Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Friday, January 23, 2015

Trojan creating using RAT


Now, here is the post for making of simple Trojan using DARKCOMET RAT:

Before making a Trojan get some information about it on this link: Detail About Trojan.
 
RAT: A Remote Administration Tool (RAT) is a piece of software that allows a remote "operator" to control a system as if he has physical access to that system. Malicious RAT software is typically installed without the victim's knowledge, often as payload of a Trojan horse, and will try to hide its operation from the victim and from security software.

Many Trojans and backdoors now have remote administration capabilities allowing an individual to control the victim's computer. Many times, a file (often called a client or stub) must be opened on the victim's computer before the hacker can have access to it.



Many clients/stubs will display a fake error message when opened, to make it seem like it didn't open. Some will also disable antivirus and firewall software. A well-designed RAT will allow the operator the ability to do anything that they could do with physical access to the machine.




Requirements:
  1. DarkComet RAT
  2. Host (you can go for no-ip.com) and a DUC (Dynamic DNS Update Client).
  3. Virtual Machine
  4. VMware/Virtual Box

Step 1: Downloading DarkComet & DUC:

  • Download Darkcomet here Darkcomet 5.31 
  • Extact the downloaded RAR file of Darkcomet
  • Sign up if you do not have no-ip account or sign in if you have already created the account.
  • Go to Add Host
  • You can choose any name for free host (like xyz.no-ip.biz)
  • Finally click on Add Host after selecting the host name
  • Now download DUC (Dynamic DNS Update Client)
  • Install DUC
  • Sign-in with your account

Step 2: Using DarkComet:
  • Open DarkComet
  • Choose any port number (like 100,80,81,etc). The default port is 1604.
  • Now go to Full Editor Mode (Expert Mode). 


  • The "Main Settings" will open the click twice or thrice on the Random.


  • Then click on "Network settings" (This is the main part of Trojan making), write the IP/DNS
  • Open the DUC and go to "Edit Host" and write down the host name in IP/DNS box.


  • Click on add host
  • Go to "Module Startup"


  • Go to next one that is "Install message" (this is optional)


  • Go to "Module Shield"


  • Choose icon (if you want this, it is also optional)


  • Now finally click on "Built The Stub"


  • Save this Trojan and test this on any Virtual Machine like VMware/Virtual Box.
  • It will surely work now and send this Trojan to victim.

NOTE: The Firewall and Antivirus programs should not be activated on victims system. If any of these things are activated, then it will detect and delete the Trojan automatically from the victim's system.


Terms & Warning:
Use this script for educational purposes only and for your self knowledge.
Pro Hack Tricks Blog Team, its Author, Admin cannot be held responsible for any legal action or other action taken against you if you use this script illegally.
Use at your own risk. But remember no one is untraceable.

Wednesday, December 17, 2014

Trojan - The Most Unwanted Thing

Trojan


Trojan is MALWARE program that contains MALICIOUS code. The program that perform malicious activity that is not authorized by the user or victim.

Malware, short for malicious software, is any software used to disrupt computer operation, gather sensitive information, or gain access to private computer systems. 


Malware is defined by its malicious intent, acting against the requirements of the computer user, and does not include software that causes unintentional harm due to some deficiency.

RAT (Remote Administration Tool): 

Remote Administration Tool is used to Trojans. With the help of RAT you can create Trojan easily. It is also used to control Victims PC. RAT is created by the Hackers to help Hackers.
Rat are available for both types of Trojans (Direct Connection, Reverse Connection Trojan). There are numerous RATS available over the internet.



If Trojans gets into your system then it will collect all your personal information without you being aware of it. Trojans are very difficult to remove on your own and slow down your PC. We can say Trojan as a program. This program gets installed in the background while you are doing something else on the internet. Trojans has fairly widespread because of your cable modem or DSL connection is always connected.

With the help of Trojan an attacker can get access to stored password, he can able to read your personal documents stored in your PC, delete files, and he show the images on the screen.

Difference between Virus, Worms and Trojans:




TROJAN: Trojan is a program that once executed performs a task other then expected. 

VIRUS: Virus is an application it self replicates by injecting its code into other data files. Virus spreads and attempts to consume specific targets and are normally executable.

WORMS: Worm copies itself over a network. It is a program that views the infection points of another computer rather than as other executable files on an already infected computer.

Types of Trojans:
1. Direct connection Trojan
2. Reverse connection Trojan

Trojans are transmitted in many ways:
1. Email Attachments
2. Physical Access
3. Software
4. Images
5. Advertisements
6. Fake programs


Trojan Creators looks for:
1. Confidential Documents
2. Credit Card Information
3. Account Data (Email, Password, Username, etc)
4. Financial Data
5. Using Victims PC for illegal purpose.

BEAST:
Beast is a Windows-based backdoor Trojan horse, more commonly known in the underground hacking community as a RAT. It is capable of infecting versions of Windows from 95 to XP.



Beast was one of the first Trojans to feature a reverse connection to its victims, and once established it gave the attacker complete control over the infected computer. Beast came with a built-in firewall by-passer and had the ability of terminating some Anti-Virus or firewall processes. It also came with a binder that could be used to join two or more files together and then change their icon.

It is discontinued in year 2004 and any PC infected by Beast can be easily disinfected by starting windows XP in safe-mode and than removing some infected system files. Also the system restore must be turned off to do this process.

Stay Safe !!!