typeentityfamilyunclassified-js-rentry-telegram-dropperconfidencelowcreated2026-06-29updated2026-06-29scriptdropperloaderreconnaissanceexfiltrationc2telegrampersistence

Unclassified JS Rentry-Telegram Dropper

A single-sample JScript/WScript dropper family using javascript-obfuscator control-flow flattening and a 190-entry string-array lookup table. The sample downloads a secondary VBS payload from a rentry.co paste, patches hardcoded URLs/ filenames inside it, stages to %TEMP%\tempScript.bat, and copies itself to the Startup SpecialFolder for persistence. Victim fingerprinting (OS, username, external IP, antivirus products) is exfiltrated via the Telegram Bot API.

Confidence: low (single sample, no siblings in corpus).

Capabilities

  • javascript-obfuscator-cff-string-array-obfuscation
  • noise-comment-padding-size-inflation
  • rentry-pastebin-payload-staging
  • vbs-payload-string-replacement
  • temp-directory-payload-staging
  • startup-specialfolder-self-copy-persistence
  • wmi-system-fingerprinting
  • wmi-antivirusproduct-enumeration
  • external-ip-resolution-ipify
  • telegram-bot-api-exfiltration
  • winhttp-request-downloader
  • msxml2-xmlhttp-exfil-post

Related