Trojan-Downloader.Win32.Genome.qiw Insecure Permissions

Trojan-Downloader.Win32.Genome.qiw malware suffers from an insecure permissions vulnerability.

MD5 | 00a3fd2fe45a56e989c84555bf89a8e4

Discovery / credits: Malvuln - (c) 2021
Original source:
Contact: [email protected]

Threat: Trojan-Downloader.Win32.Genome.qiw
Vulnerability: Insecure Permissions
Description: Genome.qiw creates an insecure dir named "tmp" under c:\ drive and grants change (C) permissions to the authenticated user group. Standard users can rename the executables dropped by the malware to disable it or replace it with their own executable. Then wait for a privileged user to logon to the infected machine to potentially escalate privileges.
Type: PE32
MD5: 5cddc4647fb1c59f5dc7f414ada7fad4
Vuln ID: MVID-2021-0164
Dropped files: 003.exe, BtPlayer_Setup_9999.exe
Disclosure: 04/07/2021

C:\>cacls tmp
C:\tmp BUILTIN\Administrators:(OI)(CI)(ID)F
NT AUTHORITY\Authenticated Users:(ID)C
NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C

C:\>dir \tmp
Volume in drive C has no label.

Directory of C:\tmp

09/02/2009 02:59 PM 25,076 003.exe
09/02/2009 02:57 PM 2,218,086 BtPlayer_Setup_9999.exe
2 File(s) 2,243,162 bytes

