{"id":"cdd54ad599d195175f9a2cbb41c2032f","title":"JS PowerShell Dropper — JS PowerShell Dropper · 下载器/投放器 · Script","md5":"cdd54ad599d195175f9a2cbb41c2032f","sha256":"00d9e0c440cc5d6c65a4bd401afb58c2198a281793f4c8aaa1e14ce096d77727","family":"JS PowerShell Dropper","apt":null,"verdict":null,"sample_type":"下载器/投放器","lang":"N","file_format":"Script","compiler":"JavaScript","published_at":"2026-08-09T16:00:00.000Z","summary":"该样本是使用自定义混淆方案（自定义 Base64 字母表 + RC4 流密码）加密的 JavaScript 下载器，设计用于 Windows Script Host (WScript) 环境执行。 核心恶意行为： 混淆层：248 个加密字符串，通过 _0x4363() 函数在运行时解密（自定义 Base64 + RC4），解密密钥分散在代码各处 下载执行：使用 ActiveXObject('MSXML2.XMLHTTP') 从 hxxp://178.16.53[.]176/DV/ojdcrypted.ps1 下载第二阶段的 PowerShell 载荷 持久化暂存：通过 Scripting.FileSystemObject 在 C:\\Temp\\ 目录创建文件 命令执行：powershell.exe -nop -ep bypass -file 绕过执行策略执行下载的 PowerShell 脚本 重试机制：最多重试 2 次，检查 HTTP 200 状态码 反调试：通过 Function 构造函数检测调试器（检查 arguments.callee.caller.toString()） C2 基础设施：178.16.53[.]176 为俄罗斯 IP 地址，托管 PowerShell 载荷文件。","url":"https://zseceye.com/report/cdd54ad599d195175f9a2cbb41c2032f","json_url":"https://zseceye.com/report/cdd54ad599d195175f9a2cbb41c2032f.json","html_url":"https://zseceye.com/report/cdd54ad599d195175f9a2cbb41c2032f","hash_urls":{"md5":"https://zseceye.com/hash/cdd54ad599d195175f9a2cbb41c2032f","sha256":"https://zseceye.com/hash/00d9e0c440cc5d6c65a4bd401afb58c2198a281793f4c8aaa1e14ce096d77727"},"search_urls":{"md5":"https://zseceye.com/?q=cdd54ad599d195175f9a2cbb41c2032f","sha256":"https://zseceye.com/?q=00d9e0c440cc5d6c65a4bd401afb58c2198a281793f4c8aaa1e14ce096d77727"},"sample_download_url":"https://zseceye.com/report/cdd54ad599d195175f9a2cbb41c2032f/sample","sample_filename":"00d9e0c440cc5d6c.zip","iocs":[],"ips":[]}