Guide to RAT




Remote Administration Tools

RATs stand for Remote Administration Tools. It is a program used to control an Remote PC. Hence, the name “Remote Administration Tool”. They can be used both for White Hat or Fun or personal purposes and also Black Hat or Malicious purposes. The user may take complete or partial control of a Remote Computer with or without his acknowledgement.

Functioning of a RAT

The RAT program is referred to as Client. The RAT client builds an program called server/virus. The server is often referred to as Trojan Horses. The RAT Client needs to use a specific port for the program to communicate with the host. For more about it just scroll down. So, when the server is ran on a remote PC, the infected PC starts communicating with the client. Many RAT used for Black Hat purposes make their functioning hidden from the Host. Thus, when a connection is established the Client can take full or partial control of his computer. When a RAT server is installed without the acknowledgement of the Host then the Host is often referred to as Bot, slave, slave, install, etc. 

Types of RATs and its features

Non-Malicious RATs
They're mostly used for Personal or White Hat purposes. These require the Host’s permission and the host can cut off the connection any time if wanted. So it’s useful to fix a Remote Computer just sitting at your PC.

Malicious RATs
The name suggests it. It is used for blackhat purposes. Like stealing their information, spying on them,etc. Especially without their knowledge.

TCP RATs
They communicate directly from the host to the client. They require portforwarding. They have many feature than Php/Http bots.
So more features = More fun. They are always the first priority. Get to the Php/Http RAT if you have serious problems in portforwarding. 


Free RATs
  • Dark-comet
  • Cyber Gate
  • Poison Ivy
  • Bi-frost
  • Spy-Net
  • Xtreme RAT

Paid RATs
  • Blackshades NET
  • Paradox RAT
  • Client mesh
  • Anguish RAT

PHP/HTTP RATs
They work without the need to port forward. Its more stable than TCP RATs but will have relatively less features though.

List of common Php/Http RATs
  • Vertex NET
  • Loki RAT
  • BlackShades Fusion
  • Lynx RAT

Some general features of a RAT
  • Block mouse and keyboard
  • Change your desktop wallpaper
  • Download, upload, delete, and rename files
  • Drop viruses and worms
  • Edit Registry
  • Format drives
  • Grab passwords, credit card numbers
  • Hijack homepage
  • Hide desktop icons, taskbar and files
  • Log keystrokes, keystroke capture software
  • Open CD-ROM tray
  • Overload the RAM/ROM drive
  • Print text
  • Play sounds
  • Randomly move and click mouse
  • Record sound with a connected microphone
  • Record video with a connected webcam
  • Shutdown, restart, log-off, shutdown monitor
  • Steal passwords
  • View screen
  • View, kill, and start tasks in task manager


Port
A port is needed for any Remote Connection to communicate with your Computer. For Example, Port 80 used for Web services , Port 25 is used for SMTP. So, a port is needed for every specific program to communicate with a Remote device. Obviously, a RAT too needs a port to communicate with the Remote PC(Host).

Port Forwarding
Port forwarding is the method of opening a specific port on the router to allow out bounding connections. For forwarding a port you must need access to your router. Sometimes UPnP is used in case you don’t have access to your router and your router supports UPnP. UPnP means Universal Plug and Play. If your router supports UPnP then the port may be opened using a third party software such as Utorrent.

VPN
VPN or Virtual Private Network. I need not explain it much here. Its used to hide your IP and stay anonymous. Its like if your under a VPN when you request a web resource it first goes into the VPN server and gets the web resource. Some VPNs may allow you to open some certain ports. So, it can solve your port-forwarding issues.

DNS
DNS known as Domain Name System. If you have an dynamic IP your IP changes often. So, its practically not possible for the bots to stay connected to you. So, a DNS provides you an domain which will redirect to whatever IP you have.

There many DNS providers the most widely used are:
  • NO-IP
  • dyndns

Cryptography
It’s the method of hiding your server from Anti-Viruses. It’s because most of the RAT server are detected by many Anti-Viruses. So when your Victims open your server their Anti-Virus may block it. So in this case a crypter is used. It’s the software that protects your server from Anti-Viruses. So, every crypter has a stub either inbuilt or separate from the crypter. A stub is a code when added to your server makes it FUD or UD.

FUD: Fully Un-Detected
It means that the stub is un-detectable by all Anti viruses.
UD: Un-detected
It means that the stub is un-detected by few anti-viruses and few detect it.


Virus scanning sites
They are often used to check a binary for threats/viruses. These sites use multiple Antivirus engines to test the binary uploaded. Most of them are co-operated by Antivirus companies and they send the binary samples to the Antivirus companies for analyzing them. So if your FUD server is uploaded to sites like this your server will get detected by Antivirus companies. So, obviously your FUD server will become UD. But, some sites do not give out the binary samples to Antivirus companies. They are often used to check the FUD or UD status of the server/stub.
Some sites that give out samples
Some sites that don't give out samples:

Dependencies
Some crypters coded in VB.NET or C# needs .NET framework for the stub to run. So, they are often described as “.NET dependent crypter”. .NET framework usually comes pre-installed on Windows Vista or above.
Some crypters coded in C++, ASM, VB6 or any other language that does not involve .NET can be run on systems even without .NET framework. They are pretty much stable and have high execution rates. But, they are relatively costlier than the .NET dependent ones.


Java Driveby
It’s a java applet its uploaded to an webhost. Its often covered by an legit looking site clone. So, when the slave opens up the website. An java message pops up. With two options Run or cancel. 90% of people will click Run. So, when Run is clicked your server is executed inside their computer without their knowledge.

Botkilling
Botkilling also known a Ruskilling. The name describes it killing your bot/server. So, it means killing other bots/servers inside the slave’s computer. Some crypters and RATs have this function. Though it may be useful sometimes it will frustrating when you buy some bots and they botkill your server.


Read More Add your Comment 0 comments


[FULL]How to setup Cythisia Botnet




Cythosia Botnet



Controlled via: Webpanel
Found at: Opensc.ws
Language: C# (2.0)
Developed by: Post.Mort3m

Current Version: 1.0.8

# Runs on Win2k - Win7 / x86 and x64

~ Limited/Guest/Administrator Acconts

# Various Autostart Names and Entries

Main Functions:

+ Download & Execute
+ Update

Distributed Denial of Service Functions (DDoS)

+ Syn
~ 20 Bots can kill little Sites
~ Customizeable Port & Strength(Http, Sql, Gameserver)
+ UDP
~ Perform attacks on homeconnections
~ Highly customizeable
+ HTTP
~ Multithreaded GET Requests - Generates Traffic as hell
~ Keeps GET Requests open

Socks5 Proxy

+ Opens Port with UPnP if router supports it
+ Redirects all TCP requests multithreaded -> very good speed
+ Configureable Username and Password

Control Panel

+ Nice looking Ajax Panel
+ Hardcoded Password -> secure
+ Taskmanagement System
+ Export Online SOCKS5 LIST





How to Setup Cythisia v2

1.First of all Download it here (mediafire link)

2. After Downloading you should have the .rar file. Extract it and it should look like this: [Image: ib0Ch2.jpg]

3. Now you need a Webhost to upload it. If you not allready have one, i would suggest http://www.azok.org
Create a account there with subdomain etc.

4. Once your subdomain is ready, go to your control panel.

5. In your Control Panel go to Advanced, then "Mysql Databases".


6. Fill out the required data.


7. Next to "mysql databases, there should be the task "phpmyadmin". Click on it. Then there should show up your created database. Click on "enter phpmyadmin".

8. Now you are in phpmyadmin. Goto to Import, then browse to to dump.sql, which you can find in the "webpanel" folder. Upload it and your done.

9. After this go to "File Manager 1"

10. Go into the public html folder.

11. Click Upload and browse to the "Webpanel.zip" archive ( make sure you upload it on the right side.

12. After succesful uploading, go back to the File manager, tick the webpanel folder and click on "chmod"


13. chmod the folder to 777 and tick the two fields below.
[Image: 36537506.jpg]

14. Ok now you uploaded the files. Now you have to edit one of the files with your mysql data, which can you find again in "mysql databases" in the control panel.

15. Go to /Webpanel/admin/inc/config.php and click edit.

16. Now you will see the php file, you have to edit it with your mysql database datas like me:

17. Now go to your website: http://www.yoursite.com/Webpanel/
A small box with "password" should pop up. The default password is "admin". To edit the password edit the index.php which you can find in /Webpanel/index.php

18. Login and your Panel should look like this:
19. Now we go for the builder part, open Cythbuilder.exe and edit the data like me (for example):
[Image: 65265859.jpg]

20. Get the builded.exe and spread it.

21. Done

I hope you liked my little tutorial. Enjoy.
and use @ your own risk bcoz it is not mine post..i seen over net so i posted for my friends over here...


Read More Add your Comment 0 comments


How To setup Cybergate RAT



In This Tutorial You'll Learn Following:

Cybergate 1.07.5 Set Up - Download Cybergate RAT Here

Setting Up An No-IP
Spreading
Port Forwarding
Setting Up An No-IP Duc - Download Here!
WinRar: 32 Bit 64 Bit

Quick Troubleshooting: If You Cant Open The .exe Or It Wont Extract, Try Disabling Your Windows Defender And/Or AV And The Re-Download It.


This Is What You Can Do With This RAT;

Managers:

  • File Manager
  • Process Manager
  • Service Manager
  • Device Manager
  • Window Manager
  • Regitry Manager
  • Installed Programs
  • Active Port list

Spy:

  • Screen Capture
  • Webcam Capture
  • Password Recovery
  • Keylogger
  • Audio Capture

Network Tools:

  • Socks 4/5 Proxy
  • HTTP Proxy
  • Send File
  • Download and Execute
  • Open Webpage
  • URL Redirection

Extras

  • Dos Prompt
  • Quick Search (for logs)
  • Chat
  • Extras (open-close CD-ROM etc.)
  • And Alot More!

Setting Up The No-IP & Client

1. Start Off By Going To; No-IP.com And Register. If You Have An Account There Already, Then Just Log In.

2. Once You've Logged In, Press "Add Host"

[Image: NOIP1.png]

3. Now It's Time To Choose Your Host Name!

[Image: NoIP2-1.png]


Hostname: Your Host Name, EG:

Quote:YourHostName.no-ip.biz
Host Type: DNS Host (A)

Dont Care About The Rest, Once You've Choosen Your Host Name, Press "Create Host" In The Lower Right Bottom.


The Host Is Now Finished! Lets Move On To The No-IP Client.

1. The No-IP Client You Downloaded In The Beginning, Extract It To Your Desktop & Install It.

2. Now When You've Installed It, Open It Up & Log In With Your No-ip Username & Password.

3. When You're Logged In Press "Select Hosts" And Then Check That Little Box With Your Hostname.

[Image: AP2uIE.png]

Note: Always Have No-IP Open When You Have Cybergate Open!


There! Your No-IP Host & Your No-IP Duc Is Now Sat Up!

Setting Up Cybergate 1.07.5

1. Extract The Cybergate File You Downloaded In The Beginning To Your Desktop! Once Extracted, Open It & Wait 20 Seconds For The Agreement To Pass! :)

2. When It's Open, Press: Control Center -> Start.

3. Press: Control Center -> Options -> Select Listening Ports

[Image: RAT4-1.png]

4. Once You've Pressed The "Select Listening Ports" This Window Should Appear:

[Image: RAT5-1.png]

5.Firstly, Write "100" In That Little Box And Press The Blue Arrow. Then It Should Appear Under "Active Ports"

Active Ports: The Port You Will Forward Later!

Connections Limit: The Max Amount Of Victims You Can Have.

Connection PW: The Connection Password. Use "123456"

[V] Show Password: (Shows Password)

Once This Is Done, Press "Save"!

6. Now We'll Go To The: Control Center -> Build -> Create Server.

[Image: RAT6-1.png]

User: First, Press "New" And Name It To: "Plutonium". Once Done, Press "OK"

Now Just Double Click On "Plutonium" Or Press "Plutonium" And Then Press "Forward"

7. Now We're In The "Connection" Tab.

[Image: RAT7.png]

First, Press "127.0.0.1 - 999" And Then Press Delete.
Now Press "Add" And Write Your Hostname In It + :100.
Like This:
Quote:YourHostName.No-ip.biz:100

Change The Identification To: Cyber
Change The PW To: 123456

**Note, If You Want To Try The Server On Yourself, Then Delete Both:

- 127.0.0.1:999
- YourHostName.No-ip.biz

And Replace Them With; 127.0.0.1:100 Since 127.0.0.1 Means "Local Computer & LAN Internet"

Make The DNS/HostName Server First Though! :)

DNS: Your Host Name, EG:
Quote:YourHostName.no-ip.biz
Port: The Port You Will Forward Later.
Identification: The slave Name
PW: The Password You Wrote In The Options, "123456"

8. Once You're Done With Theese, You'll Move On To The "Installation" Tab.

[Image: 2010-08-02_1609.png]

9. Have The Same Settings As I Do, And Follow The Instructions In The Image!

Install Directory: Where The Server Installs,

%System%
%Windows%
%Root%
%Program Files%
%Other%

Use The "System"! :).

Boot: This Is The "Startup" Option. Have Everything Checked & Press "Random" 5 Times And It Will Startup On Your slave Everytime They Start Their Computer!

Directory: Where The Virus Folder Installs
File Name: What The File Will Be Inside The Folder.

Inject Into. What Process It Injects into, Use Default Browser!

[V] Persistance: Keeps Trying To Inject Until Succed.
[V] Hide File: Hides The File, (Not FUD Though!)
[V] CCD: Changes The Creation Date From 16th July To 4 September 2005.

Mutex: Mutex Of The Server, Just Press Random A Couple Of Times!

There We Go, You've Now Completed The "Installation" Tab!

Skip The Message & Keylogger Since They Are Pre-Set Already!

10. You Should Now Have Trumbled Into The "Antis" Tab, Have Everything Checked! (Except SANDBOXIE If You Are Gonna TRY IT ON YOURSELF!)

[Image: RAT9-1.png]

Ok, The Final Tab.. "Creation Of The Server". Have Every Setting As Me!

[Image: RAT10-1.png]

[V] Use Icon: Yes
[V] Delayed Execution: (How Many Seconds It Takes Until Your Server Injects And They Pop Up In Your RAT)
[V] Google Chrome PW: Yes, Steals Their GC Passwords :)
[X] Bind Files: No, Get An Real Binder Instead! (Have Your Server Crypted Though First!)
[X] Compress With UPX: Makes The Server Smaller But More AV's Detects It!


There! Your RAT Is Now Fully Sat Up. You Do Only Need To PORT FORWARD First To Make It Work! Follow This Tutorial: Port Forward Tutorial! Now With UTorrent! And Everything Should Work Out Well!

Quick Troubleshooting If Your RAT Doesent Work:

Non-Connecting RATs

Make Sure That....

1. ..You are properly port-forwarded if using a router.
2. ..You have the No-IP Client installed and running.
3. ..Your DNS entries are correctly spelled when building your server.
4. ..The password in Listening Ports and the password your server uses are identical.
5. ..You are Listening on the correct ports.
6. ..Your Firewall is letting connections through on the port you're listening on.
7. ..Your server is added to excluded files in your Antivirus and Firewall.

''//'' If You Have ANY Troubles With This, Feel Free To PM Me & I'll Reply As Fast As I Can.


Spreading Tips: (Once Your Server Is Crypted & Ready: How To Spread Your Bot

Also, Some Tips On HOW To Not Get Caught And Reported To The FBI. ALWAYS USE AN VPN OR PROXY.

:: A Proxy//VPN Is Something That Replaces Your IP With Another Somewhere Throughout The World.

Get Your VPN // Proxy From Here:
Major Proxy // VPN List


Where To Get Your Server Crypted: Here

Once You've Port Forwarded Your Port: "100" Then Just Get It Crypted And Start Spreading! And In A While You Should Get Some Victims That You Can Have Fun With! (Hopefully Ugly Men Or Sexy chicks ;D...)

Now, some FAQs ;

Q: What is CyberGate?
A: CyberGate is a remote administrative tool or trojan for Windows operating systems. You can use CyberGate to manage computers, monitoring your child etc.

Q: Where can I get CyberGate?
A: There is an website for CyberGate, but you can easily download it from my thread.

Q: What operating systems are supported by CyberGate?
A: Windows 95/95B
Windows 98/98SE
Windows ME
Windows NT 4.0
Windows 2000
Windows XP
Windows Vista
Windows 7

Q: Will CyberGate slow my computer?
A: No. CyberGate won't slow your computer, it is a small program and works in background and has been optimized to minimize resource use.

Q: When I downloaded CyberGate, I can't extract it, a problem occurs. What should I do?
A: That's because of your anti virus, they detect it as unwanted applications so your anti virus could prevent downloading. Disable your anti virus and try again.

Q: When I have downloaded CyberGate, my antivirus detect it as virus. What should I do?
A: Well, since RATs are hacktools, and all the hack tools are detected as viruses, Turkojan is detected as virus also. To download and install CyberGate you will need to turn off your anti-virus.

Q: Why should I use no-ip?
A: If you don't have a static IP, you're IP will change each time your Internet reconnects so the server won't be able to reach you. To prevent loosing victims because of your dynamic IP, you will need no-ip host.


Q: I've created a server, but I don't see it in the directory. Why?
A: That's caused by your antivirus. The server is detected, and it won't let it. I suggest you to remove or just simply de-activate your antivirus if you are going to use RATs.

Q: I've send my server to a friend on MSN, but he doesn't connect.
A: That's because he has an antivirus or firewall and it won't let him to connect in your RAT. To make it FUD, (Fully Undetectable), you should use a crypter.

Q: Is CyberGate illegal?
A: No. CyberGate is a legal RAT. The author of CyberGate created his program for legitimate purposes. For example, there are many legal activities. Parents can use keyloggers to protect their children from online abuse etc. Some people use it for stealing passwords, credit cards and more but it's not a software which breaks the law, but the person who uses it.

Q: Can CyberGate be used for legitimate purposes?
A: Yes. You can monitor your children online activity.. to make sure they don't visit pornographic websites. You can find out if someone uses your computer while you are away, ensure no one is accessing your personal files while you are away and more.

Q: How do I make my server FUD?
A: You should use a binder or crypter.

Managers:

File Manager

This allows you to easily scramble through all their files on their harddrives. Quite handy in my oppinion ^^

Process Manager

This allows you to pretty much, end/start their processes in the Task Manager. This way you can shut off their AV :).

Service Manager

Pretty much the same as the above ^

Device Manager

Pretty much the same as the above ^. No biggie.

Window Manager

This allows you to shut down their "tasks" from the desktop bar. Love it.

Registry Manager

If you're skilled with the Registry you can change aloot of stuffs, since you have the possibility to do it.

Installed Programs

Allows you to check what programs they have installed on their HDD.

Active Port list

This one is also quite handy, if you need to catch one of their open ports, this is the tool.

Spy:

Screen Capture

If you're interested in what your slave's doing, then you can easily check it out with this.

Webcam Capture

Want to get really "spy" ? Then you should really check out how your slave looks by using this.

Password Recovery

IF you want to catch some of their saved passwords.

Keylogger

Not the best keylogger there is, but it works. Catches all the keystrokes your slave presses.

Audio Capture

Yep.. This one only works if they have a microphone. I once caught my slave having sex. With both webcam and audio capture.. *Shrugs*

Network Tools:

Socks 4/5 Proxy

Use this and you have less of a chance to get FBI busted upon your ass.

HTTP Proxy

Using a web proxy.

Send File

This way you can send them any file. It wont execute tho, so i'd suggest you just leave this , cause the bottom option is even better. (Download & Execute.)

Download and Execute

My favourite. This way you can infect your slave with others viruses, since it sends and downloads. You can send a prank virus too, like.. Anything!

Open Webpage

If you want to play a fool joke on your slave, by going to. etc. (Lolfish.org <---- Don't visit!) Or Nobrain.dk, works too. Have the webcam capture up when you open one of theese pages. See their rections, hilarious!

URL Redirection

I still really haven't figured out what to do with this, but I guess YOU guys will eventually learn? :P

Extras

Dos Prompt

Opens up the Command Prompt window, and allows you to execute several commands.

Quick Search (for logs)

If you want some of their logs.

Chat

This way you can act like either way, FBI, or a hacker. Such as.. "Hello, this is Mr. Andersson from FBI. We've caught you surfing the web to watch child porn. Your computer will be confiscated in 20 minutes." Have the webcam capture up.. Oh my god I always laugh my ass off. XD

Open/Close CD-Rom

Hilarious, they think their computer is haunted.

Change MSN Status

This one isn't really great.. Just changes the MSN status of their MSN. ^^

And Alot More!

Actually, this tool is very nice. I've used it for a few years now, even before I wrote this tutorial.

Thing is, most people (20 % out of 100%) PMs me cause they can't set their ports up. It's not actually that hard.

1. Open up your CMD (Command Prompt) by entering Start -> Run -> CMD

2. Type in IPConfig and get your default gateway. (Usually 192.168.1.1 or 192.168.0.1) -- Something along thoose lines.

3. Remember that IP and open up your webbrowser. Type that IP in.

4. Log in to your router - usually Admin-Admin or Root-Password or just Admin and no password.

5. Once you're IN, go to your portforward tab or VIRTUAL SERVER. Depends on which router you have.

6. Use ports 100 for UCP and TCP.

7. If you have to enter IP, go back to the Command prompt, above default gateway (192.168.0.1) there should be another IP, like;

"192.168.1.12 or 196.168.1.14" yeah, you get it. Thats the IP you use.

8. Port Forward.

9. Open up Cybergate, and make sure you have port 100 selected already in Cybergate.

10. Go to Canyouseeme.org - Type in 100 - If it works, success. And if it doesen't work, then you'll have to follow my even more detailed port forward tutorial 

This program is very very funny to use if you want to prank your friends, get revenge on an enemy, or just having fun.


Read More Add your Comment 0 comments


 

WhoIsAmoungUS

Trace

Copy Restrict

About Me

Scroll Button

Popular Posts

Counter

© 2014 Hacking-The Art of Exploitation All Rights Reserved Vishal S Sangwa A Ethical Hacker White Hat Hacker