Saturday, June 24, 2017

REMCOS RAT

1:00 PM Leave a Reply
Remcos is a powerful Remote Administration Tool with

a wide array of functionalities, contained in a tiny package
The backdoor part, written in C++, is only ~60 kb of size uncompressed and contains all the functions.

No dependencies, and fully compatible with any Windows
from WinXP to Win10, 32-64 bit, including Server editions.
Remcos will not require any extra dependency to run.
All it needs is contained in any standard Windows installation.

Robust connection:
Robust Keep alive system makes sure your connection with the remote host/s will never get lost.
100% Encrypted connection protects transmitted data from sniffers. Not a single byte is sent unencrypted.
Backup connection addresses will make sure your remote host will connect even if one or more addresses go offline.

Auto-Tasks:
You don't even have to sit at the computer: Download logs and files, and performs other actions automatically on hosts connection.

Mass Commands:
You can send any command to more then one remote host, or even to all the connected ones in same time.
Search for a file name on all your machines network, download&execute a file, shutdown all of them and much more.

Surveillance functions:
Transform the remote machine in a completely stealth surveillance station.
ScreenLogger takes screenshots on a time-interval basis or when the user opens some chosen windows, webpages or programs.
Screenshots are stored encrypted and are erased when the remote operator retrieves them.
Offline Keylogger stores logs totally encrypted, and will wipe them out after sending them to C&C operator (even automatically using Autotasks)
Online Keylogger lets you see what remote user types (and which window opens) in realtime.
Camera Capture lets you capture a live stream of the remote camera, and save frames to disk.
Microphone Capture lets you capture the audio from the machine's microphone in real-time, or even when you are offline, storing audio files.

Extra-Stealth:
Want to use Remcos as a stealthy remote surveillance tool?
Process Injection, Anti-Analysis techniques, total encryption of connection and stored logs, and full compatibility with exe crypters, will make it hard to spot.

-------------------------------------------------------------------

Main panel with menu of functions which can be performed on one or multiple hosts at the same time:
[Image: functions.PNG]

AutoTasks
Automatically send tasks to hosts as soon as they connect.
Download logs and files, update/uninstall your remote client, and more.
Without needing your physical presence at the PC.
[Image: autotasks.PNG]

ScreenLogger: take automatically screenshots offline, and store them encrypted.
View and download screenshots comfortably anytime.
Screenshots can be taken each x minutes, or when window title or webpage contains a word from a wordlist. This allows you to take screenshots automatically anytime the user opens some webpage or application of interest.
[Image: screenlogger.PNG]

File Search:
want to look for a file on any of your machines?
Perform a fast file search on one, multiple hosts or your entire network. At the same time!

Download

0 comments :