SkD RAT 1.0 b Public Edition
(Backdoor.Win32.Skrat.a)
(Backdoor.Win32.Prorat.19.p)

by SkD

Written in Visual Basic

Released in June 2005

more versions



Some thing's you have to know:
-Remember to RESTART Server before disconnecting because you may have problem's in connecting to the server again.
-Use E-Mail Notification to know when the victim is online and his IP address to connect to.
-After version 0.6, Screenshot function stopped working properly.
-Services manager is underconstruction.
-After packing the edited dloader.exe, size may be around 10 KB.
-Do not pack the template server and downloader .exe's.
-After packing the edited server .exe, you may encounter problem's with E-Mail notification.
-The server uses MsWinsck.ocx after version 0.9, it installs the .ocx and a MSN Password grabber.[ That's why the server has such a big size ] .

SkD


Server:
dropped files:
c:\templog.txt                                 Size: 103 bytes 
c:\WINDOWS\eimsn.exe                           Size: 57,344 bytes 
c:\WINDOWS\system32\rewt\servertemplate.exe    Size: 446,464 byte

port: 1234 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows "load"
old data: 
new data: C:\WINDOWS\system32\rewt\servertemplate.exe 

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows "run"
data: C:\WINDOWS\system32\rewt\servertemplate.exe 


tested on Windows XP
June 06, 2005

MegaSecurity