New Trojan on the block [CIA Trojan]

"Chris Norton" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Ok hopefully my last post and a new snort rule for the new CIA Trojan/Backdoor 1.23 beta.
Although the readme states that the code is Semi-Polymorhic and that only 7%
of the time is the signature the same but when I looked at 2 .exe files made by
the main program they were almost the same except for the features added to
the second one to see if it would make a different file. You can use the following
snort rule to identify if the trojan is being downloaded or uploaded on your network:


alert ip any any -> any any (msg:"Possible CIA Trojan/Backdoor download/upload attempt"; content:"|6C 75 66 6A 65 6F 6F|"; classtype:trojan-activity; sid:5000826; rev:1;)

this string appears in all of the Trojan/Backdoor's and is decoded as: lufjeoo

-------------------------------------------------------------
Chris Norton - UAT Student Software Engineering Network Defense
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.