ET MALWARE BPFDoor Direct Connection Client Response (Outbound)

SID: 2065015Rev: 10 views
Sourceet/open
CreatedSeptember 30, 2025
UpdatedOctober 1, 2025
Classificationcommand-and-control
alert tcp $HOME_NET any -> any any (msg:"ET MALWARE BPFDoor Direct Connection Client Response (Outbound)"; flow:established,to_client; dsize:4; flags:PA; window:510; content:"|33 34 35 38|"; reference:url,www.trendmicro.com/en_us/research/25/d/bpfdoor-hidden-controller.html; classtype:command-and-control; sid:2065015; rev:1; metadata:affected_product Linux, affected_product MySQL, attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2025_09_30, deployment Perimeter, confidence Medium, signature_severity Major, tag Backdoor, tag BPF, updated_at 2025_10_01, mitre_tactic_id TA0010, mitre_tactic_name Exfiltration, mitre_technique_id T1041, mitre_technique_name Exfiltration_Over_C2_Channel;)

Metadata

affected productMySQL
attack targetClient_Endpoint
tls stateTLSDecrypt
created at2025_09_30
deploymentPerimeter
confidenceMedium
signature severityMajor
tagBPF
updated at2025_10_01
mitre tactic idTA0010
mitre tactic nameExfiltration
mitre technique idT1041
mitre technique nameExfiltration_Over_C2_Channel

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!