Posted inMalware Analysis
The comeback of DTLMiner
Summary
- DTLMinermakes a comeback and adds exploitation of- CVE-2024-23692vulnerability.
- DTLMinerreplaces the primary domain with- d.0000o[.]xyz, and- t.0000o[.]xyzas the domain for downloading scripts and other components.
- DTLMinernow has fewer modules on both Windows and Linux platforms and obfuscates scripts at most once.
- The DTLMinerlateral movement module removesElastic Search,Solr,Dockerpropagation methods, actual code ofSSH Brute Force Modulehas also been removed and only retains the commands that are executed after a successful exploit.
- DTLMineragain introduces a backdoor module, but like the mining module are executable file, not a fileless module.