FTP Banner Dead Drops Deliver E4del And PINHOLE RAT Commands
Two newly documented RATs, E4del and PINHOLE, use FTP server banners as dead-drop command sources, with SOCRadar tracing chains that involve WebDAV, PowerShell, Cloudflare Workers and injection techniques.

FTP server banners are being used as command-delivery points for two previously undocumented remote access trojans, The Hacker News reported, giving defenders a new malware-delivery pattern to watch outside the usual web-based dead-drop channels.
Security researchers tied the activity to E4del and PINHOLE, two RAT families that retrieve commands from text strings returned by FTP servers when a client connects.
SOCRadar identified the technique as a dead drop resolver method and said MalwareHunterTeam first highlighted the approach early last month.
The E4del chain starts with Spanish-language voucher lures that persuade users to run a Windows Shortcut file.
The shortcut retrieves a command from an FTP banner, reaches a WebDAV server and uses rundll32.exe with conhost to execute a downloaded DLL export.
A separate FTP sequence at 157.254.194[.]31:21 and 167.148.41[.]164:21 leads to PowerShell activity that downloads, extracts and runs a ZIP-hosted binary.
E4del is built as a Node.js RAT embedded inside a digitally signed Electron application posing as Discord.
Its functions include persistence, system fingerprinting, encrypted command-and-control communication, interactive reverse shell access, screenshots, live desktop streaming, file download and additional payload delivery.
SOCRadar's technical report gives the malware a three-state beaconing model.
E4del checks in rapidly during the first 20 seconds after receiving a task, slows to a two-to-five-second interval between 20 and 40 seconds, and then moves to a five-to-nine-second interval after 40 seconds without new commands.
PINHOLE uses the same FTP-banner idea but adds higher-reputation services and Cloudflare Workers into the resolution path.
A banner at 209.99.185[.]38:21 contains PowerShell commands that retrieve a secondary script from a Cloudflare-linked domain, save it under the temporary directory, execute it and delete it.
The payload then moves through a wrapper presented as an update utility from a non-existent Weston Computing Systems Ltd.
The PINHOLE loader uses the Halo's Gate technique before handing the final executable to an Early Bird APC Injection routine inside a suspended legitimate process.
The source described six unpacking layers before the 119 KB native x86-64 payload appears, a sequence designed to complicate endpoint detection.
Once installed, PINHOLE can poll for commands over HTTP GET and POST, upload or download files, execute payloads, run PowerShell commands, enumerate directories and processes, take screenshots, terminate processes by PID and initialize a PowerShell session through anonymous pipes.
Researchers also found a dedicated FTP Stats Panel at 69.48.228[.]126:5000 that tracked script executions, total connections and unique active or blocked IP addresses.
The panel showed only 11 execution events at the time of analysis, leaving the campaign at an early stage rather than a broadly measured outbreak.
FTP-banner abuse is also less stealthy than traditional web dead drops because unusual FTP connections can stand out in monitored environments, but the technique gives attackers another place to hide first-stage instructions before defenders inspect the full payload chain.




















