Common Information
Type Value
Value
rule apt_ext4_linuxlistener {
	meta:
		description = "Detects Unique Linux Backdoor, Ext4"
		author = "Insikt Group, Recorded Future"
		TLP = "White"
		date = "2018-08-14"
		md5_x64 = "d08de00e7168a441052672219e717957"
	strings:
		$s1 = "rm /tmp/0baaf161db39"
		$op1 = { 3C 61 0F }
		$op2 = { 3C 6E 0F }
		$op3 = { 3C 74 0F }
		$op4 = { 3C 69 0F }
		$op5 = { 3C 3A 0F }
	condition:
		all of them
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Pdf 2018-08-20 16 Chinese Cyberespionage Originating From Tsinghua University Infrastructure