exeinarchive
OpenCTI label exe-in-archive applied to spam-trap JavaScript droppers that arrive inside archive files (ZIP/RAR/ISO) attached to phishing emails. The label is generic and does not denote a single technical family; rather, it clusters socially engineered JS droppers that share a common delivery vector and a typical multi-stage payload chain.
Typical Build / RE
- Delivery: Business-themed phishing lure (invoice, quotation, payment, purchase order) with a
.jsfile inside a.zipor.rararchive. - Outer stage: Obfuscated JavaScript, commonly produced by the
javascript-obfuscatornpm package — string-array lookup table, control-flow flattening, custom alphabet base64 encoding. ^[techniques/javascript-obfuscator.md] - Intermediate stage: Base64-encoded PowerShell that decrypts itself via RC4 (KSA/PRGA loop with a hardcoded hex key). ^[techniques/rc4-encrypted-powershell.md]
- Final stage: XOR-encrypted .NET assembly, decrypted at runtime in PowerShell and loaded reflectively via
System.Reflection.Assembly::Load(byte[]). ^[techniques/xored-dotnet-in-memory-assembly.md] - Target process:
aspnet_compiler.exe— the assembly is executed in the context of this .NET build tool, used as a proxy host. ^[techniques/aspnet-compiler-sandbox-evasion.md]
Deploy / ATT&CK
| Tactic | Technique | Typical Evidence |
|---|---|---|
| Initial Access | T1566.001 | Business-themed JS file in email attachment archive. |
| Execution | T1059.005 | WScript / CScript execution of the outer .js. |
| Execution | T1059.001 | PowerShell intermediate stage with -ExecutionPolicy Bypass. |
| Defense Evasion | T1027 | Multi-layer obfuscation: JS obfuscator → Base64 → RC4 → XOR. |
| Defense Evasion | T1497.001 | aspnet_compiler process-name gate (presence or absence checked). |
| Defense Evasion | T1620 | Reflective .NET assembly loading in memory, no disk touch. |
Capabilities
- javascript-obfuscator-string-array-wrapper
- base64-embedded-powershell-stage
- rc4-encrypted-powershell-decryptor
- xor-decrypt-dotnet-assembly
- reflective-dotnet-assembly-load
- aspnet-compiler-process-proxy-injection
- business-themed-spam-lure-delivery
Notable Analyses
aa913765e7243b4c67b9d9953ceae4914696dbc59a2cfe49157a6ed2b64b05c3—Required Quotation.js, four-stage JS→RC4→XOR→ConfuserEx .NET dropper, invertedaspnet_compilergate, final payloadWWOMEN.dll. ^[/intel/analyses/aa913765e7243b4c67b9d9953ceae4914696dbc59a2cfe49157a6ed2b64b05c3.html]37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2—Payment-Swift-TT05294758.js, two-stage JS→PowerShell downloader,javascript-obfuscatorobfuscation,itegroup.sbsC2, triple persistence (Task Scheduler + Startup LNK + HKCU Run). Note: This sample carries the OpenCTIexe-in-archivelabel but technically resolves to theitegroup-sbs-droppercluster rather than the canonicalexeinarchivefour-stage chain. ^[/intel/analyses/37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2.html]
Related
- spamita — Italian-language sibling family using the identical four-stage chain. The
exeinarchivelabel overlaps heavily with spamita variants distributed via English-language lures. - javascript-obfuscator — outer-stage obfuscation pattern.
- rc4-encrypted-powershell — intermediate-stage decryption technique.
- xored-dotnet-in-memory-assembly — final-stage loading technique.
- aspnet-compiler-sandbox-evasion — process-name gate technique.