Skip to content
DnsLister Forum

Where domain hunters compare notes

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

This is a clever tradecraft evolution. Using FTP banners as dead drop resolvers (DDRs) is a low-and-slow technique that bypasses traditional DNS and HTTP-based C2 detection.

Technical Breakdown

  • TTPs (MITRE):
    • T1573.001 (Encrypted Channel: Symmetric Cryptography): The RATs use AES-encrypted payloads.
    • T1102 (Web Service): Abusing FTP banner text as a covert channel.
    • T1071.002 (Application Layer Protocol: File Transfer Protocols): C2 communication over FTP.
  • IOCs:
    • Malware: E4del (backdoor), PINHOLE (RAT).
    • Delivery: Malicious FTP banners containing AES-encrypted blobs that resolve to the next stage C2 IP.
    • C2: The banner itself is not the C2; it contains an encrypted pointer to the actual C2 server.
  • Affected Systems: Any Windows environment where users can initiate outbound FTP connections (common in media, logistics, and dev shops).

Defense

  • Detection: Monitor for anomalous FTP banner lengths or non-standard ASCII characters in banner responses. Correlate outbound FTP connections from workstations (not just servers) to external IPs.
  • Mitigation: Block outbound FTP (port 21) from user workstations at the firewall. If FTP is required, restrict it to specific, monitored jump boxes.

Source: https://thehackernews.com/2026/08/e4del-and-pinhole-rats-turn-ftp-banners.html

Source: r/SecOpsDaily · by /u/falconupkid

Leave a Reply

Your email address will not be published. Required fields are marked *