Remote Administration Tools | All You Need to Know | Tutorial 11-17-2014, 09:26 PM
#1
--------------------------------------------------------------------------------------------------------------------------------------------
I did NOT write this post. This is just copied and pasted from another forum.
The Original Post, i hope i am allowed to do this if not feel free to tell me and i will remove the link as fast as possible
--------------------------------------------------------------------------------------------------------------------------------------------
I did NOT write this post. This is just copied and pasted from another forum.
The Original Post, i hope i am allowed to do this if not feel free to tell me and i will remove the link as fast as possible
--------------------------------------------------------------------------------------------------------------------------------------------
Welcome to my first EVER RAT tutorial - it should cover everything that is needed of you to know.
First off - lets start off with some basic knowledge. A RAT(Remote Administrator Tool) is simply a tool that helps you connect to your victim. To a certain extent, RAT's can be 'legal' however we all know that it is used otherwise. RAT's can be used to gain access to ones computer, while having full access to their webcam/desktop/files and what not.
What this thread will cover:
Setting up your DNS
Choosing a RAT Client
Portforwarding
Crypting
Spreading tips
Frequently Asked Questions
Setting up your DNS
Choosing a RAT Client
Portforwarding
Crypting
Spreading tips
Frequently Asked Questions
FREE:
![[Image: 22515540.jpg]](http://img593.imageshack.us/img593/4986/22515540.jpg)
Download links to the following RAT posted above can be found here:
Darkcomet Download Links
Darkcomet Download Links
Now let's get started on setting up our RAT - once you've downloaded Darkcomet 5.3.1F drag it over to your desktop so it will be easier to open it up at a later point.
1) Setting up No-IP
What we're going to want to do at this point is head over to No-IP to set up our DNS. No-IP simply gives us a place to host our slaves on, if you ever lose access to your No-IP account, you will lose access to your slaves. So be sure to know all your information.
Once you're on the site, simply head over to "Sign Up" or just visit this URL:
Enter all the required information, for username enter whatever you'd like.
For your Hostname - be sure to enter something that cannot be traced back to you if you want to stay Anonymous.
For example, using a name like Understalker.no-ip.biz as my hostname would be a very stupid move by me as it can be traced back to me with ease.
Instead use something like, ma89we9821.no-ip.biz
![[Image: 23b2cb0600092b42bd5761d999533ee2.png]](http://gyazo.com/23b2cb0600092b42bd5761d999533ee2.png)
Once you've finished entering all your information, click "Free Sign Up"
![[Image: 62b01bf46aaa0b31d86cf9b849d7d690.png]](http://gyazo.com/62b01bf46aaa0b31d86cf9b849d7d690.png)
Confirm the email they will send you.
Once you've confirmed the email and logged on, you should see something like this:
![[Image: 0e012dcd6d1695cd1d6704c6e495aa7a.png]](http://gyazo.com/0e012dcd6d1695cd1d6704c6e495aa7a.png)
Head over to Manage Hosts and you should see the No-IP host you've registered:
![[Image: 9acba0ee31d271ccae67d545102d8ba9.png]](http://gyazo.com/9acba0ee31d271ccae67d545102d8ba9.png)
Once that is done, simply head over to http://www.noip.com/download and download the DUC client.
Once you've successfully downloaded the client, sign on with all required information and keep it open.
2) Portforwarding
Portforwarding is quite simple. All in all, it can be done within 5 minutes.
For this step, what we're going to want to do is simply going to take us 5 steps.
First off, head over locate and open cmd.exe.
Once you've opened it successfully - enter the following command:
Code:
ipconfigYou should see something like this,
![[Image: 3bc03e435f4d2fe33beb0892189878ef.png]](http://gyazo.com/3bc03e435f4d2fe33beb0892189878ef.png)
There are two very important things here, the Default Gateway and the IPv4 Address.
The next step is going to be opening up a web browser, and inputting your Default Gateway as your URL.
You should then, click 'login' or a login screen should automatically pop up. If you do not know your information, simply try out the default ones such as:
Code:
admin:admin
admin:pass
user:pass
user:userOnce you've successfully logged in, what you're going to want to do is locate the portforwarding tab.
This is where your IPv4 address comes to play, your settings should look something like this with a few different changes:
![[Image: 03bdca72b59de474b69efee3a746faf1.png]](http://gyazo.com/03bdca72b59de474b69efee3a746faf1.png)
Once you believe you've successfully portforwarded, you can move on to the next step.
3) Setting up your Client
Assuming you've already downloaded Darkcomet from the links provided above, I will suggest you go ahead and open it.
You should see something like this:
Spoiler:
![[Image: ccbf2877e836961ee5107cdd0283afea.png]](http://gyazo.com/ccbf2877e836961ee5107cdd0283afea.png)
The first thing you're going to want to do is head over to the Socket / Net tab.
Once you're in there, simply right click somewhere inside of it and click "[+] Add port to listen" and input the port you've put on the Default Gateway, in my case it will be 1604.
![[Image: d3c84335878bc0ab42b9b56b655434a3.png]](http://gyazo.com/d3c84335878bc0ab42b9b56b655434a3.png)
To confirm that your ports are indeed open I would recommend using the following site to check:
If your ports are still not open, here are some ideas as to why they're closed:
Spoiler:
Your Firewall is on.
AV is preventing the ports to be open.
You didn't PF correctly
AV is preventing the ports to be open.
You didn't PF correctly
If you do indeed see that your ports are open, you should see something like this:
Code:
Success: I can see your service on **.**.**.** on port (1604)
Your ISP is not blocking port 1604.Moving on to the next step would be setting up your RAT stub.
What we're going to want to do is click the "Darkcomet-RAT" tab and then head over to the "Server module" > Full editor (Expert)
![[Image: 52f5210c4f5a1d7c53704efca674418d.png]](http://gyazo.com/52f5210c4f5a1d7c53704efca674418d.png)
If you do not have a crypter, use these settings
Spoiler:
![[Image: 9418b36e23d05b269d58e32960a6df37.png]](http://gyazo.com/9418b36e23d05b269d58e32960a6df37.png)
![[Image: c6b55e5a10aed1376e58057563ba26df.png]](http://gyazo.com/c6b55e5a10aed1376e58057563ba26df.png)
![[Image: ab718dce7170c02846dbfd85d8941e2b.png]](http://gyazo.com/ab718dce7170c02846dbfd85d8941e2b.png)
![[Image: daad7523644222bf45431cb1837e91e6.png]](http://gyazo.com/daad7523644222bf45431cb1837e91e6.png)
![[Image: db02fa4f8827c10ed2ddefbdd4094624.png]](http://gyazo.com/db02fa4f8827c10ed2ddefbdd4094624.png)
Once you've set these settings up, click on "Build The Stub" - save it on Desktop and have a decent name for it.
4) Testing your RAT
To test your server, I will recommend downloading the following:
After you've installed Sandboxie, from this point forward everything is quite simple.
Go to Darkcomet-RAT --> Server module --> Minimalist (Quick).
![[Image: 52f5210c4f5a1d7c53704efca674418d.png]](http://gyazo.com/52f5210c4f5a1d7c53704efca674418d.png)
![[Image: c606b70b39ffb5e7a097c63161be5929.png]](http://gyazo.com/c606b70b39ffb5e7a097c63161be5929.png)
Click on "Normal" and save your stub to your desktop.
![[Image: 68293a676590b6827526abe87c4885a3.png]](http://gyazo.com/68293a676590b6827526abe87c4885a3.png)
After you've created your stub, what you're going to want to do is Right click it --> Run Sandboxed --> DefaultBox
After you've successfully ran it via Sandboxie, you should see yourself pop up.
![[Image: b497220d30ef43bd6c127130f4acbd9d.png]](http://gyazo.com/b497220d30ef43bd6c127130f4acbd9d.png)
However, testing it on yourself is not the only way to testing it.
Another way would be testing it on Anubis.
The link to Anubis is as follows:
You would need to create a completely new stub for this, and I would recommend the settings listed below:
![[Image: 1e653619fd3e6f6d8ddadcc4b0629bd0.png]](http://gyazo.com/1e653619fd3e6f6d8ddadcc4b0629bd0.png)
Simply click on Normal, and name your stub something like anubislol.exe
Shortly after you should see something like this:
![[Image: 832bd848ab7644990d81d223faccc51e.png]](http://gyazo.com/832bd848ab7644990d81d223faccc51e.png)
![[Image: 0702c89fcc34de716a923967bbc71eff.png]](http://gyazo.com/0702c89fcc34de716a923967bbc71eff.png)
If you did indeed receive a temporary slave, then you should now know that your stub is working flawlessly.
5) Crypting
As you all know, any public RAT that you use WILL be detected.
My last scan on Darkcomet was 46/49.
What I would personally recommend is purchasing a crypter, however there is multiple other ways to crypt your stub, but I will not be explaining that here.
Crypters can be found all over the Marketplace and I am recommending you purchase either one(1) crypted server, or a whole crypter itself to do unlimited crypts.
A crypter by itself can cost anywhere from $10-25 a month.
However, a single crypt can cost you $1-5.
If you're using a crypter, use MINIMALIST settings. Any settings you want on your stub, will have to be added via your Crypter.
6) Spreading Tips
I will be providing you guys a few spreading tips I personally recommend.
If you do put your effort in to it there is no doubt you can easily obtain 100s of slaves per day.
The YouTube method:
My number one spreading advice is to get a niche you know lots of people are interested in and uploading a fake YouTube video.
After you've done so, simply start botting some views and getting some like/comments on your video to make it seem legit.
Rinse and repeat the method and once your video starts getting some fame, you will be earning an easy 5-10 slaves an hour.
uTorrent spreading:
This is similar to the YouTube spreading for the getting a decent niche part and uploading it.Make sure it is over 64 MB so it looks legit and the victim cannot scan your stub on VirusTotal.
Spoiler:
![[Image: 4b4769008492a91862c94b08b989d460.png]](http://gyazo.com/4b4769008492a91862c94b08b989d460.png)
Pedophile Spreading:
Simply set up a ewhore persona and start spreading on chat sites.7) F.A.Q
Can I use a RAT without portforwarding?
Unless you're using a VPN that supports portforwarding or a PHP ART, then no.
Unless you're using a VPN that supports portforwarding or a PHP ART, then no.
Are there any good free crypters?
No.
No.
Is mining on your bots profitable?
Unless they're altcoins, no.
To find out what altcoins are most profitable to mine, check out: http://www.coinwarz.com/cryptocurrency
Unless they're altcoins, no.
To find out what altcoins are most profitable to mine, check out: http://www.coinwarz.com/cryptocurrency
Have any questions you'd like me to add here? Let me know.







![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)












haahahha



