This bot is used by one group of Russian carders and is not for sale, they call it 'triton'
IDA Map file imported to Olly, without IDA i got huge problem to understand the exe:
Decoded strings (some, not everything):
Aleksandr Matrosov know better than me this threat go have a look his article: http://blog.eset.com/2012/12/19/win32spy-ranbyus-modifying-java-code-in-rbs
Let's do directly to the panel...
Clicking on a random day:
A screenshot took by the bot:
Orders to send:
Some task urls:
Some files can be found here: http://vxvault.siri-urz.net/ViriList.php?IP=18.104.22.168
Search via IP:
Search via ID: