typeanalysisfamilyletsdiskusscomconfidencehighcreated2026-08-23updated2026-08-23malware-familyloaderscriptnodejsobfuscationevasionpersistence
SHA-256: 2c86df65c4976ae885860d5c8568d545d47e50989e4008f34cb486b0f0eeb327

letsdiskusscom: 2c86df65 — Update_12.js, twenty-first confirmed sibling with 21st distinct msvcp140.dll morph

Executive Summary

Twenty-first confirmed sibling in the letsdiskusscom Node.js poem-word-list dropper cluster. Filename Update_12.js (8.5 MB) continues the numbered-suffix steganography template (gentle1, hush2, etc.) and decodes to the same signed RevoSrp.exe + vcruntime DLL payload set shared by all twenty prior siblings, but introduces a twenty-first distinct msvcp140.dll morph (SHA-256 077c6dc7...). Self-contained local installer with BAT-based HKCU Run persistence. No C2. Static-only (CAPE skipped — JavaScript source not supported for detonation).

What It Is

Field Value
SHA-256 2c86df65c4976ae885860d5c8568d545d47e50989e4008f34cb486b0f0eeb327
Filename Update_12.js
Size 8,456,411 bytes (8.1 MB)
Type JavaScript source, ASCII text, CRLF line terminators, 63,365-char lines ^[file.txt]
Family letsdiskusscom (high-confidence, 21st confirmed sibling)
Build Node.js script, custom 256-word English poem lookup-table with numbered suffixes
Payload Signed RevoSrp.exe (52,400 bytes) + msvcp140.dll (1,012,224 bytes) + vcruntime140.dll (101,672 bytes) + vcruntime140_1.dll (44,328 bytes) + BAT persistence script (440 bytes)

How It Works

The script defines a 256-word lookup table (wlist) written as an English poem fragment, then encodes five binary payloads as sequences of word indices from that table ^[strings.txt:4-6]. A writePositionsToFile function performs a.indexOf(word) lookups and writes index & 0xFF bytes to disk ^[strings.txt:18-25].

Decoded payloads:

File Size SHA-256 Notes
Microsoft Edge Updates Helper.exe 52,400 8b94af60... Same signed RevoSrp.exe as all 20 prior siblings
msvcp140.dll 1,012,224 077c6dc7... 21st distinct morph in cluster; MSVC 14.27.29016.0
vcruntime140.dll 101,672 ff43e813... Same as all prior siblings
vcruntime140_1.dll 44,328 7b8f70dd... Same as all prior siblings
dZiDIakVihSz.bat 440 dff20059... Same BAT persistence script as all prior siblings

The staging directory is %ProgramData%\Microsoft Edge Updates Helper dZiDIakVihSz ^[strings.txt:5]. After writing files, the script spawns the BAT with the EXE path as argument, then spawns the EXE directly ^[strings.txt:33-41].

The BAT adds an HKCU Run registry entry pointing to the EXE ^[strings.txt:11].

Steganography variant: Of the 256 words in wlist, 164 carry numbered suffixes (gentle1, hush2, that3 ... fail164) ^[strings.txt:6]. This poisons frequency-analysis tools while preserving the encoding semantics — a.indexOf(word) still resolves correctly because each suffixed token is unique in the lookup table.

C2 Infrastructure

None. The dropper is entirely self-contained; no network calls, no download URLs, no C2 beacons. The threat is the silent payload staging and execution of a signed Revo Uninstaller component under a deceptive directory name.

Interesting Tidbits

  • Build-counter filename: Update_12.js continues the Update_N.js naming pattern seen in siblings Update_3.js through Update_25.js, suggesting an internal build counter or campaign wave tracker.
  • 21st distinct msvcp140.dll: The msvcp140.dll SHA-256 077c6dc7... does not match any of the twenty prior siblings, confirming the builder actively rotates this runtime DLL while reusing the same signed EXE and vcruntime pair.
  • Same signed payload: The EXE retains its DigiCert Authenticode signature (PKCS#7 overlay, 19,120 bytes) and RevoSrp.pdb path, confirming it is the legitimate Revo Uninstaller Pro component repurposed as a masquerade payload.
  • No obfuscation beyond steganography: Unlike the first sibling (9dc2cded) which used javascript-obfuscator, this sample has no IIFE wrappers, no string-array rotation, no self-defend — just the poem encoding.

Deployable Signatures

YARA rule

rule letsdiskusscom_poem_dropper {
    meta:
        description = "Node.js poem-word-list dropper (letsdiskusscom cluster)"
        author = "PacketPursuit"
        date = "2026-08-23"
        sha256 = "2c86df65c4976ae885860d5c8568d545d47e50989e4008f34cb486b0f0eeb327"
    strings:
        $js_fs = "const fs = require('fs');" ascii wide
        $js_path = "const path = require('path');" ascii wide
        $js_spawn = "const { spawn } = require('child_process');" ascii wide
        $app_name = "Microsoft Edge Updates Helper" ascii wide
        $func_write = "function writePositionsToFile(listA, listB, outPath)" ascii wide
        $wlist = "const wlist = \"gentle hush that wraps the midnight air" ascii wide
        $exe = "const exe = \"unwearied tides candle53" ascii wide
        $safeMakeDir = "function safeMakeDir(dir)" ascii wide
        $launch = "function launchExecutable" ascii wide
    condition:
        filesize > 5MB and
        filesize < 15MB and
        4 of ($js_*) and
        $app_name and
        $func_write and
        $wlist and
        $exe
}

Sigma rule

title: Node.js poem-word-list dropper execution
description: Detects Node.js scripts spawning EXEs from ProgramData with Microsoft Edge masquerade
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - CommandLine|contains:
            - 'node.exe'
            - 'Update_*.js'
        - ParentImage|endswith: 'node.exe'
    spawn:
        - Image|endswith:
            - 'Microsoft Edge Updates Helper.exe'
            - 'RevoSrp.exe'
        - CommandLine|contains: 'Microsoft Edge Updates Helper'
    condition: selection and spawn
falsepositives:
    - Unknown
level: high

IOC list

Indicator Value Type
SHA-256 (carrier JS) 2c86df65c4976ae885860d5c8568d545d47e50989e4008f34cb486b0f0eeb327 File
SHA-256 (decoded EXE) 8b94af60bb58bc1629edb3b4f6a86ccff5769bb9b96d8826f06686af2d7fc55f File
SHA-256 (decoded BAT) dff20059f161090c76f9f45ac2269f2965bdc96023c78c1072f8d1aa66b06919 File
SHA-256 (msvcp140.dll) 077c6dc7ac87ebd65e055f99079048032a315eb9f5cf6ce5f669e7c771940aa1 File
Staging directory %ProgramData%\Microsoft Edge Updates Helper dZiDIakVihSz Path
Registry persistence HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Edge Updates Helper Registry
Masquerade name Microsoft Edge Updates Helper String

Behavioral fingerprint

This 8.5 MB JavaScript file defines a 256-word lookup table (an English poem fragment), encodes five binary payloads as word-index sequences, and uses writePositionsToFile to decode them to %ProgramData%\Microsoft Edge Updates Helper <random_suffix>\. It writes a signed RevoSrp.exe, three VC++ runtime DLLs, and a BAT persistence script, then spawns both the BAT and EXE. The BAT adds an HKCU Run registry entry. No network C2. File naming follows Update_N.js build-counter pattern.

Detection Signatures

ATT&CK ID Technique Evidence
T1059.007 JavaScript execution Node.js require('fs') + require('child_process') ^[strings.txt:1-3]
T1027.002 Obfuscated Files or Info 256-word poem lookup-table with numbered-suffix obfuscation ^[strings.txt:6]
T1036.005 Masquerading Microsoft Edge Updates Helper directory and filename ^[strings.txt:4]
T1547.001 Registry Run Keys BAT calls reg add HKCU\...\Run ^[strings.txt:11]
T1543.003 Create/modify system process child_process.spawn(..., {shell: true}) ^[strings.txt:30]

References

Provenance

  • file.txt — file(1) output (GNU file 5.44)
  • strings.txt — raw JavaScript source (8.5 MB, line-extracted via strings)
  • exiftool.json — ExifTool 12.76 metadata
  • triage.json — triage-fast pipeline output (schema v1)
  • dynamic-analysis.md — CAPE skipped (JS source not supported)
  • Decoded payload SHA-256s computed via Python 3.12 hashlib.sha256() from word-list index reconstruction