
JScript Downloader Checks Its Own IP Before Calling Home
An unsigned UTF-16 JScript file pauses through sandbox-evading sleep cycles and verifies its public IP against checkip.dyndns.org and reallyfreegeoip.org before contacting a single German VPS. The behavior — paired with a weakly-linked RAR sibling under the same generic AV label — makes this downloader's evasion tradecraft the most solid finding in an otherwise thin infrastructure picture.
An unsigned UTF-16 JScript file, submitted four times from three separate sources on the same day, spends its opening moments doing something most invoice-lure malware skips: it pauses, checks whether it is being watched, and looks up its own public IP address before doing anything else. That combination — deliberate sleep cycles tagged internally as "long-sleeps" and "idle," paired with an external-IP self-check against checkip.dyndns.org and reallyfreegeoip.org — is the most concrete and…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read