b4d2dda66b99ed120f83232168035aa60ca72ff58dd05201b14f8189b82d6236letsdiskusscom: b4d2dda6 — Update_21.js, twenty-ninth confirmed sibling with twenty-ninth distinct msvcp140.dll morph
Executive Summary
The twenty-ninth confirmed sibling of the letsdiskusscom Node.js dropper cluster. A 9.5 MB JavaScript file (Update_21.js) uses numbered-suffix poem-word-list steganography to embed a signed Revo Uninstaller component (RevoSrp.exe) plus three VC++ runtime DLLs and a BAT-based registry persistence script. The carrier is self-contained: no network C2. Static-only analysis (CAPE skipped — JS source is not a supported binary class).^[file.txt]^[dynamic-analysis.md]
What It Is
| Field | Value |
|---|---|
| SHA-256 | b4d2dda66b99ed120f83232168035aa60ca72ff58dd05201b14f8189b82d6236 |
| Filename | Update_21.js |
| Size | 9,527,277 bytes |
| File type | JavaScript source, ASCII text, with very long lines (63,365), CRLF terminators^[file.txt] |
| ssdeep | 6144:4ubnYpscZ3SqA5mPYsTvQw1z8jBZlLtH+Bp89S5mfsMwpNAVwS0msFJvXiESUWjf:WPDT6^[ssdeep.txt] |
| tlsh | 29A6CFAB6DEC361D3000B1C2F48521F5EA621336DBDE12D9B8F924337AF649AC46D746^[tlsh.txt] |
| Family | letsdiskusscom — high-confidence cluster sibling |
All embedded payload hashes match the invariant set observed across all 28 prior siblings except for msvcp140.dll, which rotates for the twenty-ninth time:
| Embedded file | SHA-256 | Size | Notes |
|---|---|---|---|
Microsoft Edge Updates Helper.exe |
8b94af60bb58bc1629edb3b4f6a86ccff5769bb9b96d8826f06686af2d7fc55f |
52,400 B | Signed RevoSrp.exe (VS Revo Group, DigiCert Trusted G4), MSVC 14.44, compiled 2025-06-02. Invariant across cluster. |
msvcp140.dll |
7f0888f5c41d81ef2c76fd6da1202b24c925fd35ea6a670ae6598764a6dab3ce |
1,161,216 B | Twenty-ninth distinct morph. MSVC 14.27.29016.0, compiled 2020-06-16. |
vcruntime140.dll |
ff43e813785ee948a937b642b03050bb4b1c6a5e23049646b891a66f65d4c833 |
101,672 B | Invariant across cluster. Microsoft-signed. |
vcruntime140_1.dll |
7b8f70dd3bdae110e61823d1ca6fd8955a5617119f5405cdd6b14cad3656dfc7 |
44,328 B | Invariant across cluster. Microsoft-signed. |
CN0raP8J4vup.bat |
dff20059f161090c76f9f45ac2269f2965bdc96023c78c1072f8d1aa66b06919 |
440 B | HKCU Run persistence script. Invariant across cluster. |
How It Works
The script defines a 256-word English poem lookup table (wlist) and five encoded payload strings (exe, dll1, dll2, dll3, bat).^[strings.txt:6] The lookup table is split: indices 0–91 are plain vocabulary words; indices 92–255 are suffixed versions (gentle1, hush2, ... fail164).^[strings.txt:6] The encoded payloads use only the suffixed half, defeating naive word-frequency clustering.
At runtime, writePositionsToFile splits the lookup table, maps each payload word to its index, and writes index & 0xFF to disk as raw bytes.^[strings.txt:18-25] Files are staged to %ProgramData%\Microsoft Edge Updates Helper CN0raP8J4vup\.^[strings.txt:5]
After writing, the script spawns the BAT with shell: true, which adds HKCU\Software\Microsoft\Windows\CurrentVersion\Run persistence pointing to the EXE path, then launches the EXE.^[strings.txt:29-40] The BAT file also accepts a command-line argument for the EXE path, but the caller passes the path explicitly.^[strings.txt:40]
Decompiled Behavior
No PE decompilation performed — the carrier is JavaScript source, not a binary. The embedded RevoSrp.exe is the same signed payload analyzed in all prior siblings; see letsdiskusscom entity page for its import surface and Authenticode chain.^[entities/letsdiskusscom.md]
C2 Infrastructure
None. The sample is a fully self-contained local installer. No network URLs, IPs, domains, or callback mechanisms are present in the carrier. The threat is silent payload staging + execution + persistence, not remote C2.^[strings.txt]
Interesting Tidbits
- The
Update_21.jsfilename continues the internal build-counter pattern observed sinceUpdate_1.jsthroughUpdate_25.js. This suggests a builder that auto-increments a counter per generated sample.^[metadata.json] - The staging directory suffix
CN0raP8J4vupis a random alphanumeric string, unique per sibling, confirming builder-level randomization of the install path.^[strings.txt:5] - The BAT payload is assigned to both
autorunPathanddll4Pathin the source — a minor variable-reuse quirk that does not affect execution.^[strings.txt:13-17] - The
msvcp140.dllin this sample is the twenty-ninth distinct morph, continuing the builder's practice of rotating a single DLL while keeping the EXE and other DLLs invariant. This may be an attempt to evade hash-based detection or simply a side effect of pulling the DLL from different MSVC redistributable packages.^[entities/letsdiskusscom.md]
How To Mess With It (Homelab Replication)
The poem-word-list steganography is trivial to replicate. See the Reproduce on your own VMs section at poem-word-list-steganography for a working Python encoder/decoder. To produce a sample with the same behavioral fingerprint:
- Encode
RevoSrp.exeand the three DLLs using the 256-word lookup table with numbered suffixes. - Wrap in a Node.js script that calls
fs.mkdirSyncandfs.writeFileSync. - Add the BAT launcher with
child_process.spawn(..., {shell: true}). - Verify: the resulting
.jsshould be ~7–11 MB with extremely long lines and thewritePositionsToFilefunction signature.
Deployable Signatures
YARA
rule letsdiskusscom_poem_stego_js {
meta:
description = "Node.js poem-word-list steganography dropper (letsdiskusscom cluster)"
author = "PacketPursuit"
date = "2026-08-24"
sha256 = "b4d2dda66b99ed120f83232168035aa60ca72ff58dd05201b14f8189b82d6236"
strings:
$func1 = "writePositionsToFile" ascii wide
$func2 = "safeMakeDir" ascii wide
$func3 = "launchExecutable" ascii wide
$app = "Microsoft Edge Updates Helper" ascii wide
$wlist = "gentle hush that wraps the midnight air" ascii wide
$exePath = "Microsoft Edge Updates Helper.exe" ascii wide
$dll1 = "msvcp140.dll" ascii wide
$dll2 = "vcruntime140.dll" ascii wide
$bat = "CN0raP8J4vup.bat" ascii wide
$reg = "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run" ascii wide
condition:
filesize > 1MB and
$func1 and $app and $wlist and
3 of ($dll*, $bat, $reg)
}
Sigma
title: letsdiskusscom Node.js Dropper Execution
logsource:
product: windows
category: process_creation
detection:
selection_node:
Image|endswith: '\node.exe'
CommandLine|contains: 'Update_'
selection_bat:
ParentImage|endswith: '\node.exe'
CommandLine|contains: 'CN0raP8J4vup.bat'
selection_exe:
ParentImage|endswith: '\cmd.exe'
Image|endswith: '\Microsoft Edge Updates Helper.exe'
condition: selection_node and (selection_bat or selection_exe)
falsepositives:
- Unknown
level: high
IOCs
| Type | Value |
|---|---|
| SHA-256 (carrier) | b4d2dda66b99ed120f83232168035aa60ca72ff58dd05201b14f8189b82d6236 |
| SHA-256 (embedded EXE) | 8b94af60bb58bc1629edb3b4f6a86ccff5769bb9b96d8826f06686af2d7fc55f |
| SHA-256 (msvcp140.dll) | 7f0888f5c41d81ef2c76fd6da1202b24c925fd35ea6a670ae6598764a6dab3ce |
| Staging directory | %ProgramData%\Microsoft Edge Updates Helper CN0raP8J4vup |
| Registry persistence | HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Edge Updates Helper |
| Process tree | node.exe → cmd.exe /c CN0raP8J4vup.bat → Microsoft Edge Updates Helper.exe |
Behavioral Fingerprint
A Node.js script (typically named Update_N.js, 7–11 MB) writes five files to a fake Microsoft Edge Updates Helper directory under %ProgramData%: a 52 KB Authenticode-signed EXE (RevoSrp.exe), three Microsoft VC++ runtime DLLs, and a 440-byte BAT script. The BAT adds an HKCU\...\Run registry entry for the EXE and then launches it. The carrier contains no network C2 and no obfuscation beyond the poem-word-list encoding of the embedded binaries.
Detection Signatures
| ATT&CK ID | Technique | Evidence |
|---|---|---|
| T1059.007 | JavaScript / Node.js execution | require('fs'), require('child_process'), spawn(..., {shell: true})^[strings.txt:1-3] |
| T1027.002 | Obfuscated Files or Information | Numbered-suffix poem-word-list steganography (gentle1, hush2, etc.) maps words to byte indices 0x00–0xFF.^[strings.txt:6] |
| T1036.005 | Match Legitimate Name or Location | Microsoft Edge Updates Helper directory and EXE name masquerade.^[strings.txt:4-5] |
| T1547.001 | Registry Run Keys | BAT script writes HKCU\Software\Microsoft\Windows\CurrentVersion\Run value pointing to the staged EXE.^[strings.txt:29-40] |
| T1543.003 | Create or Modify System Process | child_process.spawn with shell: true and stdio: 'inherit' launches the BAT and then the EXE directly.^[strings.txt:29-41] |
References
- letsdiskusscom — Entity page for the family (28 prior siblings)
- poem-word-list-steganography — Technique page for the 256-word poem encoding
- natural-language-payload-encoding — Concept page for prose-based payload hiding
- registry-run-persistence — Procedure page for the BAT-based Run key technique
Provenance
Analysis based on static extraction from the JavaScript carrier. Payloads decoded by replicating the writePositionsToFile index-mapping logic in Python. File-type and metadata from file and exiftool. No dynamic execution performed — CAPE skipped because the carrier is JavaScript source.^[file.txt]^[exiftool.json]^[dynamic-analysis.md]