Malware
FDMTP
FDMTP is a newly discovered hacking tool developed in .NET, used by Earth Preta. It functions as a simple malware downloader and is based on the TouchSocket framework over the Duplex Message Transport Protocol (DMTP). In one campaign, threat actors embedded FDMTP in the data section of a DLL. This allows it to be launched through DLL side-loading. The embedded network configurations are encoded and encrypted to enhance security and evade detection, utilizing Base64 and DES encryption methods. It has been observed to serve as a secondary control tool, often deployed by the PUBLOAD backdoor.
Indicators of Compromise 5
MITRE ATT&CK TTPs 8
T1021.001 T1053.005 T1055 T1059.007 T1071 T1071.001 T1112 T1204.002
Remote Desktop Protocol
Lateral Movement
Scheduled Task
Execution
Process Injection
Defense Evasion
JavaScript
Execution
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Modify Registry
Defense Evasion
Malicious File
Execution