|
|
The TIc.K 4.0 RAT Information
| Name: |
The TIc.K 4.0 |
| Category: |
RAT |
| Alias: |
- Alias: Backdoor.Netrex, NetRex, Picture-Nag |
| Advice: |
Remove |
| Risk: |
High Risk
High risk threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction. May open up communication ports, use polymorphic tactics, stealth installations, and/or anti-spy counter measures. May use a security flaw in the operating system to gain access to your computer. |
| Description:
|
It is remote administration tool which upload & run an executeable file to the server
It is a kind of RAT tool which Upload & run an executeable file to the server search, download, run, close & delete files from the Server Icq notified exit windows copies itself into win/sys dir (Starfield.src) Win autostart Selectable Port 72 kbs Server (about 22kbs with UPX) Undetectable by AVS Get Country, Username, Icq Number Sound capture with selectable Wav Options
|
| Signatures:
|
process: Client.exe: MD5 Hash: 24bede112376a109be4.. |
| Type: |
RAT - A Remote Administration Tool (RAT) is a Trojan type of software that when run, provides an attacker with the capability of remotely controlling a user's computer (victim) over the Internet. The attacker usually has full access to functions on the victim's computer. The victim's computer usually listens on the Internet for the attacker's commands. |
Top RAT Visited Pages:
SubSeven - Alias: BackDoor-G22, BackDoor-Sub7 - 295 visits
NetBus v.1.70 - 210 visits
The Prayer - Alias: BackDoor-DI, Backdoor.Prayer.15 - 75 visits
Cyrex msn trojan - Alias: BackDoor-AOB, Backdoor.VB.dm, Backdoor.VB.dm, Cyrex msn trojan, W32/Delf.B - 69 visits
Global Killer - Alias: Backdoor.GlobalKiller 1.0, Global Killer 1.0 - 55 visits
Systray BackDoor - 53 visits
AutoSpY - Alias: Backdoor.AutoSpy - 49 visits
Secret Agent - Alias: Backdoor.Antinuke.10, Secret Agent 1.0 - 47 visits
Undetected - Alias: Backdoor.tds.4f, Backdoor.tds.se.23, Backdoor.tds.se.23a, Backdoor.tds.se.30, Backdoor.TDS.SE.31, Ba - 42 visits
Netbus - Alias: Backdoor.Netbus - 42 visits
Random RAT Pages:
Virus.Delf.i
Igloo - Alias: Backdoor.Igloo.00, Backdoor.Igloo.15.a, Backdoor.Igloo.15.b, Backdoor.Igloo.15.c, Backdoor.Igloo.18,
Progenic
Satan - Alias: Backdoor.Satan.b, W32/Backdoor.Progeni
Arctic - Alias: Backdoor.Artic.06
Majesty Backdoor
Back Orafice 2000 - Alias: Orifice2K, W32/Bo2K, Backdoor.BO2K.10
Remote Home
Poltergeist
NetRex - Alias: Backdoor.Netrex, NetRex, Picture-Nag
|
|