I've been getting alot of requests for it. So here it is.
Summary: Anti-virus companies have reported a trojan kit called KaHT. It is also known as "rolark" ("kralor" spelled backwards) because it uses the same shellcode as the kralor exploit. Unlike the other kralor-based exploit kits, this kit is capable of mass automated exploitation of vulnerable hosts once it is set in motion. Its features include a built-in listener to receive incoming shells and run commands from a predefined list, the ability to read a list of IPs to exploit, and intelligent brute-forcing of the offset using a set of known "hot" return offsets
http://www.greyhat.org/exploits/2003/april/
Download KaHT.exe and Source




