Hartrell, Greg. (2002, August). Get a handle on cd00r: The invisible backdoor. Retrieved October 13, 2018.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
Malwarecd00r | cd00r can discover the IP for the network interface on the compromised device. |
| T1040 Network Sniffing |
Malwarecd00r | cd00r can use the libpcap library to monitor captured packets for specifc sequences. |
| T1095 Non-Application Layer Protocol |
Malwarecd00r | cd00r can monitor incoming C2 communications sent over TCP to the compromised host. |
| T1205.001 Port Knocking |
Malwarecd00r | cd00r can monitor for a single TCP-SYN packet to be sent in series to a configurable set of ports (200, 80, 22, 53 and 3 in the original code) before opening a port for communication. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.