{"id":25542,"date":"2022-06-07T20:52:06","date_gmt":"2022-06-07T16:52:06","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167433\/MVID-2022-0608.txt"},"modified":"2022-06-14T12:14:39","modified_gmt":"2022-06-14T07:44:39","slug":"trojan-banker-win32-banker-agzg-mvid-2022-0608-insecure-permissions","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/trojan-banker-win32-banker-agzg-mvid-2022-0608-insecure-permissions\/","title":{"rendered":"Trojan-Banker.Win32.Banker.agzg MVID-2022-0608 Insecure Permissions"},"content":{"rendered":"<p>Discovery \/ credits: Malvuln (John Page aka hyp3rlinx) (c) 2022<br \/>\nOriginal source:<br \/>\nhttps:\/\/malvuln.com\/advisory\/ef1e59148c9a902ae5454760aaab73fe.txt<br \/>\nContact: malvuln13@gmail.com<br \/>\nMedia: twitter.com\/malvuln<\/p>\n<p>Threat: Trojan-Banker.Win32.Banker.agzg<br \/>\nVulnerability: Insecure Permissions<br \/>\nDescription: The malware writes a PE file to c drive granting change (C)<br \/>\npermissions to the authenticated user group. Standard users can rename the<br \/>\nexecutable dropped by the malware to disable it or replace it with their<br \/>\nown executable. Then wait for a privileged user to logon to the infected<br \/>\nmachine to potentially escalate privileges.<br \/>\nFamily: Banker<br \/>\nType: PE32<br \/>\nMD5: ef1e59148c9a902ae5454760aaab73fe<br \/>\nVuln ID: MVID-2022-0608<br \/>\nDisclosure: 06\/06\/2022<\/p>\n<p>Exploit\/PoC:<br \/>\nC:\\&gt;cacls tuto.exe<br \/>\nC:\\tuto.exe BUILTIN\\Administrators:(ID)F<br \/>\nNT AUTHORITY\\SYSTEM:(ID)F<br \/>\nBUILTIN\\Users:(ID)R<br \/>\nNT AUTHORITY\\Authenticated Users:(ID)C<\/p>\n<p>C:\\&gt;dir tuto.exe<br \/>\nVolume in drive C has no label.<\/p>\n<p>Directory of C:\\<\/p>\n<p>05\/04\/2022 02:56 AM 14,336 tuto.exe<br \/>\n1 File(s) 14,336 bytes<\/p>\n<p>Disclaimer: The information contained within this advisory is supplied<br \/>\n&#8220;as-is&#8221; with no warranties or guarantees of fitness of use or otherwise.<br \/>\nPermission is hereby granted for the redistribution of this advisory,<br \/>\nprovided that it is not altered except by reformatting it, and that due<br \/>\ncredit is given. Permission is explicitly given for insertion in<br \/>\nvulnerability databases and similar, provided that due credit is given to<br \/>\nthe author. The author is not responsible for any misuse of the information<br \/>\ncontained herein and accepts no responsibility for any damage caused by the<br \/>\nuse or misuse of this information. The author prohibits any malicious use<br \/>\nof security related information or exploits by the author or elsewhere. Do<br \/>\nnot attempt to download Malware samples. The author of this website takes<br \/>\nno responsibility for any kind of damages occurring from improper Malware<br \/>\nhandling or the downloading of ANY Malware mentioned on this website or<br \/>\nelsewhere. All content Copyright (c) Malvuln.com (TM).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Discovery \/ credits: Malvuln (John Page aka hyp3rlinx) (c) 2022 Original source: https:\/\/malvuln.com\/advisory\/ef1e59148c9a902ae5454760aaab73fe.txt Contact: malvuln13@gmail.com Media: twitter.com\/malvuln Threat: Trojan-Banker.Win32.Banker.agzg Vulnerability: Insecure Permissions Description: The malware writes a PE file to c drive granting change (C) permissions to the authenticated user group. Standard users can rename the executable dropped by the malware to disable it or &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-25542","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/25542","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=25542"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/25542\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=25542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=25542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=25542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}