X RAT (b)
(Backdoor.Win32.XRat.b)

by XSystem

Written in Microsoft Visual C++, compressed with UPX

Released in September 2004

Made in Russia

more versions


1. Configuration

  Use "X-Rat -setup" enter config mode, you can set:
  
* 1.Set listen port
  2.Set access password
  3.Set edit server password
  4.Set service name
  5.Set service display name
  6.Set EXE filename
* 7.Set reverse connection // NOT SUPPORTED NOW!
  8.View config information

  9.Help
  0.Complete

  ps: the option with "*" blackball each other, only 1 will active.

XSystem  


dropped file:
c:\WINDOWS\system32\Rat.exe
size: 52,736 bytes 

port: 20888 TCP

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_X-RAT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\X-Rat
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_X-RAT
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\X-Rat



tested on Windows XP
January 06, 2005

MegaSecurity