""ET TROJAN W32/Taidoor.Backdoor CnC Checkin With Default Substitute MAC Address Field""

SID: 2014529

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2012_04_06, updated_at 2012_04_06

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: ".php?id="

  • Value: "121212121212"

Within:

PCRE: "/\x2F[a-z]{5}\x2Ephp\x3Fid\x3D.+121212121212/U"

Special Options:

  • http_uri

  • http_uri

source