4-decrypted PowerShell 1,105,989 bytes RC4 (KSA/PRGA) Hex key 72939FEB29E54C40A112A94F8F37A3703BA87DA4A75FD1637F326F68504E75D7
3 XOR-decrypted .NET assembly 55,296 bytes XOR + Base64 Passphrase SKIDOvik56@@

All stages recovered via manual extraction and verified against their own embedded decryption routines.

Build / RE

Toolchain & Framework

  • Stage 0 (JavaScript): javascript-obfuscator npm package — identifiable by the _0x62f8() string-array lookup table with 513 entries, control-flow flattening via while(!![]) dispatch loops, and custom base64 alphabet encoding. ^[strings.txt:1] ^[techniques/javascript-obfuscator.md]
  • Stage 2 (PowerShell): Pure PowerShell 5.1+ syntax. Uses [System.Convert]::FromBase64String, byte-array XOR loops, and System.Reflection.Assembly::Load. No external dependencies.
  • Stage 3 (.NET assembly): .NET Framework 4.5.1 (TargetFrameworkAttribute: .NETFramework,Version=v4.5.1). ^[file.txt on /tmp/aa913765-final-assembly.bin] PE32 DLL, console, x86. Compiled with standard .NET toolchain; not Native AOT — COM_DESCRIPTOR is present.

Packing / Obfuscation

  • ConfuserEx 1.6.0 on the final .NET assembly — confirmed by string ConfusedByAttribute and Confuser.Core 1.6.0+447341964f in the binary. ^[strings on /tmp/aa913765-final-assembly.bin]
  • SuppressIldasmAttribute present — blocks IL disassembly by ildasm.exe. ^[strings on /tmp/aa913765-final-assembly.bin]
  • No native packer (UPX, Themida) observed on any stage. The obfuscation is entirely managed/script-layer.

Anti-Analysis

  • Inverted aspnet_compiler process gate: Test-ProcessAbsent -ProcessName "aspnet_compiler" checks whether aspnet_compiler.exe is missing from the process list. If absent, the payload executes. This is the inverse of the spamita gate (which required the process to be present). Inverting the gate is a trivial but effective mutation against naive signature detection. ^[powershell:Test-ProcessAbsent]
  • Perpetual monitoring loop: Invoke-PerpetualMonitoring runs an infinite while ($true) loop with a 5-second sleep, re-injecting into aspnet_compiler.exe if the process disappears. This acts as both a watchdog and a re-injection mechanism. ^[powershell:Invoke-PerpetualMonitoring]
  • ConfuserEx anti-tamper: Standard ConfuserEx integrity checks expected but not verified statically.

Embedded Resources

  • Stage 0: Single 2,998,092-character Base64 block embedded in the obfuscated JS, decoded to the PowerShell RC4 decryptor. ^[manual extraction from /tmp/aa913765...bin]
  • Stage 2: $encryptedPayload variable — a 98,304-character Base64 string that XOR-decrypts to the 55 KB .NET assembly. ^[manual extraction from /tmp/aa913765-inner.bin:95]
  • No external network fetch — the entire chain is file-based and self-contained.

Notable Functions

  • Unprotect-XORData: Takes a Base64-encoded XOR ciphertext and a passphrase, decodes, then byte-wise XORs. Returns a UTF-8 string (which is itself another Base64 payload). ^[powershell:Unprotect-XORData]
  • Execute-DynamicAssembly: Reflective loader — Assembly.Load(byte[]) → GetType($TypeName) → GetMethod($MethodName) → MethodBase.Invoke($null, $Parameters). Standard in-memory .NET assembly execution with no disk touch. ^[powershell:Execute-DynamicAssembly]
  • Invoke-PerpetualMonitoring: Watchdog loop. Hardcodes $TargetProcess = "aspnet_compiler", $IntervalSeconds = 5, and $MasterKey = "SKIDOvik56@@". ^[powershell:Invoke-PerpetualMonitoring]

Deploy / ATT&CK

Dynamic analysis: Unavailable — CAPE skipped the outer JS file because it is ASCII text, not a supported binary class. ^[dynamic-analysis.md] All behaviour below is inferred from static recovery.

TTPs

Tactic Technique Evidence
Initial Access T1566.001 (Spearphishing Attachment) Filename Required Quotation.js — business-themed social-engineering lure. ^[metadata.json:4]
Execution T1059.005 (Visual Basic / JScript) Outer file executed via WScript.Shell → powershell.exe. ^[strings.txt:extracted _0x62f8 table]
Execution T1059.001 (PowerShell) Stage 2 is pure PowerShell with Invoke-Expression equivalent via Execute-DynamicAssembly. ^[powershell:Execute-DynamicAssembly]
Execution T1059.012 (Python) Not observed.
Defense Evasion T1027 (Obfuscated Files or Information) Four layers: JS obfuscator → Base64 → RC4 → XOR → ConfuserEx. ^[full chain]
Defense Evasion T1497.001 (Virtualization / Sandbox Evasion) Inverted aspnet_compiler process-name gate. ^[powershell:Test-ProcessAbsent]
Defense Evasion T1620 (Reflective Code Loading) Assembly.Load(byte[]) followed by GetMethod(...).Invoke(...). ^[powershell:Execute-DynamicAssembly]
Defense Evasion T1218.011 (System Binary Proxy Execution: Rundll32) Not observed.
Persistence T1543 (Create or Modify System Process) Not observed statically.
Persistence T1053 (Scheduled Task/Job) Not observed.
Discovery T1082 (System Information Discovery) Get-Process enumeration in Test-ProcessAbsent. ^[powershell:Test-ProcessAbsent]
Collection T1113 (Screen Capture) Not observed.
Exfiltration T1041 (Exfiltration Over C2 Channel) No C2 URLs, IPs, or domains recovered from any stage.
Impact T1496 (Resource Hijacking) Not observed.

C2, Persistence, and Exfiltration

  • Zero network indicators recovered from any of the four stages. No URLs, domains, IP addresses, or socket API strings found in the final ConfuserEx .NET assembly. The assembly contains GetProcessById, processHandle, thread, threadHandle, payload, EXECUTE, LAUNCH, and allocationType — strongly suggesting process injection / hollowing behaviour, but without a disassembly of the ConfuserEx-obfuscated IL, the exact mechanism is not recoverable statically. ^[strings on /tmp/aa913765-final-assembly.bin]
  • No persistence strings (Run keys, Scheduled Tasks, Services, Startup folders) observed in any stage.
  • Target process: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe — the final assembly is executed in the context of this .NET build tool, a common proxy target for reflective loaders. ^[powershell:Invoke-PerpetualMonitoring:105]

Attribution

  • Family linkage: The build chain (JS→Base64→RC4 PowerShell→XOR .NET→reflective load→aspnet_compiler gate) is an exact structural match for the spamita family (sample 129ef925..., Invio proforma.js). The differences are:
    1. Geographic/language target: English (Required Quotation) vs Italian (Invio proforma).
    2. XOR key: SKIDOvik56@@ vs SKIDO56@@fhsdgh.
    3. Final payload obfuscation: ConfuserEx 1.6.0 (this sample) vs unobfuscated (spamita).
    4. Process gate direction: inverted (absent → execute) vs original (present → execute).
  • These differences are minor mutations within the same builder/template. Medium-confidence assessment: this is a spamita variant or sibling built from the same multi-stage generator. The OpenCTI label exeinarchive is a generic container label ("executable inside archive") applied to spam-trap JS droppers and does not denote a distinct technical family. ^[entities/spamita.md]
  • No linguistic or cultural clues in the binary itself. The lure text is generic English business language.
  • Builder/version artefacts: ConfuserEx version 1.6.0+447341964f is a specific commit from the ConfuserEx GitHub repository ( circa 2021–2023 ). The WWOMEN.dll internal name and Copyright © 2026 timestamp suggest active development as of 2026.

IOCs

Type Value Stage
SHA-256 aa913765e7243b4c67b9d9953ceae4914696dbc59a2cfe49157a6ed2b64b05c3 Outer JS
Filename Required Quotation.js ^[metadata.json:4]
Size 3,083,607 bytes ^[metadata.json:5]
RC4 key (hex) 72939FEB29E54C40A112A94F8F37A3703BA87DA4A75FD1637F326F68504E75D7 Stage 1→2
XOR passphrase SKIDOvik56@@ Stage 2→3
Target process aspnet_compiler.exe Stage 2
.NET assembly size 55,296 bytes Stage 3
.NET framework 4.5.1 Stage 3
Obfuscator ConfuserEx 1.6.0+447341964f Stage 3
Internal name WWOMEN.dll Stage 3
Copyright Copyright © 2026 Stage 3
Version 1.0.0.0 Stage 3

Verdict

Medium-confidence placement as a spamita variant / sibling within the exeinarchive OpenCTI label group. The full four-stage payload chain was recovered and verified. The final .NET assembly is ConfuserEx-obfuscated, preventing static disassembly of its runtime behaviour, but the presence of process/thread/injection-related strings and the EXECUTE/LAUNCH/payload artefacts indicate the expected post-load activity is process injection or hollowing into aspnet_compiler.exe. No network C2 or persistence recovered statically; the threat logic is likely entirely contained within the obfuscated IL, requiring dynamic detonation or ConfuserEx deobfuscation to fully map.