RGDoor Backdoor
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
RGDoor is implemented as a secondary backdoor, produced in C++ the backdoor results in a Dynamic Link Library (DLL). The DLL has a function called RegisterModule which allows an attacker to infer that the DLL was an HTTP module.
When code calls RegisterModule it is done so by ignoring any incoming HTTP GET requests, yet it does not do the same for HTTP POST requests. This will allow an attacker to upload or download files from the target server as well as run commands through the command prompt.
Remediation steps
Last edited: 17 February 2020 12:53 pm