typeentityconfidencemediumcreated2026-08-13updated2026-08-27malware-familyscriptdropperspamjsdefense-evasion

exeinarchive

OpenCTI label exe-in-archive applied to spam-trap JavaScript droppers that arrive inside archive files (ZIP/RAR/ISO) attached to phishing emails. The label is generic and does not denote a single technical family; rather, it clusters socially engineered JS droppers that share a common delivery vector and a typical multi-stage payload chain.

Typical Build / RE

  • Delivery: Business-themed phishing lure (invoice, quotation, payment, purchase order) with a .js file inside a .zip or .rar archive.
  • Outer stage: Obfuscated JavaScript, commonly produced by the javascript-obfuscator npm package — string-array lookup table, control-flow flattening, custom alphabet base64 encoding. ^[techniques/javascript-obfuscator.md]
  • Intermediate stage: Base64-encoded PowerShell that decrypts itself via RC4 (KSA/PRGA loop with a hardcoded hex key). ^[techniques/rc4-encrypted-powershell.md]
  • Final stage: XOR-encrypted .NET assembly, decrypted at runtime in PowerShell and loaded reflectively via System.Reflection.Assembly::Load(byte[]). ^[techniques/xored-dotnet-in-memory-assembly.md]
  • Target process: aspnet_compiler.exe — the assembly is executed in the context of this .NET build tool, used as a proxy host. ^[techniques/aspnet-compiler-sandbox-evasion.md]

Deploy / ATT&CK

Tactic Technique Typical Evidence
Initial Access T1566.001 Business-themed JS file in email attachment archive.
Execution T1059.005 WScript / CScript execution of the outer .js.
Execution T1059.001 PowerShell intermediate stage with -ExecutionPolicy Bypass.
Defense Evasion T1027 Multi-layer obfuscation: JS obfuscator → Base64 → RC4 → XOR.
Defense Evasion T1497.001 aspnet_compiler process-name gate (presence or absence checked).
Defense Evasion T1620 Reflective .NET assembly loading in memory, no disk touch.

Capabilities

  • javascript-obfuscator-string-array-wrapper
  • base64-embedded-powershell-stage
  • rc4-encrypted-powershell-decryptor
  • xor-decrypt-dotnet-assembly
  • reflective-dotnet-assembly-load
  • aspnet-compiler-process-proxy-injection
  • business-themed-spam-lure-delivery

Notable Analyses

  • aa913765e7243b4c67b9d9953ceae4914696dbc59a2cfe49157a6ed2b64b05c3 — Required Quotation.js, four-stage JS→RC4→XOR→ConfuserEx .NET dropper, inverted aspnet_compiler gate, final payload WWOMEN.dll. ^[/intel/analyses/aa913765e7243b4c67b9d9953ceae4914696dbc59a2cfe49157a6ed2b64b05c3.html]
  • 37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2 — Payment-Swift-TT05294758.js, two-stage JS→PowerShell downloader, javascript-obfuscator obfuscation, itegroup.sbs C2, triple persistence (Task Scheduler + Startup LNK + HKCU Run). Note: This sample carries the OpenCTI exe-in-archive label but technically resolves to the itegroup-sbs-dropper cluster rather than the canonical exeinarchive four-stage chain. ^[/intel/analyses/37e8fc3692a69b04324eea93dd65d70a329bd117c8126119357bc43680f79fa2.html]

Related