Original source: https://malvuln.com/advisory/e184abe44bec183a522d2c66bc3f90e0.txt
Contact:
Media: twitter.com/malvuln
Threat: Packed.Win32.Katusha.o (Ransomeware)
Vulnerability: Insecure Permissions EoP
Description: The malware create two dirs, one of them under the
users home dir. The files dropped are hidden and can be viewed
using dir /a command. Then after about 35 secs locks the victims
screen, issuing a warning about pirated software and to pay in BTC.
If not paid, a warrant will be issued for arrest. However, the
malware grants full (F) permissions to everyone for the "bkkYoIYg"
dir under that targets users home dir.
C:\>cacls C:\Users\VICTIM\bkkYoIYg\BkkMEYcs.exe
C:\Users\VICTIM\bkkYoIYg\BkkMEYcs.exe No permissions are set. All
user have full control
Type: PE32
MD5: e184abe44bec183a522d2c66bc3f90e0
Vuln ID: MVID-2021-0061
Dropped files: BkkMEYcs.exe, BkkMEYcs, BkkMEYcs.inf,
C:\ProgramData\HcgIwoAM\DiAYIoQI.exe, DiAYIoQI.inf
Disclosure: 01/28/2021
Exploit/PoC:
1) switch user to standard user for PoC
2) open taskmgr kill the malware
3) now you are able to place any files under the vuln "bkkYoIYg"
dir under the privileged users home dir.
Disclaimer: The information contained within this advisory is
supplied "as-is" with no warranties or guarantees of fitness of use
or otherwise. Permission is hereby granted for the redistribution
of this advisory, provided that it is not altered except by
reformatting it, and that due credit is given. Permission is
explicitly given for insertion in vulnerability databases and
similar, provided that due credit is given to the author. The
author is not responsible for any misuse of the information
contained herein and accepts no responsibility for any damage
caused by the use or misuse of this information. The author
prohibits any malicious use of security related information or
exploits by the author or elsewhere. Do not attempt to download
Malware samples. The author of this website takes no responsibility
for any kind of damages occurring from improper Malware handling or
the downloading of ANY Malware mentioned on this website or
elsewhere. All content Copyright (c) Malvuln.com (TM).