ATT&CKReferencesHartrell cd00r 2002

Hartrell cd00r 2002

Hartrell, Greg. (2002, August). Get a handle on cd00r: The invisible backdoor. Retrieved October 13, 2018.

Open the source

Techniques2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
Malwarecd00r

cd00r can discover the IP for the network interface on the compromised device.

T1040
Network Sniffing
Malwarecd00r

cd00r can use the libpcap library to monitor captured packets for specifc sequences.

T1095
Non-Application Layer Protocol
Malwarecd00r

cd00r can monitor incoming C2 communications sent over TCP to the compromised host.

T1205.001
Port Knocking
Malwarecd00r

cd00r can monitor for a single TCP-SYN packet to be sent in series to a configurable set of ports (200, 80, 22, 53 and 3 in the original code) before opening a port for communication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.