X RAT 2.0
(Backdoor.Win32.XRat.c)

by XSystem

Written in Microsoft Visual C++, compressed with UPX

Released in September 2004

Made in Russia

more versions


1. Configuration

  Use "X-Rat -setup" enter config mode, you can set:
  
* 1.Set listen port
  2.Set access password
  3.Set edit server password
  4.Set login banner
  5.Set service name
  6.Set service display name
  7.Set EXE filename
* 8.Set Direct reverse onnection
* 9.Set HTTP path for reverse connection
  10.View config information

  11.Help
  0.Complete

  ps: the option with "*" blackball each other, only 1 will active.

XSystem  


dropped file:
c:\WINDOWS\system32\Rat.exe
size: 53.760 bytes 

port: 20888 TCP

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_X-RAT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\X-Rat
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_X-RAT
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\X-Rat



tested on Windows XP
January 05, 2005

MegaSecurity