Byte-ul Posted July 9, 2013 Report Posted July 9, 2013 Copy-Paste HF:CarberpOtstuk 60-90%Win XP/Vista/7 x86--Complete setEach successive includes previousMinimum:- Loader- FTP grabber (31 client)- Passvord grabber- Form Grabber (IE, FF, Opera)- FTP sniffer- Grabber basic-authentication in IE- Remove cookie and sol in IE and FF- DDOS- Socks5 proxy- Support injected in IE and FF- A program for writing and debugging injected with convenient GUI- Encrypted Traffic- Builder- Multi-bot AdminExtended:- Grabber Serta from IE- Module Hunter- Universal keylogger- AutoUpdate crypt and Domains- Search words in documents and send to the admin panel- Video recording on the boat for debugging inzhey and AZ- Enhanced functionality in the adminFull:- VNC (win xp/vista/7 admin / user) and RDP (win xp admin)Bootkit:- MBR-loader bot (win xp / 7)--Program list grabberMessengersMiranda, ICQ2003, RQ,Trillian, ICQ99b, MSN, Yahoo,AIM, Gaim, QIP, Odigo, IM2,SIM, GTalk, PSI, Faim, LiveMessenger,PalTalk, Excite, Gizmo, Pidgin, AIMPRO,MySpace, Pandion, QIPOnline, JAJC, Digsby,AstraEmail clientsBecky, The_Bat, Outlook,Eudora, Gmail, MRA, IncrediMail,GroupMailFree, VypressAuvis, PocoMail,ForteAgent, Scribe, POPPeeper,MailCommander, Windows_Mail_Live, Windows_Mail_VistaFTP clientsTotal Commander, FAR Manager, WS_FTP, CuteFTP,FlashFXP, FileZilla, FTP Commander, FTP Navigator,BulletProof, SmartFTP, TurboFTP, FFFTP, CoffeeCup,Core FTP, FTPExplorer, Frigate3, UltraFXP, FTPRush,SecureFX, Web Publisher, BitKinex, Classic FTP PC,Fling, SoftX FTP Client, Directory Opus, FreeFTP,DirectFTP, LeapFTP, WinSCPBrowsersFirefox, Safari, Opera, IE, ChromeOtherSysInfo, WinVNC, ScreenSaver,ASPNET, RDP, FreeCall, CamFrog,PCRemoteControl, NetCache, CiscoVPN,Credentials--Socks5 proxyTo receive a bot uses windows-server applicationWhen bot knock, the server connects and hangs it on a different portMakes bots SOCKS5-proxyWeb-based interface for connection and control bots--InjectInjection works on IE and FFIs supported by G, P, and LSyntax 1B1 as Zeus, but just in case you need to check on the performance ofThere is a convenient debugger injected with which it is easy to check its inzhey and write new--Traffic EncryptionAll traffic from the spammer to admin and back encrypted unique key for each botnetBots can not knock on the admin area to another keyAll requests from the bot to go to the admin scripts with random namesAll plug-ins, download bot from admin, just encrypted--Module HunterWhen you visit a particular url bot requests from admin certain command, so for example you can include all of the DSA bots who went to the bank or upload any exe--Universal keyloggerThrough admin defined list of processes that need to benefit from logging keystrokesBots get a list and send the admin logs as they become availableIn the admin logs are divided not only on the processes and individual bots, but for different applications launch--AutoUpdate crypt and domainsUpdate bots crypt to clean and domains without otstuk perebildinga and update botsIn the admin panel added a list of domains and loaded kriptovat buildsAdmin checks for their own services and scan4you chk4meEvery half hour boat knocks in admin for the new domains and buildsDepending on the set on the boat AB admin panel gives it a clean build and domainsWhen you update the build this way, preferred shares and domains bot are the same, regardless of the fact that the resident in buildIt's easy to check domains, without giving them the botsIf you have your own kriptor as exe, admin panel itself can kriptovat builds, making 10 of the crypts at a time, check them out, choose the cleanest and give bots, or to make a permanent link on the net to build chords, as well as update and notify exe kriptora in jabber if crypts palitsya--Search for words in documentsYou can search for a specific word or phraseThe search is performed within the documents txt, doc, docx, xls, xlsx, pdf, rtf, odt, lying on the drive, even if they are packed in zip or rar archiveAll documents found packed in one file and go to the admin panel--Video recordingWhen visiting a specific url in the browser on the boat and the recording videoVideos sent to windows-server running receiver moduleVideo is written in our own format, maximum compression and optimized, b / w 2fpsTo view using our own player, it is implemented for the convenience of a quick search on the name of the active windowOn request, you can customize video recording - the start of a specific event, record the full screen, a record for a certain time, etc.--RDP and VNCRemote connection to the bot is controlled via a single server windows-applicationAfter connecting to the server, just select the bot and press the connect buttonServer forwarding one of its ports and assign it to the boat, then you can connect and work--GatesServer other than the primary server with the admin, the request is redirected to the admin panel of bots, bots and giving answers from herThe main objective of the gate - hide admin bot from abuseFor your regular gate UPU, the main thing is not the iron, and the channelWhen abuse can quickly deploy a new gate, install time ~ 30 minutesGates can be several, and all lead to one adminThere are several types of implementations, including based on OpenVPN, but we recommend the normal Nginx-webserver is configured as a proxy--BootkitWorks on Win XP / 7, otstuk ~ 60-80%Mounted on ring3 bot, so if the installation failed, the boat ring3 remain in a healthy stateAfter installation is restarted, and if successful launch bot from ring0, ring3 version is deletedAB bootkit can not find, as well as a bot that runs through bootkit kriptovat and therefore do not need to updateEven if in the future some AV can find it, you still can not remove, the user will only reinstallVitality 65% ??or more in a month after progruza--Rules for granting licensesOne license is admin page on the same server with reference to ip + boat builder and configure a gateway. For an additional fee, you can configure the desired number of gates. License restriction in the number of servers from the admin. One license - one server.Redirecting bots on ip, which was not put our admin panel, as well as where there is untied our or its written under our boat, admin panel, is prohibited. We monitor each license carefully, and if there is a suspicion of attempted violation of the license or otvyazki bot / admin, we reserve the right to take appropriate action, up to revocation and ddos ??domain / server offender.Admin protected with IonCube latest version. Boat protected systems of our own design. Just as they present additional internal encryption and special bookmarks that define ip / domains binding. If it is found that the bot / Admin decoupled, bookmarks make to the work of random distortion, resulting in a bot / Admin begin to not work properly, do not carry out the commands, or simply fail. As a result, it becomes impossible to control the botnet will be lost logs, bots will breathe much faster, etc. And at first glance, the bot can work untethered and knock in the same way as normal. Defects can be detected only by detailed analysis. With each new version, along with modifications to the functional and improved otstuk also will change and become more complex protection.Software is provided as is, manibek not provided. Resale of software is prohibited.--Plans to develop- Inject and formgrabber for Chrome- 64-bit mode- RPD under Win 7- Loader minimum size for all models- P2p to regain control of the botnetItalics marked updates that will be distributed free of charge, provided that the unit to which the update has already been purchasedIf you have your own suggestions, we will add them to this list, prioritize the development of themselves--UpdatesBug fixes in the current module and minor additions to the functional freeNew modules and major additions to the current for a feeFor an additional fee, any possible improvements--Grabbers and AZ of any complexityWe accept orders for writing grabbers and AZOur team has extensive experience in writing grabbers passwords, keys, balance sheets and AZ any difficulty under any systemWe have already written a grabber and AZ-based systems:- HTML / Javascript- ActiveX- Java- Win32Thanks to the close cooperation of our programmers, we can adjust and finish our bot order the AZ for maximum resultsThere is a full featured Admin AZPrices and conditions are specified for each order separatelyThis is not a service for writing small inzhey, work only with large customers-- BEGIN PGP PUBLIC KEY BLOCK --Version: GnuPG v1.4.10 (GNU / Linux)Removed - useless here-- END PGP PUBLIC KEY BLOCK ----Requirements for Admin bot:php> = 5.3.3IonCube Loaderphp-mysqliphp-zipphp-geoip (possible and without it there is remote but it is less efficient so it is better this otkompilenny right in php)php-pcntlLighttpd + Lighttpd FastCGI + FastCGI Alow-XSendFile (Can and Apache 2.2 but mnee productive if you want to put it to him that necessarily mod_xsendfile)Download Link: http://priv8.ru/archive/krab.rarNu deschideti .exe-uri sau alte chestii pe care la gasiti acolo. Quote
alinh0 Posted July 9, 2013 Report Posted July 9, 2013 Lasa'te https://rstforums.com/forum/71141-sursa-carberp-bootkit-other-c-projects-worth-60k.rst Quote
malsploit Posted July 9, 2013 Report Posted July 9, 2013 hxxp://www.xylibox.com/2013/06/carberp-remote-code-execution-carpwned.html Quote