[ᴛ]ᴏᴏʟ [s]ɪɢɴᴀʟ [s]ᴛᴀɢᴇ
April 15

RHAD Stealer *Wiki*

CLICK*WEB.ver

Main features

Build Generation

requirements:

Build Generation steps:

@bingo_sir Rhadamanthys Stealer.mp4

1. Click "Build" to open the client build page
2. Modify the URL and replace it with the
 
IP and port of the shim server (or main server). 
Choose to use according to your specific needs

The complete URL composition is:http(s)://srver 
IP port/gateway address/file name

Only need to replace the part of server ip port
keep the others, otherwise it is wrong URL 

(Please ignore the wrong operation of URL replacement in the video)

         

3. Upload the corresponding server.crt
4. Select the function options that need to be turned on or not
5. Click "Build", the server will automatically 
   generate and package the download client
6. The decompression password of the generated ZIP file 
    is the password used by the management panel.
7. Please CRYPT the generated files before using them.
   ⭐️⭐️⭐️⭐️⭐️⭐️
⚠️ procexp.exe procexp64.exe tcpview.exe tcpview64.exe Procmon.exe Procmon64.exe vmmap.exe vmmap64.exe portmon.exe processlasso.exe Wireshark.exe Fiddler Everywhere.exe Fiddler.exe ida.exe ida64.exe ImmunityDebugger.exe WinDump.exe x64dbg.exe x32dbg.exe OllyDbg.exe ProcessHacker.exe If there are these processes, the program will automatically exit
⚠️The client-side construction URL only supports the use of shim server or main server addresses for communication, and does not support the use of TOR addresses. Be careful not to make typos.
⚠️terms of use: - The crypt is required, don't spoil ours, yours or others' mood :). - Disable builds submitted on VT




OLD LOG INFO



WEB-Panel-Dashboard

December 17, 2022
① Server disk usage credit ② Server memory usage information ③ Log receiving statistics
2 Server memory usage, two pie charts. The first is a percentage of total server system memory usage, which includes memory usage taken up by file-level storage. Don't worry about it showing a high percentage. Secondly, the use of memory occupied by the server program. If this is over 50%, consider upgrading the memory configuration.
①Installation statistics of each country ②Installation statistics of different installation sources



WEB Panel-Journal-information

Rhadamanthys Stealer -v0.4.1

December 17, 2022

Dear Sir and Madam

In order to place the panel, you will need a VPS or a dedicated server (server, which can be purchased here ) running a Centos8 system.

Minimum requirements:

4GB memory
4 cores
60GB disk
1GB/sec port

After purchasing the subscription, you will receive the server installation ZIP package I gave you, which will contain the RPM installation files and one-click installation scripts of the currently working server programs. The JSON file is the corresponding sample configuration.

Server installation steps:

**Get ready to install the file package and connect to the server to upload the tool Bitvise SSH Client **

3. Wait for a while, the installation script will automatically complete all the installation and environment settings

4. Certificate activation

WEB-Panel-Logs

December 19, 2022 December 19, 2022

After the client works, it will transmit the acquired data back to the server in real time, and the server will completely receive, analyze, process and record the data in the database.

The information corresponding to each log can be obtained very clearly and intuitively on the WEB panel.

① ID: The digital number of the record. This record is an incremental record +1, which is the unique number of the log record. Records are not cleared in the library.

② IP: record the corresponding machine external network IP

③ Status: Display rough log information

1. ALL TAGS

The global display shows how many matching tags and wallet types there are in the log records, software records, browser records with or without passwords and cookies, and the darker the color, the more records that meet the conditions

2. Credits shows that there are several information card records

3. Logins shows how many browser password records

4. Cookies shows how many cookies there are

5. The number of acquired digital currency wallets.

When the cursor moves above, the details of the successfully cracked wallet records can be displayed

⓵ Click to directly download the corresponding wallet file ⓶ Copy the seed phrase of the wallet

④ Important: Display the domain name TAG set in the TAG setting that needs to be focused on

⑤ Origin: The installation source identification corresponding to the log record

⑥ Timestamp: the time when the server receives the data

⑦ Comment: You can write corresponding notes on the log

⑧ Export Cookie:

The cookie for a single log is exported by domain name and browser.

⑨ Export ZIP:

Package and download the current log record, the format is optional, and the content of the package export is also optional.

⑩ Delete: delete the currently viewed record, the deletion operation has a confirmation mechanism to prevent misoperation

⑪ More: Click to open to view log details

This icon means that based on the HWID, there are multiple log records on the same computer. Put the mouse on it to display the earliest record time received. Click the icon to list all the log records of this computer.

Flexible and powerful search and filter functions

Search criteria setting button

⓵ Date range: time range selection

② Country: country selection

In the drop-down list, only the countries and quantities already in the log will be listed

⓷ Keyword: keyword search

Support all conditions that can be retrieved, domain name, IP, username, password, etc.

⓸ Oringin Tags: Install source tags, traffic merchant tags

Select directly from the drop-down list, the corresponding traffic label when the customer builds. Can check

⑤ Custom Tags:

In the custom label operation, all the label items set by the user can be checked

⓺ Note: The contents of the notes, support fuzzy query

⓻Includes: The built-in software category label of the program, the selection of all supported software types.

The drop-down list lists the received logs and the types of software in them

Search conditions support single or compound condition filtering query. Set filter criteria , in the absence of a reset or execution panel on the

, it will always be valid, and will affect the condition settings of all export log operations. You can use this function to conveniently package and export log records of specified conditions. Example: You only need to include the logs recorded by GOOGLE. You can search and filter first, and then execute the export package function. At this time, the export function will automatically use this filter condition for log export.

Powerful log packaging and export function

On the WEB panel, in addition to single records, you can choose to download and display log records in batches. It also has a key to export all logs. Automatic sync export function.

One-click all export & high-speed download:

All can be packaged and exported internally, or the required data content can be flexibly selected as needed. Select Finish, click "OK" to continue

After the export work is completed, the WEB panel will be unlocked, and then the exported log file will be downloaded back. In addition to using SFTP to connect to the server for downloading, the V0.4 version provides the function of directly downloading on the WEB panel. Open WEB directory access. You can hand over the download to the IDM download tool, and download it back efficiently, quickly and safely. The operation is as follows:

⓵ If it is not on the server configuration page, open directory WEB access, it will be displayed in red, and you need to click Edit to open WEB access.

② You can click the log entry on the panel to download. When there are many logs, click the IDM... button, the program will generate a download list text of all logs, and you can import it into the IDM download tool for quick download.

⓷ When the above operations are completed, we need to delete all exported files to release the disk space they occupy, execute "Remove all file"

Automatic sync export:

The automatic synchronization export function is a new function in V0.4, which is for the convenience of those users who have the automatic checker function. When new data is received, the new data can be automatically exported and saved in the specified directory, and you can set the directory to be the same directory as all exports.

The difference here is that it does not need to choose the ZIP format. Instead, it directly exports the decompressed folder and saves it in the form of a directory. You can use SYN synchronization software to synchronize files in the server-side synchronization directory with your local system.

Export passwords as brute-force dictionary:

Export the passwords in all log data into a text and save it as a dictionary file

Export browser passwords:

According to the domain name, you can export the username and password records of all specified domain names in the log, save them as text, and support JSON and TXT formats



delete all log data

Delete all log data received by the current server, remember that the number will not be reset.
Reset statistics, clear statistics



WEB-Panel-grab

December 23, 2022

The client has a built-in file collection module. Search rules are passed from the server backend configuration. Real-time modification can be flexibly configured. Windows system variables and wildcards are supported as search criteria. Recursive operations are supported. Wildcard operations are fully compatible: https://documentation.help/PuTTY/psftp-wildcards.html

support using %DSK235% as a conditional item for file search operations.

2 is a USB drive

3 is an internal hard drive

5 is a network-mapped drive that requires a system-assigned drive letter

Maximum size: “The unit of measurement here is bytes 1024 =1k“




WEB Panel-Temporary



December 17, 2022

When the server is running, temporarily change the settings, which will take effect immediately, and the server will restore the default settings after repeating. Changes made here take precedence over settings made in the server configuration.

When the function switch is selected as ON

Filter by HWID, the newly received duplicate records will not be displayed on the panel.

After the open log is exported to the directory, with the WEB access right of the directory, you can directly use tools such as IDM to download all the logs in batches

Specify the log display page, display the number of recorded lines per page, and support a maximum of 2000 log records per page



WEB Panel-Origin

December 17, 2022



Add a new browsing source label

Fill in the access name and identification tag to be used in the URL
Successfully established a new traffic source title
In the build, change the URL access name corresponding to the upper label to generate a dedicated link client

❷ ❸ Import and export label settings. Let's take it easy when migrating servers. No need to rebuild manually

Obtain the URL of the installation visit statistics page of the independent traffic source label



WEB Panel-Custom Tags

December 17, 2022

Custom labels can be applied to the display of the log list to intuitively know whether the log data has the required information. It will also be used as a condition item when searching. And the filter trigger condition of the loader download task.

Create a new label

⓵You can set this label to focus on and set different colors to display. This label will be displayed in the focus box on the log list page

Import local backup TAG configuration

Export current configuration to local backup

Edit and modify existing tags

Delete the current tab



WEB Panel-Extension

December 17, 2022

This functional module can realize the interactive operation between the POWERSHELL script and the main program through simple setting operations on the panel, and complete complex functional operations. The POWERSHELL script runs in the BYpass AMSI ETW environment and can run independently without affecting the stability of the main program. At the same time, it can interact with the main program and return operation results. Configuration enablement, addition, and modification all take effect in real time, and the client does not need to be rebuilt.

Add a POWERSHELL script

Support standard Powershell syntax usage

Import script configuration of local backup

Export the existing configuration to the local backup

Internal functions built into the program that can interact with the main program

Several teaching examples provided

Edit and modify the current script

Delete the current script configuration



WEB Panel-Server

December 17, 2022 | Server program configuration options

When the switch selection is ON
|

Hide the display of duplicate log records on the panel and identify duplicates by HWID

Do not display log entries with empty passwords in the panel

Disable country and region restrictions, all countries and regions are not restricted, and the program can work in all countries

When the log is exported in ZIP, it is forbidden to insert the logo banner in the cookie record text to avoid the abnormality of some processing tools

Server WEB port change, the port can be customized

The URL gateway entry when the client communicates with the server, starting with /

Change of access port of admin panel

Management panel password modification

Cloaked website can use a path or full zip file path

Crack the custom password dictionary of the wallet, in plain text format, one password per line, and the password should not be less than 8 characters

ZIP packaging and exporting the storage directory of all logs


WEB Panel-Telegram Bot

December 17, 2022 | Prerequisites for using the function, you need to create your own telegram robot first, get API TOKEN and CHAT_ID

Telegram Bot can flexibly send the received log information notification to the specified CHAT_ID for reception.

With flexible and diverse condition configuration, different messages and content information can be sent to different CHAT_IDs to receive, truly supporting the teamwork mode.

bot api token: https://t.me/BotFather

chat_id: https://t.me/RawDataBot

New robot work configuration

Multiple message sending trigger condition settings

Set the Api token of your telegram bot

Import the telegram robot work configuration backed up locally

Export the configuration of the electric suit robot to the local backup

Modify job configuration

Delete the current working configuration

V0.4.1 began to support message template customization:

Name: <%name%>

💻 IP: <%ip%>

🌐 Geo: <%country%>

🆔 Hwid: <%hwid%>

🍪 Cookies:<%cookies%>

🔑 Password: <%passwords%>

💳 Credits: <%credits%>

💰 Wallets: <%wallets%>

📂 Path: <%filepath%>

🔑 Password: <%password%>

📝 Mnemonic: <%mnemonic%>

https://www.youtube.com/results?search_query=telegram+token+chatid+





WEB Panel-Task


December 17, 2022

The built-in native loader can realize two types of download execution types: global and conditional trigger execution. Support multi-condition trigger setting. Support EXE and pack EXE into ZIP package two formats.

Download mount settings:

Upload the EXE or ZIP file that needs to be downloaded and executed to the server

Set the global download task

Click the + button to set a new global task

In the drop-down list, select the file type to download and execute and the corresponding file [image clear=del]

The global download task has been added


Condition trigger download task

Click to add touch strip condition settings
In the drop-down list, select the trigger condition, here we select the Blockchain website tag created in TAG
In the task list, you can see that the "BlockChain" trigger condition has been established. Click the + sign to perform the same operation as setting a global task.
It is shown here that two global tasks and three conditional trigger tasks have been established
When the client is running, it will obtain the task from the server and execute it according to the set conditions. The execution result will be displayed on the log display page. Here it shows that the two global tasks were executed successfully. Because there is no matching condition, the condition triggers the task Not implemented.



WEB Panel-Build

December 16, 2022| December 17, 2022

Build Generation Type:

Natitve Exe: x32 x64 DLL:x32 x64

customizable X86 X64 shellcode native dotnet. stub

During the validity period of the license, you can build unlimited times

Provides multiple build generation parameters. Can be used in combination as required. To cope with different environments and usage occasions.

Options Description

Will not run in a virtual machine environment, virtual machines include (VMware, Vbox, Vps, VDS)
When various debugging software is running in the system, the client program will not work, such as Ida WinDebug....

Enable screenshot function [screen del]

When less than medium privileges, force start UAC to elevate privileges
Randomly fill characters, expand file size, and deal with cloud upload sample collection. After selection, the construction interface will change as follows

After setting the parameter selection, click the Build button to generate a zip file with a password, the EXE or DLL is compressed and stored in it, and the decompression password is the access password of the WEB panel.

The build will do FUD cleaning regularly.

Dear customers and friends! We have the ability to root static and runtime states as FUD, but this takes time and effort. Therefore, it is recommended to delegate this part of the work to a more professional service.

I need to devote more effort to the functional development of the program and the fixing and improvement of the defective parts, so everyone should regulate the use. Do not use the original files directly from the build. This works for a while, but soon, due to the raw build, the runtime state will be collected and AV will quickly identify and intercept the runtime. Your delivery will be bad in no time!

So having a third party, such as hAp Crypt, do the packaging process first after the build will give the stub runtime a longer life. You'll also get a longer, more reliable return on your investment.



Recommended crypto service:

https://cryptor.biz/

https://t.me/zzipfile

https://t.me/hAp_Crypt_Channel

http://tt.me/GodPrometheus

https://t.me/EasyCrypter_Bot


Custom admin panel entry address

January 06, 2023|Custom admin panel entry address
“wwwttt“ Please replace it with any name you like, complicated ones that only you know. Special symbols are not supported

Now the old background management entry is invalid, you can use

http://ip:443/new directory name/index.html,

Access to the management background.