Full Disclosure: Backdoor.Win32.ControlTotal.t / Insecure Credential Storage / MVID-2025-0702
seclists.org·4d
🎯NTLM Attacks
Preview
Report Post

Full Disclosure mailing list archives


From: malvuln <malvuln13 () gmail com> Date: Sat, 20 Dec 2025 23:17:42 -0500


Discovery / credits: Malvuln (John Page aka hyp3rlinx) (c) 2025
Original source:
https://malvuln.com/advisory/6c0eda1210da81b191bd970cb0f8660a.txt
Malvuln Intelligence Feed: https://intel.malvuln.com/
Contact: malvuln13 () gmail com
Media: x.com/malvuln

Threat: Backdoor.Win32.ControlTotal.t
Vulnerability: Insecure Credential Storage
Description: The malware listens on TCP port 2032 and requires
authentication. The password "jdf4df4vdf" is stored in cleartext
within the PE file. We send using a custom client to validate the
password, as the malware did not like nc64 likely due to CRLF
characters.
Family: Contr...

Similar Posts

Loading similar posts...