""ET TROJAN Linux Backdoor Linux/Cdorked.A Redirect 2""

SID: 2016814

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2013_05_03, updated_at 2013_05_03

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: from_server,established

Contents:

  • Value: "302"

  • Value: "/index.php?"

  • Value: "mc3VyaT0"

Within:

PCRE: "/^Location\x3a\x20\s?https?\:\/\/[a-f0-9]{16}.[^\r\n]+?\/index.php\?[a-z]=(?:[A-Za-z0-9+\/]{4})(?:[A-Za-z0-9+\/]{2}==|[A-Za-z0-9+\/]{3}=|[A-Za-z0-9+\/]{4})\r$/Hmi"

Special Options:

  • http_stat_code

  • http_header

  • http_header

  • fast_pattern

source