kekbotHTTP ist jetzt ein aktuelles Projekt von mir geschrieben in pure C++ und ein wenig inline assembler.
Aktuelle Features (Safe Bot Loader): The Safe Bot Loader checks for the safety of the execution environment and unpacks main bot resources
[Implemented] Safe Environment Checkup
[Implemented] Anti Debug/Anti Virtualization/Anti VM/Anti Disasm/Anti Dump
[Implemented] Anti Memory Modification / Analysis
[Implemented] UAC Elevation with SE technique
[Implemented] Runs all bot resources if environment is safe
Aktuelle Features (Main Bot): The main bot runs in a zombie process of a trusted windows application
[Implemented] Stable Networking (HTTP/HTTPS)
[Implemented] System information grabber (PC-Name, IP, OS, Architecture, Elevation, Unique HardwareID)
[Implemented] Ring3 Rootkit without drops (x86/x64)
[Implemented] .NET Disabler ( Prevents .NET applications from running on target machine completely )
[Implemented] Anti Debug/Anti Virtualization/Anti VM/Anti Disasm/Anti Dump
[Implemented] Advanced Anti Botkiller
[Implemented] Safe Stub Updater (Bypasses HIPS)
[Implemented] BTC Wallet Stealer
[Implemented] Download & Execute (Hidden/Visible)
[Implemented] Download & Execute with Parameters (Hidden/Visible)
[Implemented] Download & Inject (No drops, HIPS Bypass)
[Implemented] Download & Install (Hidden, application will run on reboot)
[Implemented] Url Visit (Hidden/Visible)
[Implemented] Bot Uninstaller
Aktuelle Features (Persistence Watchdog): Monitors active bot resources and recovers missing/corrupted parts of the bot if needed
[Implemented] Injected Watchdog Instance
[Implemented] Anti Debug/Anti Dump
[Implemented] Anti Memory Modification / Analysis
[Implemented] Protects botkiller injection
[Implemented] Protects registry entries
[Implemented] Protects bot files
[Implemented] Persistence runtime of the bot ( no, I'm not just restarting the bot executable like a skid )
Aktuelle Features (Botkiller Watchdog): Detects active malicious threats and removes them (worked on all bots tested yet, including big bots)
[Implemented] Injected Botkiller Instance
[Implemented] Anti Debug/Anti Dump
[Implemented] Anti Memory Modification / Analysis
[Implemented] Injection/RunPE Detector
[Implemented] Heursitic Scan/Startup Scan/Open TCP Connections Scan
[Implemented] Active handles scan
[Implemented] Process dumper (x86/x64)
[Implemented] Secure techniques to remove the active threat
[Implemented] Aggresive malware remover module (Module which will be injected to corrupt the runtime and trigger runtime instability)
[Implemented] Anti .NET (Detects .NET processes and kills them instantly)
[Implemented] Full 32/64 bit support
[Info] Multithreaded
[Info] Thread safe dispatch routines
[Info] No dependencies (no C-Runtime, no .NET, no JVM/JRE)
TODO list:
[In Progress] Rewriting usermode rootkit (full inline hooking instead of IAT hooking)
[Queued] Communication Encryption
[Queued] Formgrabber (removed due to incompatibility)
[Queued] C&C Panel
[Queued] kekbot Builder
Changelog:
Current Status: Bot Development
Die erste Version von kekbotHTTP wird Freeware, jedoch ohne Formgrabber, Anti Botkill, Full Ring3 Rootkit (abgespeckte Version), Persistence Watchdog.
Updates, etc. werden in diesem Post bearbeitet.
Release Date gibt es noch nicht.
Bei Fragen oder Anmerkungen, Jabber: siehe Signatur
MfG