Posted inMalware Analysis
The comeback of DTLMiner
Summary
DTLMinermakes a comeback and adds exploitation ofCVE-2024-23692vulnerability.DTLMinerreplaces the primary domain withd.0000o[.]xyz, andt.0000o[.]xyzas the domain for downloading scripts and other components.DTLMinernow has fewer modules on both Windows and Linux platforms and obfuscates scripts at most once.- The
DTLMinerlateral movement module removesElastic Search,Solr,Dockerpropagation methods, actual code ofSSH Brute Force Modulehas also been removed and only retains the commands that are executed after a successful exploit. DTLMineragain introduces a backdoor module, but like the mining module are executable file, not a fileless module.