Trojan-Dropper.Win32.Daws.etlm Unauthenticated Reboot

Trojan-Dropper.Win32.Daws.etlm malware suffers from a remote unauthenticated system reboot vulnerability.

MD5 | 68c57accbf9d176f0f232920d6f0c18f

Discovery / credits: Malvuln - (c) 2021
Original source:
Contact: [email protected]

Threat: Trojan-Dropper.Win32.Daws.etlm
Vulnerability: Remote Unauthenticated System Reboot
Description: Daws.etlm drops an executable named "MSWDM.EXE" under Windows dir and listens on UDP port 139. Unauthenticated third-party attackers can send a single uppercase char "D" datagram packet to the infected machine causing it to reboot. Basic testing using other upper/lower case chars from A-Z or numbers 0-9 did not reveal anything else of interest.
Type: PE32
MD5: a0479e18283ed46e8908767dd0b40f8f
Vuln ID: MVID-2021-0111
Dropped files: MSWDM.EXE
Disclosure: 02/25/2021

from socket import *


def doit():
except Exception as e:


print("Trojan-Dropper.Win32.Daws.etlm / Remote Unauthenticated System Reboot")
print("MD5: a0479e18283ed46e8908767dd0b40f8f")
print("By Malvuln");

if __name__=="__main__":

