Sinisterly
Tutorial FUD jRAT 4.1.1_1 + Keylogger Plugin * Windows Only * - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Remote Administration & Stress Testing (https://sinister.li/Forum-Remote-Administration-Stress-Testing)
+--- Thread: Tutorial FUD jRAT 4.1.1_1 + Keylogger Plugin * Windows Only * (/Thread-Tutorial-FUD-jRAT-4-1-1-1-Keylogger-Plugin-Windows-Only)



FUD jRAT 4.1.1_1 + Keylogger Plugin * Windows Only * - Lynux - 03-05-2014

How To FUD jRATs Server For Windows


First before I start the tutorial I would like to point out a few things, the victim still requires Java on their system for this to work, they also need C++ Redistributable 2010 on their system for the final .exe to run (I have a work around for this, see below) Also this method has been used over & over since the end of 2012 and it's still FUD so please don't spam the thread with oh no you uploaded it their!


The generated .exe file needs a .dll file MSVCR100.dll to run otherwise it will just crash, you can download this .dll file HERE and package it with your .exe in various way's, I will leave that upto you.


Step One Let's Build Our Server


Spoiler:
[Image: FdReI9q.jpg]

This is the first thing we see when we start the advanced builder, we need to enter a password, copy the encryption key & give our server a name.

Spoiler:
[Image: 8aIB1SI.jpg]

This is our network settings, we need to enter our External IP which you can find over at whatsmyip.org, enter our port number E.G. 666 you also need to port forward the same port number on your router & you can keep the reconnect rate if that suits your needs.

Spoiler:
[Image: Y8raSoZ.jpg]

These settings ensure that our server will start after a reboot so make sure it's checked, give your dropped file a name that's not to suspicious & leave the other two unchecked as the will cause our server to crash.

Spoiler:
[Image: WjKJyu7.jpg]

So here we enable Mutex, this ensures our server is only run once, so if our victim goes rage mode and keeps trying to open it our server doesn't crash.

Spoiler:
[Image: mnLxGfw.jpg]

Here we only want to select Windows as this will only work on Windows, The victim does need Java installed & C++ Redist as I mentioned earlier. (The .DLL is above)


Spoiler:
[Image: 90vyUXf.jpg]

This is the timeout settings the longer you leave it may/may not cause problems if the victim has a shitty connection you might be waiting 5 minutes every 10 minutes for him to reconnect.


Spoiler:
[Image: 0h8IIqL.jpg]

This is the delay settings the longer you set it the longer it will take to run, this is useful if he is running sandboxie or anything else like Avast because if you set this for 5 - 10 minutes most likely it will get overlooked.


Spoiler:
[Image: ibxOAWK.jpg]

The plugins the reason I'm only using the Keylogger in this tutorial is because it causes our server to become detected 2/40 which isn't bad but that's not the purpose of this tutorial


Spoiler:
[Image: euyRbCs.jpg]

We do not want to log errors in a live environment as this may cause our victim to notice something is up because the error log is generated in the same folder that the server is run, so if it's on his desktop, you get the idea.


Spoiler:
[Image: zj1iTrK.jpg]

This is self explanatory, this will show an icon in the tray on the victims machine not ours, we will leave this unchecked.


Spoiler:
[Image: NyzOeMo.jpg]

We want to make sure that if our startup RegKey is deleted it is restored other wise we will lose our slave.


Spoiler:
[Image: OUcRZZP.jpg]

I have not tested this is in a live environment, but you are welcome to do so, if you have issues with this setting I.E. your server will not run your will have to create a new server with this disabled and continue with the tutorial.


Spoiler:
[Image: mTdDSx0.jpg]

This is the same as the error logs, we don't really need them unless we are messing around in a VM.

Spoiler:
[Image: OwFj400.jpg]

Only use a the .jar output for this anything else will not work.

Spoiler:
[Image: MVH8Bw3.jpg]

Here are all your settings once more before we continue.

Spoiler:
[Image: m0BurtO.jpg]

Now we need to add our socket or listener, these must be the same as the server or your connection will fail! So Port, Pass & Encryption Key.

Step Two Jar2Exe


Spoiler:
[Image: 3Vynhgs.jpg]

This is the first screen you will see when you run Jar2Exe, you can enter anything for the User & Key E.G. xxx & xxx amd then click register.


Spoiler:
[Image: LRmy3uG.jpg]

Select your server.jar that we have just created & leave the minimum JRE at 1.2 (This just ensures backwards compatibility).


Spoiler:
[Image: 8ROf36e.jpg]

Now we select the Windows GUI so the user doesn't see anything, selecting the console will pop up a console as the server runs.


Spoiler:
[Image: U0GSHtO.jpg]

Leave this as it is, I've messed around here before and had my server break or become detectable.


Spoiler:
[Image: 5bWBPD3.jpg]

Only select Hide class files, Encrypt and hide class files makes our server become detected.


Spoiler:
[Image: s8QgFnR.jpg]

Now just hit next & finish (on the next page) and we are done.


Jar2Exe Download & Scan's
Can someone with a little bit more experience check this file for anything malicious, As their seems to be some false positives on Virustotal PM Me for the file!





Server Scans Before & After

Metascan



Virustotal





RE: FUD jRAT 4.1.1_1 + Keylogger Plugin * Windows Only * - Cubesnail - 03-05-2014

Nice share!
(03-05-2014, 01:59 AM)liquidsnake Wrote: [img]http://i.imgur.com/WjKJyu7.jpg[/img
So here we enable Mutex, this ensures our server is only run once, so if our victim goes rage mode and keeps trying to open it our server doesn't crash.
Gotta close that BB code


RE: FUD jRAT 4.1.1_1 + Keylogger Plugin * Windows Only * - Lynux - 03-05-2014

(03-05-2014, 05:00 AM)Cubesnail Wrote: Nice share!
Gotta close that BB code

Thanks man, didn't realise, it's fixed..


RE: FUD jRAT 4.1.1_1 + Keylogger Plugin * Windows Only * - Cressi - 03-05-2014

Ah, the FUD Tongue Nice share, thanks a lot ^^


RE: FUD jRAT 4.1.1_1 + Keylogger Plugin * Windows Only * - Lynux - 03-05-2014

I've updated the last scan, as there seemed to be an issue with it but now you can see what I mean, one of the main reasons this become detected is because of temporary files on your system using ccleaner to clear everything related to your temporary files & java should produce a FUD output D :~)


RE: FUD jRAT 4.1.1_1 + Keylogger Plugin * Windows Only * - Lotus Black - 03-05-2014

wow really fud? let me test. Thanks ^_^