|
[Reference] Self Help - Remote Administration Trojans (RATs)
|
|
04-24-2010, 09:45 PM
Post: #1
|
|||
|
|||
|
[Reference] Self Help - Remote Administration Trojans (RATs)
Hi, everyone.
This is an extract from a reference I was writing a few months ago. It was directed to White Hat Hackers in an attempt to educate them on RATs. There's a lot more to it, but I can't recover the whole guide at the moment, so I'll just post the midst of it. 4.0 - Remote Administration Trojans (RAT) What is a Remote Administration Trojan? A RAT or Remote Administration/Access Trojan/Tool (otherwise known as a Backdoor) is a form of malware used to gain control over someone's computer. This tool is most popular with the Black Hats and they're very common infections. RATs are becoming extremely advanced these days, and they have the capability to completely destroy an unprotected computer. This is why, it's important as helpers to know how to combat RATs. RATs have features including keyloggers, the ability to steal passwords, open and close CD trays, disconnect external devices such as monitors, delete or edit files, turn on a webcam without the user knowing, edit and delete registry entries, disable security software, and much more. Basically, they're capable of doing anything - the same things you'd do as if you were sitting in a seat behind the computer. For More Information On RATs More information can be found on Remote Administration Trojans at these links.
In this section, we're going to look at the process of cleaning a system from a RAT infection. We'll look at how to identify a RAT and what distinguishes them from other infections. I'm also going to tell you about some malware scanners that are often used to clean RATs. How To Recognize a RAT Infection To recognize an infection, you'll need to analyze the symptoms the infected member is experiencing. With experience, you'll be able to apply your common sense and knowledge to determine, based on what has been said by the infected, whether or not the user has been infected by a RAT (or any other infection for that matter). There are many things that you can look for to help determine whether or not you're dealing with a RAT, so I'm going to list some of them below. Before I do that, I'd like to alert you to some popular RAT names, just for quick reference. Common RATs
Symptoms of RAT Infections
Because a RAT infection is, basically, someone controlling one's system from a remote location, common sense can tell you whether or not particular symptoms are going to be of relation to a RAT infection. After Diagnosis - Cleaning After you've confirmed that you're dealing with a RAT, you can go about removing it from the infected's computer. Now, there are many issues that can arise when removing RATs, and your recommendations won't always be right. This is why analyzing the symptoms is crucial. General RAT Cleaning & Removal Tools This section will address removing the basic, less advanced RAT. Obviously, you'll be able to get a sense of the ferocity of the infection, judging by what you've been told by the infected. If they reveal little more than the bare minimal necessary for your to deduce that they're infected by a RAT, you should do the following.
Harvey HJT Trainee Alias: Malware Boss E-Mail: Harvey@ChannelHQ.com MSN: Harvey@ChannelHQ.com |
|||
|
05-01-2010, 07:24 PM
(This post was last modified: 05-01-2010 07:24 PM by Hero.)
Post: #2
|
|||
|
|||
|
RE: [Reference] Self Help - Remote Administration Trojans (RATs)
Very nice and and clean reference on RATs. I am sure this will help people who doesn't know what RATs are or are just looking to extend their knowledge.
|
|||
|
05-01-2010, 07:29 PM
Post: #3
|
|||
|
|||
|
RE: [Reference] Self Help - Remote Administration Trojans (RATs)
Some more symtomps you could add
thinking of some more |
|||
|
05-01-2010, 07:31 PM
Post: #4
|
|||
|
|||
|
RE: [Reference] Self Help - Remote Administration Trojans (RATs)
@mitchz; those are some fun activities that RATs do. I doubt any professional RAT owner who is looking for money would use those.
|
|||
|
05-01-2010, 08:14 PM
(This post was last modified: 05-01-2010 08:14 PM by PerM.)
Post: #5
|
|||
|
|||
|
RE: [Reference] Self Help - Remote Administration Trojans (RATs)
Very nice guide, it will help people who doesn't know much about hacking. Btw remember when cleaning the computer may not have access to the internet.
|
|||
|
05-01-2010, 08:29 PM
Post: #6
|
|||
|
|||
|
RE: [Reference] Self Help - Remote Administration Trojans (RATs)
Thanks for posting this up, I've heard so much about RATs but I never knew what they actually were. This has really broadened my understanding on this topic.
|
|||
|
05-01-2010, 11:25 PM
Post: #7
|
|||
|
|||
|
RE: [Reference] Self Help - Remote Administration Trojans (RATs)
Very good!
Thank you for posting this guide It will help for a lot of people Including me. Now all I need to do Is to find time to read It all once again. |
|||
|
05-02-2010, 01:02 AM
Post: #8
|
|||
|
|||
|
RE: [Reference] Self Help - Remote Administration Trojans (RATs)
it was a very nice guide .
do this so called rats involve encryption of files? everyweek i scan my laptop on safemode . and yet still some files are not scanned because they are marked as blue . my friend said it was either encrypted or password protected . does the administrations tools i have read could help out? |
|||
|
05-02-2010, 02:14 AM
Post: #9
|
|||
|
|||
|
RE: [Reference] Self Help - Remote Administration Trojans (RATs)
good share bro ! will surely help people who are new to this stuffs ! :)
|
|||
|
05-02-2010, 04:12 PM
Post: #10
|
|||
|
|||
RE: [Reference] Self Help - Remote Administration Trojans (RATs)
(05-01-2010 07:31 PM)Hero Wrote: @mitchz; those are some fun activities that RATs do. I doubt any professional RAT owner who is looking for money would use those. I know, but it are symptomps right?
|
|||
|
« Next Oldest | Next Newest »
|
User(s) browsing this thread: 3 Guest(s)





