Subscribe via RSS ... Subscribe via e-mail ... Follow me on Twitter ... Follow me on Facebook ...

Win32/Rbot source code.

     
Name Win32/Rbot trojanhorse
 
Malware type RAT, Worm  
 
Author Unknown  
 
Written in C  
 
Description Rbot is an IRC controlled backdoor (or “bot”) that can be used to gain unauthorized access to a victim’s machine. It can also exhibit worm-like functionality by exploiting weak passwords on administrative shares and by exploiting many different software vulnerabilities, as well as backdoors created by other malware. There are many variants of Rbot, and more are discovered regularly. Rbot is highly configurable, and is being very actively developed, however the core functionality is quite consistent between variants. Most instances of Rbot are compressed and/or encrypted with one or more run-time executable packers.

Rbot variants are able to spread in a number of different ways. Propagation is launched manually through backdoor control, rather than happening automatically. Not all variants support all propagation mechanisms.

Each spreading method begins with scanning for target machines. The worm can generate random values for all or part of each IP address it targets. Each attack vector is associated with a particular TCP port.

Via Network Shares (TCP ports 139 and 445)
Via LSASS buffer overflow vuln. (TCP port 445)
Via WebDav vuln. (TCP port 80)
Via RPC msgbuffer overflow vuln. (TCP ports 135, 445, 1025)
Via RPCSS DCOM msg buffer overflow vuln. (TCP port 135)
Via Exploiting weak passwords on MS SQL servers
Via UPnP NOTIFY buffer overflow (TCP port 5000)

Rbot’s main function is to act as an IRC controlled backdoor. It attempts to connect to a predefined IRC server and join a specific channel so that the victim’s computer can be controlled. The IRC server, port number, channel and password differ with each variant.

Rbot also listens on TCP port 113 to provide ident services, which are required by some IRC servers.

Once the victim’s computer is under control, the overseer is able to instruct Win32.Rbot to attempt to perform malicious operations such as spreading via administrative shares with weak passwords or the DCOM RPC exploit.

 
Questions Do you have a question about this RAT/bot/worm? At the bottom of this post you find the box where you can type and send your message.
 
Downloads Source
 
Sources www.ca.com


Leave a comment


But please respect the commenting rules. Critizism is appreciated and also general comments of course. If you're rude, I have to delete your comment. Also use your personal/nick name but avoid using business names. Have fun and thanks for participating the discussion.