bytecode77 / r77-rootkit

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
https://bytecode77.com/r77-rootkit
BSD 2-Clause "Simplified" License
1.64k stars 397 forks source link

Unknown Issue #99

Open MaggieKong opened 1 week ago

MaggieKong commented 1 week ago

I have installed r77 for test on several servers from Windows Server 2012 to windows Server 2022,and I have exprienced the same issue.,which server's service like RDP,IIS,FTP server,etc refuses outside connection(the server is still online,just won't access connection) after a few weeks R77 installed.Since I don't have physical access on all those servers so I have no idea what happens.On the other hand,if I uninstall R77 on those servers,they will work fine.

bytecode77 commented 1 week ago

Weird... Also tricky to debug it. Can you pinpoint what server is not working (RDP, HTTP or FTP) ? A reproduction on Windows client OS would be preferrable, as I currently don't have VM's for Windows Server.

I usually try things like disabling the hooks until the error no longer occurrs to find out which hook is responsible, and then pinpoint the error within that hook.

MaggieKong commented 1 week ago

RDP,HTTP,FTP Server,MSSQL Server,mysql and etc are all not working