familyunclassified-js-cjk-stego-dropperconfidencehigh
SHA-256: eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe84ae77fe63fff5300

eba13078 — Purchase Order 386761 SN 0002842747 DOC.js

Build / RE

Outer carrier: JavaScript source saved as UTF-16 LE with CRLF line terminators ^[file.txt], masquerading as a purchase-order document via descriptive filename (Purchase Order 386761 SN 0002842747 DOC.js). ^[triage.json]

Obfuscation: javascript-obfuscator npm package variant. The script declares a single string-array lookup function v3(key) that retrieves values from a hardcoded dictionary of 381 entries. Each entry is a long string of CJK Unified Ideographs. ^[strings.txt:1-50]

Encoding scheme: CJK Unified Ideographs (U+4E00–U+9FFF). Payload bytes are recovered by byte = charcode - 0x4E00. This is a shift from sibling 0de6482c which used CJK Extension A (byte = charcode - 0x3400) and 7129076f which used Hangul Syllables (byte = charcode - 0xAC00). ^[floss.txt:1-20]

Staging chain:

  1. 381 env-var assignments: v3("eFexOHGhRPPiuj7") = "<CJK string>" etc. ^[strings.txt:50-450]

  2. Tail execution skeleton (lines 397–426) decrypts a 15-byte key array v15 against an 8206-byte ciphertext v16 via (v16[i] - v15[i % 15] + 256) & 255, producing the PowerShell loader script assigned to v3("sVS8A4njYXDu"). ^[floss.txt:400-426]

  3. The script sets v3("bTHj33nN8i9p") = WScript.ScriptFullName (self-path reference). ^[floss.txt:410]

  4. Four ActiveXObject instantiations with inline IIFE decrypters:

    • WScript.Shell ^[r2:sym.WScript.Shell]
    • Msxml2.DOMDocument.6.0 ^[r2:sym.Msxml2.DOMDocument.6.0]
    • Msxml2.FreeThreadedDOMDocument.6.0 ^[r2:sym.Msxml2.FreeThreadedDOMDocument.6.0]
    • Msxml2.XSLTemplate.6.0 ^[r2:sym.Msxml2.XSLTemplate.6.0]
  5. XSLT JScript extension payload (decoded from char-code array v35): builds an XSL stylesheet with an embedded JScript function v1() that spawns conhost.exe --headless powershell.exe -W H -nOP -nONI -Command "&([scriptblock]::Create($env:sVS8A4njYXDu))". ^[floss.txt:419-421]

Inner payload: A 379,392-byte PE32+ x64 Mono/.NET assembly, SHA-256 5b931001c693b29c3966a70f4221d95c33b1ee3afa7d8642db709f66b9746273. Two sections (.text, .rsrc), compiled timestamp Thu Sep 22 07:00:00 2005 (common ConfuserEx / packer artifact). .NET metadata version 4.0. No manifest resources beyond a generic MyApplication.app identity. ^[file.txt] ^[rabin2-info.txt]

Inner payload strings (UTF-16LE): Semantic English obfuscation of type/method names (MaintenanceCulturalChampagnePhysiolCarried, IlluminatedProfoundAgainstTimezoneTransferred, DisciplinesBarbudaCastlesDisabledPersonalized). No hardcoded URLs, IPs, or C2 domains. Imports System.Reflection, System.Security.Cryptography, System.Security.Permissions. Target framework .NETFramework,Version=v4.8. ^[strings.txt] ^[floss.txt]

Deploy / ATT&CK

Tactic Technique Evidence
Initial Access T1566.001 Phishing attachment — JS inside archive, business-themed lure. ^[triage.json]
Execution T1059.005 WScript execution of outer .js. ^[file.txt]
Execution T1059.001 PowerShell intermediate stage (powershell.exe -Command "&([scriptblock]::Create(...))"). ^[floss.txt:419-421]
Execution T1059.007 XSLT JScript extension execution via msxsl:script inside Msxml2.XSLTemplate. ^[floss.txt:419-421]
Defense Evasion T1027 Multi-layer obfuscation: JS obfuscator → CJK steganography → env-var staging → XSLT JScript extension. ^[strings.txt]
Defense Evasion T1497.001 conhost.exe --headless used to hide PowerShell window and suppress console creation. ^[floss.txt:419-421]
Defense Evasion T1620 Reflective .NET assembly loading in memory via System.Reflection.Assembly::Load(byte[]). No disk touch. ^[floss.txt:400-426]
Defense Evasion T1070.004 Self-reference via WScript.ScriptFullName may be used for self-deletion in later stages. ^[floss.txt:410]
Discovery T1082 Inner .NET assembly references System.Reflection.Assembly and GetTypeFromHandle, consistent with runtime type introspection. ^[strings.txt]

Capabilities

  • cjk-unicode-steganography-pe-dropper
  • environment-variable-payload-staging
  • xslt-jscript-extension-execution
  • conhost-headless-powershell-spawn
  • reflective-dotnet-assembly-load
  • semantic-english-name-obfuscation
  • javascript-obfuscator-string-array-wrapper
  • purchase-order-spam-lure-delivery

IOCs

  • Outer: eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe84ae77fe63fff5300 (849,326 bytes)
  • Inner: 5b931001c693b29c3966a70f4221d95c33b1ee3afa7d8642db709f66b9746273 (379,392 bytes)
  • Filenames: Purchase Order 386761 SN 0002842747 DOC.js
  • Process chain: wscript.exe → conhost.exe --headless powershell.exe
  • No network IOCs extracted statically. The inner .NET assembly contains no hardcoded URLs or IPs; C2 configuration likely retrieved at runtime or packed in a secondary resource not visible in this stage.

Confidence

High. This sample is a confirmed third sibling of the unclassified-js-cjk-stego-dropper family, sharing the CJK steganography → env-var staging → reflective .NET load chain. The novel addition is the XSLT JScript extension execution path (previously unseen in this family) and the use of conhost.exe --headless for window suppression.