New Trojan on the block [CIA Trojan]
"Chris Norton" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Ok hopefully my last post and a new snort rule for the new CIA Trojan/Backdoor 1.23 beta. Although the readme states that the code is Semi-Polymorhic and that only 7% of the time is the signature the same but when I looked at 2 .exe files made by the main program they were almost the same except for the features added to the second one to see if it would make a different file. You can use the following snort rule to identify if the trojan is being downloaded or uploaded on your network: alert ip any any -> any any (msg:"Possible CIA Trojan/Backdoor download/upload attempt"; content:"|6C 75 66 6A 65 6F 6F|"; classtype:trojan-activity; sid:5000826; rev:1;) this string appears in all of the Trojan/Backdoor's and is decoded as: lufjeoo ------------------------------------------------------------- Chris Norton - UAT Student Software Engineering Network Defense _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions