THREAT OPS › Threat News › FTP Banners: The New Dead Drop Resolver Delivering Novel RATs
FTP Banners: The New Dead Drop Resolver Delivering Novel RATs
<h1>FTP Banners: The New Dead Drop Resolver Delivering Novel RATs</h1> <p><em>STRU found <a href="https://socradar.io/glossary/threat-actors/">threat actors</a> using FTP banners as Dead Drop Resolvers – legitimate services or protocols abused to host C2 addresses and commands, so the stager never carries them itself. Live since early July 2026 and still active. The infrastructure led to two previ
MITRE ATT&CK techniques
- Windows Management InstrumentationT1047
- Screen CaptureT1113
- System Owner/User DiscoveryT1033
- Acquire InfrastructureT1583
- ServerlessT1583.007
- IP AddressesT1590.005
- JavaScriptT1059.007
- Match Legitimate Resource Name or LocationT1036.005
- Boot or Logon Autostart ExecutionT1547
- Hide ArtifactsT1564
- Symmetric CryptographyT1573.001
- System ChecksT1497.001
- Spearphishing AttachmentT1566.001
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- Native APIT1106
- Deobfuscate/Decode Files or InformationT1140
- Credentials from Password StoresT1555
- Social EngineeringT1684
- MasqueradingT1036
- Process InjectionT1055
- Traffic SignalingT1205
- System Binary Proxy ExecutionT1218
- Electron ApplicationsT1218.015
- Credentials from Web BrowsersT1555.003
- Abuse Elevation Control MechanismT1548
- ProxyT1090
- Command and Scripting InterpreterT1059
- Indicator RemovalT1070
- File and Directory DiscoveryT1083
- Asynchronous Procedure CallT1055.004
- Virtualization/Sandbox EvasionT1497
- Web ServiceT1102
- Web ServicesT1583.006
- Spearphishing AttachmentT1598.002
- Process DiscoveryT1057
- Exfiltration Over C2 ChannelT1041
- PowerShellT1059.001
- File Transfer ProtocolsT1071.002
- Registry Run Keys / Startup FolderT1547.001
- PhishingT1566
- Web ServicesT1584.006
- Obfuscated Files or InformationT1027
- Encrypted ChannelT1573
- CredentialsT1589.001
- Query RegistryT1012
- Security Software DiscoveryT1518.001
- Hidden WindowT1564.003
- Windows Command ShellT1059.003
- File DeletionT1070.004
- ServerlessT1584.007
- Web ProtocolsT1071.001
- Software DiscoveryT1518
- Ingress Tool TransferT1105
- NTFS File AttributesT1564.004
- Dead Drop ResolverT1102.001
- CompressionT1027.015
- Acquire InfrastructureAML.T0008
- ServerlessAML.T0008.004
- Command and Scripting InterpreterAML.T0050
- Reverse ShellAML.T0072
- MasqueradingAML.T0074
- Process DiscoveryAML.T0089
- Virtualization/Sandbox EvasionAML.T0097
Indicators of compromise
- cc615d23122e1d221d9a1e43d64f121d814f0947d1cd7914a772ede5be5ba280sha256
- 117b2b7e7c0deee1f7bf0f154babc09738eac18e810625fab4f54dc8088d731csha256
- e0c41dc44368efdf504b28ce015dd3e91f4e711db12e92c159173f75b5320ddbsha256
- fcc6fdf40f4dea8f508ef0b8c45a657461310a3f7947a8c687b476e0f0b41e26sha256
- 391a605878222f23bf5900a07bc17bedcbda124fb0738d50f6bbb0c1762ae172sha256
- 27587e078b59173a92cf9746ab1839da9196089c00e8b694860361da309142a5sha256
- af769f3bff848bac7b73bf749769424b3df6c9175388980d99e0d6d0193237basha256
- ff88974f51918238f0ea9a74f013ff3ac3c536fce369ead5252ed0137fd32d9esha256
- 1a91dcd678be35849db0329effdaa823md5
- https://en.fofa.info/result?qbase64=KGJhbm5lcj0iY29uaG9zdC5leGUgLS1oZWFkbGVzcyIgfHwgYmFubmVyPSJiaXRzYWRtaW4iIHx8IGJhbm5lcj0icG93ZXJzaGVsbCIgfHwgYmFubmVyPSJTeXN0ZW0uTmV0LldlYkNsaWVudCIpICYmIHBvcnQ9IjIxIg==url
- https://app.any.run/tasks/52f21f2b-af15-4651-8034-6e46775b6918url
- https://www.electronjs.org/docs/latest/why-electronurl
- https://app.any.run/tasks/ff9fa3f0-1e6d-43e3-b922-7f8a7ba185eaurl
- https://blog.sektor7.net/#!res/2021/halosgate.mdurl
- https://persistence-info.github.io/Data/windowsload.htmlurl
- https://mx.pinterest.com/pin/1128292512937332995url
- https://mx.pinterest.com/pin/1128292512937332894/url
- https://www.surveymonkey.com/r/WW5NVT6url
- https://<D7/D8url
- https://<D5/D6url
- https://www.cyberbit.com/endpoint-security/new-early-bird-code-injection-technique-discovered/url
- https://platform.socradar.com/url
- 157.254.194.31ipv4
- 167.148.41.164ipv4
- 124.0.0.0ipv4
- 209.99.185.38ipv4
- 69.48.228.126ipv4
- 72.5.43.81ipv4
- 45.61.136.50ipv4
- 45.87.41.133ipv4
- 185.14.92.162ipv4
- 64.95.13.65ipv4
- nokierojotiarmx.comdomain
Original source: https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/