2c86df65c4976ae885860d5c8568d545d47e50989e4008f34cb486b0f0eeb327letsdiskusscom: 2c86df65 — Update_12.js, twenty-first confirmed sibling with 21st distinct msvcp140.dll morph
Executive Summary
Twenty-first confirmed sibling in the letsdiskusscom Node.js poem-word-list dropper cluster. Filename Update_12.js (8.5 MB) continues the numbered-suffix steganography template (gentle1, hush2, etc.) and decodes to the same signed RevoSrp.exe + vcruntime DLL payload set shared by all twenty prior siblings, but introduces a twenty-first distinct msvcp140.dll morph (SHA-256 077c6dc7...). Self-contained local installer with BAT-based HKCU Run persistence. No C2. Static-only (CAPE skipped — JavaScript source not supported for detonation).
What It Is
| Field | Value |
|---|---|
| SHA-256 | 2c86df65c4976ae885860d5c8568d545d47e50989e4008f34cb486b0f0eeb327 |
| Filename | Update_12.js |
| Size | 8,456,411 bytes (8.1 MB) |
| Type | JavaScript source, ASCII text, CRLF line terminators, 63,365-char lines ^[file.txt] |
| Family | letsdiskusscom (high-confidence, 21st confirmed sibling) |
| Build | Node.js script, custom 256-word English poem lookup-table with numbered suffixes |
| Payload | Signed RevoSrp.exe (52,400 bytes) + msvcp140.dll (1,012,224 bytes) + vcruntime140.dll (101,672 bytes) + vcruntime140_1.dll (44,328 bytes) + BAT persistence script (440 bytes) |
How It Works
The script defines a 256-word lookup table (wlist) written as an English poem fragment, then encodes five binary payloads as sequences of word indices from that table ^[strings.txt:4-6]. A writePositionsToFile function performs a.indexOf(word) lookups and writes index & 0xFF bytes to disk ^[strings.txt:18-25].
Decoded payloads:
| File | Size | SHA-256 | Notes |
|---|---|---|---|
Microsoft Edge Updates Helper.exe |
52,400 | 8b94af60... |
Same signed RevoSrp.exe as all 20 prior siblings |
msvcp140.dll |
1,012,224 | 077c6dc7... |
21st distinct morph in cluster; MSVC 14.27.29016.0 |
vcruntime140.dll |
101,672 | ff43e813... |
Same as all prior siblings |
vcruntime140_1.dll |
44,328 | 7b8f70dd... |
Same as all prior siblings |
dZiDIakVihSz.bat |
440 | dff20059... |
Same BAT persistence script as all prior siblings |
The staging directory is %ProgramData%\Microsoft Edge Updates Helper dZiDIakVihSz ^[strings.txt:5]. After writing files, the script spawns the BAT with the EXE path as argument, then spawns the EXE directly ^[strings.txt:33-41].
The BAT adds an HKCU Run registry entry pointing to the EXE ^[strings.txt:11].
Steganography variant: Of the 256 words in wlist, 164 carry numbered suffixes (gentle1, hush2, that3 ... fail164) ^[strings.txt:6]. This poisons frequency-analysis tools while preserving the encoding semantics — a.indexOf(word) still resolves correctly because each suffixed token is unique in the lookup table.
C2 Infrastructure
None. The dropper is entirely self-contained; no network calls, no download URLs, no C2 beacons. The threat is the silent payload staging and execution of a signed Revo Uninstaller component under a deceptive directory name.
Interesting Tidbits
- Build-counter filename:
Update_12.jscontinues theUpdate_N.jsnaming pattern seen in siblingsUpdate_3.jsthroughUpdate_25.js, suggesting an internal build counter or campaign wave tracker. - 21st distinct msvcp140.dll: The
msvcp140.dllSHA-256077c6dc7...does not match any of the twenty prior siblings, confirming the builder actively rotates this runtime DLL while reusing the same signed EXE and vcruntime pair. - Same signed payload: The EXE retains its DigiCert Authenticode signature (PKCS#7 overlay, 19,120 bytes) and
RevoSrp.pdbpath, confirming it is the legitimate Revo Uninstaller Pro component repurposed as a masquerade payload. - No obfuscation beyond steganography: Unlike the first sibling (
9dc2cded) which usedjavascript-obfuscator, this sample has no IIFE wrappers, no string-array rotation, no self-defend — just the poem encoding.
Deployable Signatures
YARA rule
rule letsdiskusscom_poem_dropper {
meta:
description = "Node.js poem-word-list dropper (letsdiskusscom cluster)"
author = "PacketPursuit"
date = "2026-08-23"
sha256 = "2c86df65c4976ae885860d5c8568d545d47e50989e4008f34cb486b0f0eeb327"
strings:
$js_fs = "const fs = require('fs');" ascii wide
$js_path = "const path = require('path');" ascii wide
$js_spawn = "const { spawn } = require('child_process');" ascii wide
$app_name = "Microsoft Edge Updates Helper" ascii wide
$func_write = "function writePositionsToFile(listA, listB, outPath)" ascii wide
$wlist = "const wlist = \"gentle hush that wraps the midnight air" ascii wide
$exe = "const exe = \"unwearied tides candle53" ascii wide
$safeMakeDir = "function safeMakeDir(dir)" ascii wide
$launch = "function launchExecutable" ascii wide
condition:
filesize > 5MB and
filesize < 15MB and
4 of ($js_*) and
$app_name and
$func_write and
$wlist and
$exe
}
Sigma rule
title: Node.js poem-word-list dropper execution
description: Detects Node.js scripts spawning EXEs from ProgramData with Microsoft Edge masquerade
logsource:
category: process_creation
product: windows
detection:
selection:
- CommandLine|contains:
- 'node.exe'
- 'Update_*.js'
- ParentImage|endswith: 'node.exe'
spawn:
- Image|endswith:
- 'Microsoft Edge Updates Helper.exe'
- 'RevoSrp.exe'
- CommandLine|contains: 'Microsoft Edge Updates Helper'
condition: selection and spawn
falsepositives:
- Unknown
level: high
IOC list
| Indicator | Value | Type |
|---|---|---|
| SHA-256 (carrier JS) | 2c86df65c4976ae885860d5c8568d545d47e50989e4008f34cb486b0f0eeb327 |
File |
| SHA-256 (decoded EXE) | 8b94af60bb58bc1629edb3b4f6a86ccff5769bb9b96d8826f06686af2d7fc55f |
File |
| SHA-256 (decoded BAT) | dff20059f161090c76f9f45ac2269f2965bdc96023c78c1072f8d1aa66b06919 |
File |
| SHA-256 (msvcp140.dll) | 077c6dc7ac87ebd65e055f99079048032a315eb9f5cf6ce5f669e7c771940aa1 |
File |
| Staging directory | %ProgramData%\Microsoft Edge Updates Helper dZiDIakVihSz |
Path |
| Registry persistence | HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Edge Updates Helper |
Registry |
| Masquerade name | Microsoft Edge Updates Helper |
String |
Behavioral fingerprint
This 8.5 MB JavaScript file defines a 256-word lookup table (an English poem fragment), encodes five binary payloads as word-index sequences, and uses writePositionsToFile to decode them to %ProgramData%\Microsoft Edge Updates Helper <random_suffix>\. It writes a signed RevoSrp.exe, three VC++ runtime DLLs, and a BAT persistence script, then spawns both the BAT and EXE. The BAT adds an HKCU Run registry entry. No network C2. File naming follows Update_N.js build-counter pattern.
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1059.007 | JavaScript execution | Node.js require('fs') + require('child_process') ^[strings.txt:1-3] |
| T1027.002 | Obfuscated Files or Info | 256-word poem lookup-table with numbered-suffix obfuscation ^[strings.txt:6] |
| T1036.005 | Masquerading | Microsoft Edge Updates Helper directory and filename ^[strings.txt:4] |
| T1547.001 | Registry Run Keys | BAT calls reg add HKCU\...\Run ^[strings.txt:11] |
| T1543.003 | Create/modify system process | child_process.spawn(..., {shell: true}) ^[strings.txt:30] |
References
- letsdiskusscom — Entity page for the family
- poem-word-list-steganography — Technique page for the 256-word poem encoding
- natural-language-payload-encoding — Concept page for prose-based payload hiding
- registry-run-persistence — Procedure page for the BAT-based Run key technique
Provenance
file.txt— file(1) output (GNU file 5.44)strings.txt— raw JavaScript source (8.5 MB, line-extracted viastrings)exiftool.json— ExifTool 12.76 metadatatriage.json— triage-fast pipeline output (schema v1)dynamic-analysis.md— CAPE skipped (JS source not supported)- Decoded payload SHA-256s computed via Python 3.12
hashlib.sha256()from word-list index reconstruction