Sub7, or SubSeven or Sub7Server, is the name of a popular backdoor program.
1. SubSeven.exe - is the file you open and use to control your server (VICTIM)
2. Server.exe - is the file you send to your victim to control him
3. EditServer.exe - is the file you will use to configure the server you chose to use (edit the server)
4. ICQMAPI.DLL - is not necessary to know about but it lets you use the ICQ functions with the client/server.
It was originally designed by someone with the handle 'mobman', whose whereabouts are currently unknown. No development has occurred in several years and the website was updated recently announcing a new version coming soon by mobman.
Since then Sub7 remained dormant for over 6 years until its return in July 2009, marking 10 years after its original creation in 1999.
In July 2009 mobman posted on www.subseven.org which appears to be the official site, that SubSeven has entered another life cycle stage and further development on the project is in the works. The site also announced 2.3 could be the next release, but gives no release date. An IRC server is also given irc.subseven.org which appears to have some of the older crew members from the Sub7Crew back from 1999.
Among Sub7's capabilities are complete file system access and real-time keystroke logging. The latter capability makes it possible for Sub7 to be used to steal passwords and credit card information. It also installs itself into the WIN.INI file and the "run" key of the Windows Registry, in addition to adding a "runner" to the Windows Shell.
How to properly configure a server using Edit Server :
1. Click "browse" and find the server.exe file you are going to edit
(named server.exe in the local directory) then click "Read Current
2. StartUp Methods: you basically check one or MORE boxes to choose
how the server will restart itself everytime the computer is booted.
key name: the registry key name that will go with the startup method
3. Notification Options: Victim Name: the name of your server that
you want to come up in your ICQ notify, Enable ICQ notify to UIN: is
the ICQ number you want the notify to go to, Enable IRC notify: will
send a bot to the IRC server you specify and will notify you of the
IP, port, password etc. Email notify seldom works, so lets not bover
with it here..
4. Protect server: you can set a password so that if your server is
found, the person cannot get it into the edit server to find out the
embedded info inside it
5. Now you can either save the settings to the server you opened,
overwriting the old settings, or you can save a new server with the
settings you just provided, still retaining the old server as well.
6. You can also change the server icon by clicking the button in the
top right corner :)
New Feature: under "Local Options - Advanced" section of the
client theres a button "Test on Local Machine" which runs the server
with special restrictions (accepts localhost connections only)
A) IP Scanner - Scans for IPs with an open port you specify
B) Get PC Info - All PC info, including Disk Size, Space, User etc
C) Get Home Info - Gets all Home Info the vic specifies for their
Windows Registration ( not always availible)
D) Server Options - Options pertaining to removing, changing port,
updating server, etc.
E) IP Notify - Adds a new notify method or changes the current
method on the current server
A) Keyboard - Open Keylogger, get offline keys, disable keyb. etc
B) Chat - Chat with the Victim
C) Matrix - Chat with the vic matrix style (black & green design)
D) Message Manager - Sends a popup message to the vic
E) Spy - ICQ, AIM, MSN, YAHOO Instant Messenger Spies
F) ICQ Takeover - displays all installed UINs on the pc, and u can
take each one over at the click of a button
A) FTP/HTTP - turns the vic into an FTP server, ready for files to
be downloaded via ur FTP client or browser
B) Find Files - searches for a specified file type or file in the
C) Passwords - retrieves Cached, Recorded, RAS, and ICQ/AIM Passes
D) RegEdit - Opens the vics Registry so u can fuck with it >:)
E) App Redirect - Lets you run a DOS command on the vic and shows
you the output
F) Port Redirect - adds an open port to the vic so you can "bounce"
from it using the vics host as your own, E.G.: proxy type of
contraption via IRC
A) File Manager - Upload, Download, Run, and do alotta other cool
shit via this client
B) Windows Manager - Displays open windows which you can close,
C) Process Manager - Shows all processes you can kill, disable,
D) Text-2-Speech - Messes with the Text2Speech engine on the vics
pc, you type, it talks
E) Clipboard Manager - View, change, empty the vics clipboard
F) IRC Bot - Connects an IRC bot from the vic to an IRC server of
5) Fun Manager:
A) Desktop/Webcam - Views Webcam continuous capture, a desktop
continuous preview and full screen capture
B) Flip Screen - Flips victims screen upside down, and sideways
C) Print - Prints on victims screen
D) Browser - Opens victims browser with the webpage you specify
E) Resolution - Changes victims pc resolution
F) Win Colors - Changes the victims computer colors
6) Extra Fun:
A) Screen Saver - Changes the Vics Screensaver
B) Restart Win - Shuts down, reboots, or logs off the victim
C) Mouse - Set Mouse trails, reverse buttons, hide curson etc
D) Sound - Record from vics mic, change volume settings
E) Time/Date - Changes system time
F) Extra - A whole buncha extra shit like hide desktop, hide start
button, hide taskbar, open cd-rom etc.
7) Local Options:
A) Quality - Adjusts the quality of the Webcam/Desktop
B) Local Folder - Changes the Sub7 Local Folder
C) Skins - Skin manager for Sub7
D) Misc Options - Misc shit like toggling animation of windows etc
E) Advanced - Messes with ports used for some Sub7 Functions Dont
bother messing around
F) Run EditServer - Hmm..i wonder what this does...