TROJAN: FuzzDB Simple PHP Backdoor

This signature detects use of the FuzzDB Simple PHP Backdoor. This signature is intended to be used to protect your own web server infrastructure and is not intended to be used to inspect web clients going outbound. While FuzzDB is intended for use in testing, the tools it provides are functional and can be used as real Trojans. If not currently conducting FuzzDB testing, this could be a sign of a real backdoor within your network and should be investigated.

Short Name
TROJAN:SIMPLE-PHP-BACKDOOR
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
TROJAN
Keywords
Backdoor FuzzDB PHP Simple
Release Date
04/07/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?