eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe84ae77fe63fff5300eba13078 — Purchase Order 386761 SN 0002842747 DOC.js
Build / RE
Outer carrier: JavaScript source saved as UTF-16 LE with CRLF line terminators ^[file.txt], masquerading as a purchase-order document via descriptive filename (Purchase Order 386761 SN 0002842747 DOC.js). ^[triage.json]
Obfuscation: javascript-obfuscator npm package variant. The script declares a single string-array lookup function v3(key) that retrieves values from a hardcoded dictionary of 381 entries. Each entry is a long string of CJK Unified Ideographs. ^[strings.txt:1-50]
Encoding scheme: CJK Unified Ideographs (U+4E00–U+9FFF). Payload bytes are recovered by byte = charcode - 0x4E00. This is a shift from sibling 0de6482c which used CJK Extension A (byte = charcode - 0x3400) and 7129076f which used Hangul Syllables (byte = charcode - 0xAC00). ^[floss.txt:1-20]
Staging chain:
-
381 env-var assignments:
v3("eFexOHGhRPPiuj7") = "<CJK string>"etc. ^[strings.txt:50-450] -
Tail execution skeleton (lines 397–426) decrypts a 15-byte key array
v15against an 8206-byte ciphertextv16via(v16[i] - v15[i % 15] + 256) & 255, producing the PowerShell loader script assigned tov3("sVS8A4njYXDu"). ^[floss.txt:400-426] -
The script sets
v3("bTHj33nN8i9p") = WScript.ScriptFullName(self-path reference). ^[floss.txt:410] -
Four
ActiveXObjectinstantiations with inline IIFE decrypters:WScript.Shell^[r2:sym.WScript.Shell]Msxml2.DOMDocument.6.0^[r2:sym.Msxml2.DOMDocument.6.0]Msxml2.FreeThreadedDOMDocument.6.0^[r2:sym.Msxml2.FreeThreadedDOMDocument.6.0]Msxml2.XSLTemplate.6.0^[r2:sym.Msxml2.XSLTemplate.6.0]
-
XSLT JScript extension payload (decoded from char-code array
v35): builds an XSL stylesheet with an embedded JScript functionv1()that spawnsconhost.exe --headless powershell.exe -W H -nOP -nONI -Command "&([scriptblock]::Create($env:sVS8A4njYXDu))". ^[floss.txt:419-421]
Inner payload: A 379,392-byte PE32+ x64 Mono/.NET assembly, SHA-256 5b931001c693b29c3966a70f4221d95c33b1ee3afa7d8642db709f66b9746273. Two sections (.text, .rsrc), compiled timestamp Thu Sep 22 07:00:00 2005 (common ConfuserEx / packer artifact). .NET metadata version 4.0. No manifest resources beyond a generic MyApplication.app identity. ^[file.txt] ^[rabin2-info.txt]
Inner payload strings (UTF-16LE): Semantic English obfuscation of type/method names (MaintenanceCulturalChampagnePhysiolCarried, IlluminatedProfoundAgainstTimezoneTransferred, DisciplinesBarbudaCastlesDisabledPersonalized). No hardcoded URLs, IPs, or C2 domains. Imports System.Reflection, System.Security.Cryptography, System.Security.Permissions. Target framework .NETFramework,Version=v4.8. ^[strings.txt] ^[floss.txt]
Deploy / ATT&CK
| Tactic | Technique | Evidence |
|---|---|---|
| Initial Access | T1566.001 | Phishing attachment — JS inside archive, business-themed lure. ^[triage.json] |
| Execution | T1059.005 | WScript execution of outer .js. ^[file.txt] |
| Execution | T1059.001 | PowerShell intermediate stage (powershell.exe -Command "&([scriptblock]::Create(...))"). ^[floss.txt:419-421] |
| Execution | T1059.007 | XSLT JScript extension execution via msxsl:script inside Msxml2.XSLTemplate. ^[floss.txt:419-421] |
| Defense Evasion | T1027 | Multi-layer obfuscation: JS obfuscator → CJK steganography → env-var staging → XSLT JScript extension. ^[strings.txt] |
| Defense Evasion | T1497.001 | conhost.exe --headless used to hide PowerShell window and suppress console creation. ^[floss.txt:419-421] |
| Defense Evasion | T1620 | Reflective .NET assembly loading in memory via System.Reflection.Assembly::Load(byte[]). No disk touch. ^[floss.txt:400-426] |
| Defense Evasion | T1070.004 | Self-reference via WScript.ScriptFullName may be used for self-deletion in later stages. ^[floss.txt:410] |
| Discovery | T1082 | Inner .NET assembly references System.Reflection.Assembly and GetTypeFromHandle, consistent with runtime type introspection. ^[strings.txt] |
Capabilities
cjk-unicode-steganography-pe-dropperenvironment-variable-payload-stagingxslt-jscript-extension-executionconhost-headless-powershell-spawnreflective-dotnet-assembly-loadsemantic-english-name-obfuscationjavascript-obfuscator-string-array-wrapperpurchase-order-spam-lure-delivery
IOCs
- Outer:
eba13078dea9e803b9120a45cd0dfad589f1defdf0f86fe84ae77fe63fff5300(849,326 bytes) - Inner:
5b931001c693b29c3966a70f4221d95c33b1ee3afa7d8642db709f66b9746273(379,392 bytes) - Filenames:
Purchase Order 386761 SN 0002842747 DOC.js - Process chain:
wscript.exe→conhost.exe --headless powershell.exe - No network IOCs extracted statically. The inner .NET assembly contains no hardcoded URLs or IPs; C2 configuration likely retrieved at runtime or packed in a secondary resource not visible in this stage.
Confidence
High. This sample is a confirmed third sibling of the unclassified-js-cjk-stego-dropper family, sharing the CJK steganography → env-var staging → reflective .NET load chain. The novel addition is the XSLT JScript extension execution path (previously unseen in this family) and the use of conhost.exe --headless for window suppression.