# SIGS: W32/Badspace.Backdoor

**URL:** <https://community.emergingthreats.net/t/sigs-w32-badspace-backdoor/1630>\
**Category:** Rule Signatures\
**Created:** [May 13, 2024, 10:31am UTC](https://community.emergingthreats.net/t/sigs-w32-badspace-backdoor/1630 "2024-05-13T10:31:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kevross33](https://avatars.discourse-cdn.com/v4/letter/k/82dd89/32.png) [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Post date:** [May 13, 2024, 10:31am UTC](https://community.emergingthreats.net/t/sigs-w32-badspace-backdoor/1630/1 "2024-05-13T10:31:23Z")

</div>

Hi,

Here is a backdoor I have given a temporary name based on the error in the user agent of extra space as all AV names are generic. You can get the PCAP from [&nbsp;6a195e6111c9a4b8c874d51937b53cd5b4b78efc32f7bb255012d05087586d8f | Triage](https://tria.ge/240430-s7lnpacb59/behavioral1). The POST body is obsucated/encrypted as is the results of the base64 cookie value but the user agent is a good but very specific match given the error they have made (Mozilla / 4.0 ).

alert tcp $HOME\_NET any → $EXTERNAL\_NET $HTTP\_PORTS (msg:“ET TROJAN W32/Badspace.Backdoor POST Request”; flow:established,to\_server; content:“POST”; http\_method; urilen:1; content:“/” http\_uri; content:“Cookie|3A| “; http\_header; content:“User-Agent|3A| Mozilla / 4.0 (compatible|3B| MSIE 6.0|3B| Windows NT 5.1|3B| [SV1|3B|.NET](http://SV1%7C3B%7C.NET) CLR 1.0.3705)”; http\_header; fast\_pattern:12,20; content:“Host|3A|” http\_header; content:”.”; http\_header; within:4; content:“.”; http\_header; within:4; content:“.”; http\_header; within:4; content:!“Referer|3A|”; http\_header; pcre:“/Host\x3A\x20\d{1,3}\x2E\d{1,3}\x2E\d{1,3}\x2E\d{1,3}/H”; classtype:trojan-activity; reference:md5,c16bdc61bbc82e9668f8cee9cc5c94c5; sid:172111; rev:1;)

alert tcp $HOME\_NET any → $EXTERNAL\_NET $HTTP\_PORTS (msg:“ET TROJAN W32/Badspace.Backdoor GET Request”; flow:established,to\_server; content:“GET”; http\_method; urilen:1; content:“/” http\_uri; content:“Cookie|3A| “; http\_header; content:“User-Agent|3A| Mozilla / 4.0 (compatible|3B| MSIE 6.0|3B| Windows NT 5.1|3B| [SV1|3B|.NET](http://SV1%7C3B%7C.NET) CLR 1.0.3705)”; http\_header; fast\_pattern:12,20; content:“Host|3A|” http\_header; content:”.”; http\_header; within:4; content:“.”; http\_header; within:4; content:“.”; http\_header; within:4; pcre:“/Host\x3A\x20\d{1,3}\x2E\d{1,3}\x2E\d{1,3}\x2E\d{1,3}/H”; classtype:trojan-activity; reference:md5,c16bdc61bbc82e9668f8cee9cc5c94c5; sid:172112; rev:1;)

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [May 13, 2024, 9:35pm UTC](https://community.emergingthreats.net/t/sigs-w32-badspace-backdoor/1630/2 "2024-05-13T21:35:55Z")

</div>

Hey @kevross33 -

Thanks for the awesome tip! We got these signatures in today’s release!!

```auto
2052557 - ET MALWARE W32/Badspace.Backdoor CnC Activity (GET)
2052558 - ET MALWARE W32/Badspace.Backdoor CnC Activity (POST) 

```

Thanks,  
Isaac

---

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [May 14, 2024, 2:56pm UTC](https://community.emergingthreats.net/t/sigs-w32-badspace-backdoor/1630/3 "2024-05-14T14:56:13Z")

</div>

Thanks @kevross33 @ishaughnessy !
