DinDoor Backdoor Abuses Deno Runtime; Researchers Identify 20 Active C2 Servers

· Original article ↗

Summary

Analysis of two DinDoor samples details their Deno-based execution, victim fingerprinting, and C2 behavior. A query of HTTP response characteristics identified 20 servers active within the week before publication.

Key points

  • The two analyzed MSI samples use PowerShell and the Deno runtime to execute malicious JavaScript, with differences in how their payloads are delivered.
  • Both samples fingerprint infected systems using the username, hostname, memory, and OS release, and use a localhost TCP listener as a mutex.
  • One sample contains a hardcoded JWT linked to campaign information and the domain serialmenot[.]com; the article describes the infrastructure as shared among multiple operators.
  • A HuntSQL query based on HTTP response characteristics identified 20 matching servers across 15 autonomous systems, active within the week before publication.
  • The article recommends monitoring unexpected Deno execution, suspicious command-line patterns and localhost binds, and restricting MSI execution where feasible.

Article Details

Attack Vectors
  • DinDoor is reportedly delivered through phishing or drive-by downloads using MSI installers.
  • migcredit.pdf.msi uses a double extension to resemble a PDF document. The researchers suggest possible targeting of MigCredit, but do not confirm the delivery method or victim.
  • The installers launch PowerShell scripts that install the legitimate Deno runtime if absent and execute attacker-controlled JavaScript without requiring administrator privileges.
  • Installer_v1.21.66.msi displays a fabricated installation error while a VBS launcher silently starts PowerShell. Its JavaScript payload is passed directly to Deno as a base64 data URI rather than written to disk.
  • Both variants fingerprint infected hosts and communicate with HTTP C2 endpoints. The Installer variant uses a hardcoded JWT, retrieves an in-memory second stage, and rotates its C2 index following failures.
Defensive Notes
  • Alert on unexpected deno.exe execution and restrict it to approved developer systems through application control where feasible.
  • Restrict MSI execution to approved users or administrators using AppLocker or WDAC.
  • Monitor for deno.exe -A data:application/javascript;base64 command lines and localhost TCP listeners on ports 10044 or 10091.
  • Treat unexpected deno.exe processes launched beneath powershell.exe or wscript.exe as high-priority investigation leads.
  • Review port 80 responses for the combined Via: 1.1 Caddy, 1.1 Caddy and X-Request-Id headers, particularly with a 404 Not Found response and Content-Length: 13. The researchers used this profile to identify 20 active hosts.
  • The researchers describe an /health response of ok as an additional validation signal for active deployments; differing responses may reflect inactive or not-yet-operational infrastructure.
  • Consider blocking the reported malicious domains and investigating communications with suspect hosting providers.

Indicators of compromise

TypeIndicatorContext
DOMAINaeeracaspsl[.]siteDomain resolving to reported DinDoor host 193.24.123[.]25.
DOMAINannaionovna[.]comDomain resolving to reported DinDoor host 199.91.220[.]216.
DOMAINbitatits[.]surfDomain resolving to reported DinDoor host 199.217.99[.]189.
DOMAINgeneralnewlong[.]comDomain resolving to reported DinDoor host 192.109.200[.]151.
DOMAINhngfbgfbfb[.]cyouDomain resolving to reported DinDoor host 85.192.27[.]152.
DOMAINilspaeysoff[.]siteDomain resolving to reported DinDoor host 193.24.123[.]25.
DOMAINineracaspsl[.]siteDomain resolving to reported DinDoor host 193.24.123[.]25.
DOMAINjusttalken[.]comTLS certificate common name on reported DinDoor host 194.48.141[.]192; resolution was not observed.
DOMAINlandmas[.]infoDomain resolving to reported DinDoor host 146.19.254[.]84.
DOMAINmyspaeysoff[.]siteDomain resolving to reported DinDoor host 193.24.123[.]25.
DOMAINplayerdragonbike[.]comResolving domain and TLS certificate common name associated with reported DinDoor host 209.99.189[.]170.
DOMAINserialmenot[.]comC2 domain used by Installer_v1.21.66.msi; described as shared multi-tenant malware infrastructure.
DOMAINweaplink[.]comDomain resolving to reported DinDoor host 193.24.123[.]25.
HOSTNAMEagilemast3r[.]duckdns[.]orgSpecific dynamic-DNS hostname resolving to reported DinDoor host 192.109.200[.]151.
HOSTNAMEbandage[.]healthydefinitetrunk[.]comResolving hostname and TLS certificate common name associated with reported DinDoor host 138.124.240[.]76.
HOSTNAMEgrafana[.]healthydefinitetrunk[.]comResolving hostname associated with reported DinDoor host 138.124.240[.]77.
HOSTNAMEsurgery[.]healthydefinitetrunk[.]comResolving hostname associated with reported DinDoor host 2.27.122[.]16.
IPV4138[.]124[.]240[.]76Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4138[.]124[.]240[.]77Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4140[.]82[.]18[.]48Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4146[.]19[.]254[.]84Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4178[.]104[.]137[.]180Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4178[.]16[.]52[.]191Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4185[.]218[.]19[.]117Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4192[.]109[.]200[.]151Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4193[.]233[.]82[.]43Reported DinDoor server used to illustrate an HTTP request to the /health endpoint.
IPV4193[.]24[.]123[.]25Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4194[.]48[.]141[.]192Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4199[.]217[.]99[.]189Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4199[.]91[.]220[.]142Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4199[.]91[.]220[.]216Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV42[.]26[.]117[.]169Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV42[.]27[.]122[.]16Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV4209[.]99[.]189[.]170Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV445[.]135[.]180[.]200Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV445[.]151[.]106[.]88Reported DinDoor infrastructure host identified through its HTTP response profile.
IPV485[.]192[.]27[.]152Reported DinDoor infrastructure host identified through its HTTP response profile.
SHA2562a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5SHA-256 of the analyzed DinDoor sample Installer_v1.21.66.msi.
SHA2567b793c54a927da36649eb62b9481d5bcf1e9220035d95bbfb85f44a6cc9541aeSHA-256 of the analyzed DinDoor installer migcredit.pdf.msi.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationPayloads are base64-encoded, and the migcredit variant uses javascript-obfuscator with a shuffled 181-entry string array.T1033 · System Owner/User DiscoveryBoth variants include the system's USERNAME in their host fingerprint.T1036.007 · Double File Extensionmigcredit.pdf.msi uses a double extension to pass the malicious installer off as a PDF document.T1059.001 · PowerShellJuliet_widget15.ps1 and tango_utility84.ps1 install Deno if needed and launch the JavaScript payload.T1059.003 · Windows Command ShellThe migcredit installer launches its PowerShell script through cmd.exe.T1059.005 · Visual BasicInstaller_v1.21.66.msi uses error.vbs for a fabricated error dialog and Viper_controller36.vbs to silently launch PowerShell.T1059.007 · JavaScriptDinDoor runs attacker-controlled JavaScript using Deno; one variant executes it directly from a base64 data URI.T1071.001 · Web ProtocolsDinDoor communicates with C2 using HTTP GET health checks and recurring requests to /event or JWT-bearing /mv2 paths.T1082 · System Information DiscoveryBoth variants collect hostname, total memory, and OS release information to construct a host fingerprint.T1105 · Ingress Tool TransferDinDoor retrieves follow-on payloads; the Installer variant's second stage remains in memory.T1140 · Deobfuscate/Decode Files or InformationJuliet_widget15.ps1 decodes embedded base64 JavaScript before writing it to Uniform_system17.js.T1189 · Drive-by CompromiseThe article reports drive-by downloads as a DinDoor MSI delivery method.T1204.002 · Malicious FileExecution of the malicious MSI installers initiates the DinDoor infection chain.T1218.007 · Msiexecmsiexec.exe executes the malicious installers and initiates their script-based payload chains.T1497.001 · System ChecksThe Installer variant's child process enumerates GPUs using Get-WmiObject Win32_VideoController, which the researchers assess as likely sandbox checking.T1564.003 · Hidden WindowThe script launchers hide execution windows, including a VBS launcher that invokes PowerShell with window style 0.T1566 · PhishingThe article reports phishing as a DinDoor delivery method without establishing a specific phishing subtype.

People

Threat Actors

Malware

Vendors

Aeza Group LLCIP 85.192.27[.]152 N/A hngfbgfbfb[.]cyou AEZA GROUP LLC, DEBL Networkssingle provider accounting for a majority of the cluster. Several networks in Figure 05 (PROSPERO 000, BL Networks, ZhyouiSat Communications, and AEZA Group) have been identified as bulletproof hosters or slow toBlueVPS OUIP 146.19.254[.]84 N/A landmas[.]info BlueVPS OU, NLDigital Hosting Provider LLCIP 193.233.82[.]43 N/A N/A Digital Hosting Provider LLC, NLHetzner Online GmbHIP 178.104.137[.]180 N/A N/A Hetzner Online GmbH, DELet's Encryptour research, though a handful of hosts did have a TLS certificate subject common name (issued by Let's Encrypt) pointing to domains that could be used in future attacks. Domains registered via Tucows and usingMHost LLCIP 45.151.106[.]88 N/A N/A MHost LLC, NLNEKOBYTE INTERNATIONAL LIMITEDIP 138.124.240[.]76 bandage.healthydefinitetrunk[.]com bandage.healthydefinitetrunk[.]com NEKOBYTE INTERNATIONAL LIMITED, DENjallapointing to domains that could be used in future attacks. Domains registered via Tucows and using Njalla for DNS nameservers were seen consistently across the host results.Omegatech LTDIP 178.16.52[.]191 N/A N/A Omegatech LTD, DEPfcloud UGagilemast3r.duckdns[.]org Pfcloud UG, NLPROSPERO OOOaeeracaspsl[.]site PROSPERO OOO, RUSKN Subnet & Telecom LtdIP 209.99.189[.]170 playerdragonbike[.]com playerdragonbike[.]com SKN Subnet & Telecom Ltd, USSOLLUTIUM EU Sp z.o.o.IP 45.135.180[.]200 N/A N/A SOLLUTIUM EU Sp z.o.o., NLThe Constant Company, LLCIP 140.82.18[.]48 N/A N/A The Constant Company, LLC, USTucowsby Let's Encrypt) pointing to domains that could be used in future attacks. Domains registered via Tucows and using Njalla for DNS nameservers were seen consistently across the host results.VDSka hostingIP 194.48.141[.]192 justtalken[.]com N/A VDSka hosting, NLZhouyiSat CommunicationsIP 185.218.19[.]117 N/A N/A ZhouyiSat Communications, DE

Products

Tools

Countries

Industries

Related Articles