Netbot Attacker 1.4
(Backdoor.Win32.Agent.amb)
(Constructor.Win32.VB.he)

by Warning Security Team

Released in March 2007

Made in China

more versions

 


NetBot_Attacker 1.4 English version

By:Security warning team(www.hackeroo.com)Development

Function on :

NetBot_Attacker Is a comprehensive pressure as well as the DDOS test attack

He may control the most PC computer to start DDOS to attack!

The main attack type has:

Ordinary attack:  SYN Flood,ICMP Flood,UDP Flood,UDP small,TCP Flood,TCP multi-link

WEB Attack:HTTP No-Cache Get Flood,CC Variety attack,HTTPGET

Special attack: GAME attack,CIDR attack,Hybrid attack

Auxiliary function::

Download operation,Shutdown unloading,Open URL,All shutdown

Help:You only need to have the FTP space and may use it,

Or you are fixed IP,Or your free application dynamic domain name.



Server:
dropped files:
c:\WINDOWS\system32\SVCH0ST.EXE
size: 86,016 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDOWS_FIREWALL\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Windows Firewall\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Windows Firewall\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\C
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_FIREWALL\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Firewall\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Firewall\Security




tested on Windows XP
March 26, 2007

MegaSecurity