cd00r

S1204

Malware.View on attack.mitre.org

About this malware

cd00r is an open-source backdoor for UNIX and UNIX-variant operating systems that was orginally released in 2000. cd00r source code is primarily based on a packet-capturing program as it utilizes a sniffer to listen for specific sequences of network traffic or "secret knock" before executing the attacker's code.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1016
System Network Configuration Discovery

cd00r can discover the IP for the network interface on the compromised device.

T1040
Network Sniffing

cd00r can use the libpcap library to monitor captured packets for specifc sequences.

T1095
Non-Application Layer Protocol

cd00r can monitor incoming C2 communications sent over TCP to the compromised host.

T1205.001
Port Knocking

cd00r can monitor for a single TCP-SYN packet to be sent in series to a configurable set of ports (200, 80, 22, 53 and 3 in the original code) before opening a port for communication.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Hartrell cd00r 2002 Open source
    Hartrell, Greg. (2002, August). Get a handle on cd00r: The invisible backdoor. Retrieved October 13, 2018.
  2. Lumen J-Magic JAN 2025 Open source
    Black Lotus Labs. (2025, January 23). The J-Magic Show: Magic Packets and Where to find them. Retrieved February 17, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.