<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title> &#187; RAT</title>
	<atom:link href="http://www.megapanzer.com/tag/rat/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.megapanzer.com</link>
	<description></description>
	<lastBuildDate>Wed, 08 Sep 2010 12:49:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Trj/Casper.A sources.</title>
		<link>http://www.megapanzer.com/2010/02/15/trjcasper-a-sources/</link>
		<comments>http://www.megapanzer.com/2010/02/15/trjcasper-a-sources/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 07:12:30 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[RAT sources]]></category>
		<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[Casper]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[RAT]]></category>
		<category><![CDATA[source]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3468</guid>
		<description><![CDATA[&#160; &#160; &#160; Name Trj.Casper &#160; Type RAT &#160; &#160; Author Unknown &#160; &#160; Written in C &#160; &#160; Description This sourcecode dates back to 2004. It is quite old and its functionality is rather limited. The intresting part in this source code is the injection section which represents the biggest part of it. It [...]]]></description>
			<content:encoded><![CDATA[<table border="0" width="100%">
<tbody>
<tr valign="top">
<td width="30%">&nbsp;</td>
<td width="50%">&nbsp;</td>
<td width="20%">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Name</strong></td>
<td>Trj.Casper</td>
<td rowspan="5">
<img src="http://www.megapanzer.com/wp-content/uploads/trojan_horse.jpeg" alt="RAT" title="RAT" width="100" height="96" class="alignright size-full wp-image-2132" />
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Type</strong></td>
<td>RAT</td>
<td>
&nbsp;
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Author</strong></td>
<td>Unknown</td>
<td>
&nbsp;
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Written in</strong></td>
<td>C</td>
<td>&nbsp;</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Description</strong></td>
<td colspan="2">
This sourcecode dates back to 2004. It is quite old and its functionality is rather limited. The intresting part in this source code is <strong>the injection section</strong> which represents the biggest part of it. It contains an injection function based on the <strong>CreateRemoteThread</strong> call and all required functions to make it completely run in a remote process. You can use it as a basic example and extend it with your own functionality.
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Questions</strong></td>
<td colspan="2">In case you have a question just register at the <a href="http://www.megapanzer.com/bbpress">Megapanzer forum</a> and leave an entry in the according board. Your question will be answerd as soon as possible.</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Downloads</strong></td>
<td colspan="2"><a href="http://www.megapanzer.com/wp-content/uploads/casper.zip">Source</a></td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
</tbody>
</table>
<p><br/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/02/15/trjcasper-a-sources/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FBI RAT source code.</title>
		<link>http://www.megapanzer.com/2010/01/24/fbi-rat-source-code/</link>
		<comments>http://www.megapanzer.com/2010/01/24/fbi-rat-source-code/#comments</comments>
		<pubDate>Sun, 24 Jan 2010 14:30:53 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[RAT sources]]></category>
		<category><![CDATA[Albinoskunk]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[RAT]]></category>
		<category><![CDATA[sourcecode]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3398</guid>
		<description><![CDATA[&#160; &#160; &#160; Name FBI RAT &#160; Type RAT &#160; &#160; Author Albinoskunk &#160; &#160; Written in C &#160; &#160; Description After calling for your submissions this is the first RAT source that reached me. It was coded by Albinoskunk. The source is based on Aryan v0.5, it was improved at some places and contains [...]]]></description>
			<content:encoded><![CDATA[<table border="0" width="100%">
<tbody>
<tr valign="top">
<td width="30%">&nbsp;</td>
<td width="50%">&nbsp;</td>
<td width="20%">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Name</strong></td>
<td>FBI RAT</td>
<td rowspan="5">
<img src="http://www.megapanzer.com/wp-content/uploads/trojan_horse.jpeg" alt="worm" title="worm" width="100" height="96" class="alignright size-full wp-image-2132" />
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Type</strong></td>
<td>RAT</td>
<td>
&nbsp;
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Author</strong></td>
<td>Albinoskunk</td>
<td>
&nbsp;
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Written in</strong></td>
<td>C</td>
<td>&nbsp;</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Description</strong></td>
<td colspan="2">
After calling for your submissions this is the first RAT source that reached me. It was coded by <strong>Albinoskunk</strong>. The source is based on <strong>Aryan v0.5</strong>, it was improved at some places and contains all relevant components of a RAT, client, server, GUI and what I consider as the most interesting part in this RAT is the process injection function. Albinoskunk already documented its features in the <a href="http://www.megapanzer.com/bbpress/topic.php?id=26">forum</a> but to sum it up here the main characteristics :<br />
<br/></p>
<ul>
<li>File Manager</li>
<li>System Manager</li>
<li>Keylogger</li>
<li>Screen capture</li>
<li>Webcam</li>
<li><strong>Packet Sniffer!</strong></li>
</ul>
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Questions</strong></td>
<td colspan="2">In case you have a question just register at the <a href="http://www.megapanzer.com/bbpress">Megapanzer forum</a> and leave an entry in the according board. Your question will be answerd as soon as possible.</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Downloads</strong></td>
<td colspan="2"><a href="http://www.megapanzer.com/wp-content/uploads/FBI-RAT.zip">Source</a></td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Screenshot</strong></td>
<td colspan="2"><a href="http://www.megapanzer.com/wp-content/uploads/FBI.jpg" target="_blank" target="_blank"><img width="200" height="100" src="http://www.megapanzer.com/wp-content/uploads/FBI.jpg"></a></td>
</tr>
</tbody>
</table>
<p><br/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2010/01/24/fbi-rat-source-code/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Win32/Rbot source code.</title>
		<link>http://www.megapanzer.com/2009/10/16/win32rbot-source-code/</link>
		<comments>http://www.megapanzer.com/2009/10/16/win32rbot-source-code/#comments</comments>
		<pubDate>Fri, 16 Oct 2009 21:13:31 +0000</pubDate>
		<dc:creator>carrumba</dc:creator>
				<category><![CDATA[RAT sources]]></category>
		<category><![CDATA[Tools & sources]]></category>
		<category><![CDATA[Worm sources]]></category>
		<category><![CDATA[RAT]]></category>
		<category><![CDATA[Rbot]]></category>
		<category><![CDATA[sourcecode]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://www.megapanzer.com/?p=3007</guid>
		<description><![CDATA[&#160; &#160; &#160; Name Win32/Rbot &#160; Malware type RAT, Worm &#160; &#160; Author Unknown &#160; &#160; Written in C &#160; &#160; Description Rbot is an IRC controlled backdoor (or &#8220;bot&#8221;) that can be used to gain unauthorized access to a victim&#8217;s machine. It can also exhibit worm-like functionality by exploiting weak passwords on administrative shares [...]]]></description>
			<content:encoded><![CDATA[<table border="0" width="100%">
<tbody>
<tr valign="top">
<td width="30%">&nbsp;</td>
<td width="50%">&nbsp;</td>
<td width="20%">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Name</strong></td>
<td>Win32/Rbot</td>
<td rowspan="5">
<img src="http://www.megapanzer.com/wp-content/uploads/trojan_horse.jpeg" alt="trojanhorse" title="trojanhorse" width="100" height="96" class="alignright size-full wp-image-2132" />
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Malware type</strong></td>
<td>RAT, Worm</td>
<td>
&nbsp;
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Author</strong></td>
<td>Unknown</td>
<td>
&nbsp;
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="bottom">
<td><strong>Written in</strong></td>
<td>C</td>
<td>&nbsp;</td>
</tr>
<tr>
<td colspan="2">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Description</strong></td>
<td colspan="2">
Rbot is an IRC controlled backdoor (or &#8220;bot&#8221;) that can be used to gain unauthorized access to a victim&#8217;s machine. It can also exhibit worm-like functionality by exploiting weak passwords on administrative shares and by exploiting many different software vulnerabilities, as well as backdoors created by other malware. There are many variants of Rbot, and more are discovered regularly. Rbot is highly configurable, and is being very actively developed, however the core functionality is quite consistent between variants. Most instances of Rbot are compressed and/or encrypted with one or more run-time executable packers.</p>
<p>Rbot variants are able to spread in a number of different ways. Propagation is launched manually through backdoor control, rather than happening automatically. Not all variants support all propagation mechanisms.</p>
<p><span id="more-3007"></span></p>
<p>Each <strong>spreading method</strong> begins with scanning for target machines. The worm can generate random values for all or part of each IP address it targets. Each attack vector is associated with a particular TCP port.</p>
<p><strong>Via Network Shares</strong> (TCP ports 139 and 445)<br />
<strong>Via LSASS buffer overflow vuln.</strong> (TCP port 445)<br />
<strong>Via WebDav vuln.</strong> (TCP port 80)<br />
<strong>Via RPC msgbuffer overflow vuln.</strong> (TCP ports 135, 445, 1025)<br />
<strong>Via RPCSS DCOM msg buffer overflow vuln.</strong> (TCP port 135)<br />
<strong>Via Exploiting weak passwords</strong> on MS SQL servers<br />
<strong>Via UPnP NOTIFY buffer overflow</strong> (TCP port 5000)<br />
&#8230;</p>
<p>Rbot&#8217;s main function is to act as an IRC controlled backdoor. It attempts to connect to a predefined IRC server and join a specific channel so that the victim&#8217;s computer can be controlled. The IRC server, port number, channel and password differ with each variant.</p>
<p>Rbot also listens on TCP port 113 to provide ident services, which are required by some IRC servers.</p>
<p>Once the victim&#8217;s computer is under control, the overseer is able to instruct Win32.Rbot to attempt to perform malicious operations such as spreading via administrative shares with weak passwords or the DCOM RPC exploit.</p>
</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Questions</strong></td>
<td colspan="2">In case you have a question just register at the <a href="http://www.megapanzer.com/bbpress">Megapanzer forum</a> and leave an entry in the according board. Your question will be answerd as soon as possible.</td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Downloads</strong></td>
<td colspan="2"><a href="http://www.megapanzer.com/wp-content/uploads/rBot.rar">Source</a></td>
</tr>
<tr>
<td colspan="3">&nbsp;</td>
</tr>
<tr valign="top">
<td><strong>Sources</strong></td>
<td colspan="2"><a href="http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=39437" target="_blank">www.ca.com</a></td>
</tr>
</tbody>
</table>
<p><br/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.megapanzer.com/2009/10/16/win32rbot-source-code/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
