typeanalysisfamilyletsdiskusscomconfidencehighcreated2026-08-24updated2026-08-24loaderscriptnodejsobfuscationevasionpersistence
SHA-256: b4d2dda66b99ed120f83232168035aa60ca72ff58dd05201b14f8189b82d6236

letsdiskusscom: b4d2dda6 — Update_21.js, twenty-ninth confirmed sibling with twenty-ninth distinct msvcp140.dll morph

Executive Summary

The twenty-ninth confirmed sibling of the letsdiskusscom Node.js dropper cluster. A 9.5 MB JavaScript file (Update_21.js) uses numbered-suffix poem-word-list steganography to embed a signed Revo Uninstaller component (RevoSrp.exe) plus three VC++ runtime DLLs and a BAT-based registry persistence script. The carrier is self-contained: no network C2. Static-only analysis (CAPE skipped — JS source is not a supported binary class).^[file.txt]^[dynamic-analysis.md]

What It Is

Field Value
SHA-256 b4d2dda66b99ed120f83232168035aa60ca72ff58dd05201b14f8189b82d6236
Filename Update_21.js
Size 9,527,277 bytes
File type JavaScript source, ASCII text, with very long lines (63,365), CRLF terminators^[file.txt]
ssdeep 6144:4ubnYpscZ3SqA5mPYsTvQw1z8jBZlLtH+Bp89S5mfsMwpNAVwS0msFJvXiESUWjf:WPDT6^[ssdeep.txt]
tlsh 29A6CFAB6DEC361D3000B1C2F48521F5EA621336DBDE12D9B8F924337AF649AC46D746^[tlsh.txt]
Family letsdiskusscom — high-confidence cluster sibling

All embedded payload hashes match the invariant set observed across all 28 prior siblings except for msvcp140.dll, which rotates for the twenty-ninth time:

Embedded file SHA-256 Size Notes
Microsoft Edge Updates Helper.exe 8b94af60bb58bc1629edb3b4f6a86ccff5769bb9b96d8826f06686af2d7fc55f 52,400 B Signed RevoSrp.exe (VS Revo Group, DigiCert Trusted G4), MSVC 14.44, compiled 2025-06-02. Invariant across cluster.
msvcp140.dll 7f0888f5c41d81ef2c76fd6da1202b24c925fd35ea6a670ae6598764a6dab3ce 1,161,216 B Twenty-ninth distinct morph. MSVC 14.27.29016.0, compiled 2020-06-16.
vcruntime140.dll ff43e813785ee948a937b642b03050bb4b1c6a5e23049646b891a66f65d4c833 101,672 B Invariant across cluster. Microsoft-signed.
vcruntime140_1.dll 7b8f70dd3bdae110e61823d1ca6fd8955a5617119f5405cdd6b14cad3656dfc7 44,328 B Invariant across cluster. Microsoft-signed.
CN0raP8J4vup.bat dff20059f161090c76f9f45ac2269f2965bdc96023c78c1072f8d1aa66b06919 440 B HKCU Run persistence script. Invariant across cluster.

How It Works

The script defines a 256-word English poem lookup table (wlist) and five encoded payload strings (exe, dll1, dll2, dll3, bat).^[strings.txt:6] The lookup table is split: indices 0–91 are plain vocabulary words; indices 92–255 are suffixed versions (gentle1, hush2, ... fail164).^[strings.txt:6] The encoded payloads use only the suffixed half, defeating naive word-frequency clustering.

At runtime, writePositionsToFile splits the lookup table, maps each payload word to its index, and writes index & 0xFF to disk as raw bytes.^[strings.txt:18-25] Files are staged to %ProgramData%\Microsoft Edge Updates Helper CN0raP8J4vup\.^[strings.txt:5]

After writing, the script spawns the BAT with shell: true, which adds HKCU\Software\Microsoft\Windows\CurrentVersion\Run persistence pointing to the EXE path, then launches the EXE.^[strings.txt:29-40] The BAT file also accepts a command-line argument for the EXE path, but the caller passes the path explicitly.^[strings.txt:40]

Decompiled Behavior

No PE decompilation performed — the carrier is JavaScript source, not a binary. The embedded RevoSrp.exe is the same signed payload analyzed in all prior siblings; see letsdiskusscom entity page for its import surface and Authenticode chain.^[entities/letsdiskusscom.md]

C2 Infrastructure

None. The sample is a fully self-contained local installer. No network URLs, IPs, domains, or callback mechanisms are present in the carrier. The threat is silent payload staging + execution + persistence, not remote C2.^[strings.txt]

Interesting Tidbits

  • The Update_21.js filename continues the internal build-counter pattern observed since Update_1.js through Update_25.js. This suggests a builder that auto-increments a counter per generated sample.^[metadata.json]
  • The staging directory suffix CN0raP8J4vup is a random alphanumeric string, unique per sibling, confirming builder-level randomization of the install path.^[strings.txt:5]
  • The BAT payload is assigned to both autorunPath and dll4Path in the source — a minor variable-reuse quirk that does not affect execution.^[strings.txt:13-17]
  • The msvcp140.dll in this sample is the twenty-ninth distinct morph, continuing the builder's practice of rotating a single DLL while keeping the EXE and other DLLs invariant. This may be an attempt to evade hash-based detection or simply a side effect of pulling the DLL from different MSVC redistributable packages.^[entities/letsdiskusscom.md]

How To Mess With It (Homelab Replication)

The poem-word-list steganography is trivial to replicate. See the Reproduce on your own VMs section at poem-word-list-steganography for a working Python encoder/decoder. To produce a sample with the same behavioral fingerprint:

  1. Encode RevoSrp.exe and the three DLLs using the 256-word lookup table with numbered suffixes.
  2. Wrap in a Node.js script that calls fs.mkdirSync and fs.writeFileSync.
  3. Add the BAT launcher with child_process.spawn(..., {shell: true}).
  4. Verify: the resulting .js should be ~7–11 MB with extremely long lines and the writePositionsToFile function signature.

Deployable Signatures

YARA

rule letsdiskusscom_poem_stego_js {
    meta:
        description = "Node.js poem-word-list steganography dropper (letsdiskusscom cluster)"
        author = "PacketPursuit"
        date = "2026-08-24"
        sha256 = "b4d2dda66b99ed120f83232168035aa60ca72ff58dd05201b14f8189b82d6236"
    strings:
        $func1 = "writePositionsToFile" ascii wide
        $func2 = "safeMakeDir" ascii wide
        $func3 = "launchExecutable" ascii wide
        $app = "Microsoft Edge Updates Helper" ascii wide
        $wlist = "gentle hush that wraps the midnight air" ascii wide
        $exePath = "Microsoft Edge Updates Helper.exe" ascii wide
        $dll1 = "msvcp140.dll" ascii wide
        $dll2 = "vcruntime140.dll" ascii wide
        $bat = "CN0raP8J4vup.bat" ascii wide
        $reg = "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run" ascii wide
    condition:
        filesize > 1MB and
        $func1 and $app and $wlist and
        3 of ($dll*, $bat, $reg)
}

Sigma

title: letsdiskusscom Node.js Dropper Execution
logsource:
    product: windows
    category: process_creation
detection:
    selection_node:
        Image|endswith: '\node.exe'
        CommandLine|contains: 'Update_'
    selection_bat:
        ParentImage|endswith: '\node.exe'
        CommandLine|contains: 'CN0raP8J4vup.bat'
    selection_exe:
        ParentImage|endswith: '\cmd.exe'
        Image|endswith: '\Microsoft Edge Updates Helper.exe'
    condition: selection_node and (selection_bat or selection_exe)
falsepositives:
    - Unknown
level: high

IOCs

Type Value
SHA-256 (carrier) b4d2dda66b99ed120f83232168035aa60ca72ff58dd05201b14f8189b82d6236
SHA-256 (embedded EXE) 8b94af60bb58bc1629edb3b4f6a86ccff5769bb9b96d8826f06686af2d7fc55f
SHA-256 (msvcp140.dll) 7f0888f5c41d81ef2c76fd6da1202b24c925fd35ea6a670ae6598764a6dab3ce
Staging directory %ProgramData%\Microsoft Edge Updates Helper CN0raP8J4vup
Registry persistence HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Edge Updates Helper
Process tree node.exe → cmd.exe /c CN0raP8J4vup.bat → Microsoft Edge Updates Helper.exe

Behavioral Fingerprint

A Node.js script (typically named Update_N.js, 7–11 MB) writes five files to a fake Microsoft Edge Updates Helper directory under %ProgramData%: a 52 KB Authenticode-signed EXE (RevoSrp.exe), three Microsoft VC++ runtime DLLs, and a 440-byte BAT script. The BAT adds an HKCU\...\Run registry entry for the EXE and then launches it. The carrier contains no network C2 and no obfuscation beyond the poem-word-list encoding of the embedded binaries.

Detection Signatures

ATT&CK ID Technique Evidence
T1059.007 JavaScript / Node.js execution require('fs'), require('child_process'), spawn(..., {shell: true})^[strings.txt:1-3]
T1027.002 Obfuscated Files or Information Numbered-suffix poem-word-list steganography (gentle1, hush2, etc.) maps words to byte indices 0x00–0xFF.^[strings.txt:6]
T1036.005 Match Legitimate Name or Location Microsoft Edge Updates Helper directory and EXE name masquerade.^[strings.txt:4-5]
T1547.001 Registry Run Keys BAT script writes HKCU\Software\Microsoft\Windows\CurrentVersion\Run value pointing to the staged EXE.^[strings.txt:29-40]
T1543.003 Create or Modify System Process child_process.spawn with shell: true and stdio: 'inherit' launches the BAT and then the EXE directly.^[strings.txt:29-41]

References

Provenance

Analysis based on static extraction from the JavaScript carrier. Payloads decoded by replicating the writePositionsToFile index-mapping logic in Python. File-type and metadata from file and exiftool. No dynamic execution performed — CAPE skipped because the carrier is JavaScript source.^[file.txt]^[exiftool.json]^[dynamic-analysis.md]