Added hunt sleeping beacons

This commit is contained in:
Der Benji
2026-06-11 10:55:52 +02:00
parent 44365c280e
commit d2f4253c65
7 changed files with 428 additions and 2 deletions
+35
View File
@@ -99,6 +99,7 @@ A single-page dark-themed interface that aggregates telemetry from all engines:
- **RWX Section Flagging**: Read+Write+Execute permissions highlighted (PE and ELF)
- **TLS Callback Detection**: Anti-debug indicator (PE)
- **Entropy Visualization**: Per-section Shannon entropy with color coding (red >= 7.0 = packed/encrypted)
- **Hunt-Sleeping-Beacons**: Callstack scanner for identifying sleeping C2 beacons (unbacked memory, module stomping, APC/Timer sleepmasks, return address spoofing)
### Developer Experience
@@ -156,6 +157,8 @@ A single-page dark-themed interface that aggregates telemetry from all engines:
| **Fibratus** | 8180 | Kernel ETW telemetry & behavior rules | Go |
| **Rustinel** | — | Sigma/YARA/IOC real-time detection | Rust |
| **Sysmon** | — | Windows event logging | Sysinternals |
| **Hunt-Sleeping-Beacons** | — | Sleeping C2 beacon callstack scanner | C++ / MSVC |
| **theZoo-WebUI** | 8888 | Malware sample browser | PHP |
| **Detonator** | 5000/8000 | Orchestration UI + REST API | Python |
---
@@ -374,6 +377,29 @@ make submit FILE=./samples/mimikatz.exe TARGET=both
3. Click **ELF Analysis** button
4. Review: ELF header, security audit (PIE/NX/RELRO/canary/Fortify), sections, segments, dynamic libraries, suspicious symbol imports
### Hunt-Sleeping-Beacons
Scan running processes for sleeping C2 beacons (RDP or SSH into VM):
```powershell
# Scan all processes
Hunt-Sleeping-Beacons.exe
# Scan a specific PID (e.g., after detonation)
Hunt-Sleeping-Beacons.exe -p 1234
# Include .NET processes (more false positives)
Hunt-Sleeping-Beacons.exe --dotnet
# Show command lines for suspicious processes
Hunt-Sleeping-Beacons.exe --commandline
# Shortcut alias
hsb --commandline
```
Detections include: unbacked memory in callstacks, non-executable memory pages, module stomping (SharedOriginal check), suspicious APC dispatchers, timer-based sleepmask callbacks, abnormal intermodular calls (module proxying), and return address spoofing (jmp gadget patterns).
---
## API Reference
@@ -517,6 +543,8 @@ transportable-detonation-chamber/
│ ├── install-detection-rules.ps1 # Sigma + YARA rules
│ ├── install-detonator.ps1 # Detonator + DetonatorAgent
│ ├── install-litterbox.ps1 # LitterBox sandbox
│ ├── install-thezoo.ps1 # theZoo malware repository + WebUI
│ ├── install-hunt-sleeping-beacons.ps1 # Hunt-Sleeping-Beacons (VS Build Tools + compile)
│ ├── install-webui.ps1 # Web UI deployment
│ └── configure-services.ps1 # Service registration (runs on every boot)
│
@@ -533,6 +561,9 @@ C:\DetonatorAgent\ .NET 8 execution agent
C:\LitterBox\ Analysis sandbox
C:\tools\ThreatCheck\ AV signature scanner
C:\tools\DefenderCheck\ Defender evasion tester
C:\tools\Hunt-Sleeping-Beacons\ Sleeping beacon scanner (callstack analysis)
C:\tools\Hunt-Sleeping-Beacons-src\ HSB source code + VS solution
C:\tools\theZoo-WebUI\ theZoo malware sample browser (PHP, :8888)
C:\tools\detection-rules\ Sigma + YARA + IOC rules
C:\Users\vagrant\Desktop\infected\ Malware samples (Defender-excluded)
```
@@ -561,6 +592,7 @@ Expected output:
LitterBox Running
Fibratus Running
Sysmon Running
theZoo-WebUI Running
```
### Services not starting
@@ -658,3 +690,6 @@ make install # or: .\make.ps1 install
- [rabbitstack/fibratus](https://github.com/rabbitstack/fibratus) — ETW detection engine
- [Karib0u/rustinel](https://github.com/Karib0u/rustinel) — Sigma/YARA EDR agent
- [BlackSnufkin/LitterBox](https://github.com/BlackSnufkin/LitterBox) — Payload analysis sandbox
- [thefLink/Hunt-Sleeping-Beacons](https://github.com/thefLink/Hunt-Sleeping-Beacons) — Sleeping beacon callstack scanner
- [ytisf/theZoo](https://github.com/ytisf/theZoo) — Malware sample repository
- [kawaiipantsu/theZoo-WebUI](https://github.com/kawaiipantsu/theZoo-WebUI) — theZoo web frontend
Vendored
+5
View File
@@ -103,6 +103,11 @@ Vagrant.configure("2") do |config|
path: "scripts/install-thezoo.ps1",
privileged: true
config.vm.provision "hunt-sleeping-beacons",
type: "shell",
path: "scripts/install-hunt-sleeping-beacons.ps1",
privileged: true
config.vm.provision "webui",
type: "shell",
path: "scripts/install-webui.ps1",
+5
View File
@@ -136,6 +136,11 @@ Vagrant.configure("2") do |config|
path: "scripts/install-thezoo.ps1",
privileged: true
config.vm.provision "hunt-sleeping-beacons",
type: "shell",
path: "scripts/install-hunt-sleeping-beacons.ps1",
privileged: true
config.vm.provision "webui",
type: "shell",
path: "scripts/install-webui.ps1",
+28
View File
@@ -0,0 +1,28 @@
$cred = New-Object PSCredential('vagrant', (ConvertTo-SecureString 'vagrant' -AsPlainText -Force))
$result = Invoke-Command -ComputerName 172.17.251.7 -Credential $cred -ScriptBlock {
# Check if VS installer is still running
$installer = Get-Process -Name "vs_installer*","vs_setup*","setup" -ErrorAction SilentlyContinue
if ($installer) {
Write-Output "VS Installer still running: $($installer.Name -join ', ')"
} else {
Write-Output "No VS installer processes running"
}
# Check if MSBuild exists now
$paths = @(
'C:\Program Files\Microsoft Visual Studio\2022\BuildTools\MSBuild\Current\Bin\MSBuild.exe',
'C:\Program Files (x86)\Microsoft Visual Studio\2022\BuildTools\MSBuild\Current\Bin\MSBuild.exe'
)
foreach ($p in $paths) {
if (Test-Path $p) { Write-Output "MSBUILD_FOUND: $p"; return }
}
Write-Output "MSBUILD: NOT_FOUND"
# Check choco install log
$chocoLog = Get-Content "C:\ProgramData\chocolatey\logs\chocolatey.log" -Tail 20 -ErrorAction SilentlyContinue
if ($chocoLog) {
Write-Output "=== Last 20 lines of choco log ==="
$chocoLog | ForEach-Object { Write-Output $_ }
}
}
$result | ForEach-Object { Write-Host $_ }
+228
View File
@@ -0,0 +1,228 @@
# install-hunt-sleeping-beacons.ps1
# Installs Hunt-Sleeping-Beacons - a callstack scanner for identifying sleeping C2 beacons
#
# Source: https://github.com/thefLink/Hunt-Sleeping-Beacons
# Requires: Visual Studio Build Tools 2022 (C++ Desktop workload)
#
# The tool scans process callstacks to identify IOCs indicating:
# - Unbacked/private memory in callstacks
# - Non-executable memory pages
# - Module stomping (copy-on-write detection)
# - Suspicious APC-based sleepmasks
# - Timer-based sleepmasks (enumerating timer callbacks)
# - Abnormal intermodular calls (module proxying)
# - Return address spoofing
#
# Run as Administrator
$ErrorActionPreference = "Continue"
Set-StrictMode -Version Latest
Write-Host "=== Installing Hunt-Sleeping-Beacons ===" -ForegroundColor Cyan
$ToolRoot = "C:\tools\Hunt-Sleeping-Beacons"
$SourceDir = "C:\tools\Hunt-Sleeping-Beacons-src"
$RepoUrl = "https://github.com/thefLink/Hunt-Sleeping-Beacons.git"
# --- Detect architecture ---
$arch = if ([System.Environment]::Is64BitOperatingSystem) {
$procArch = $env:PROCESSOR_ARCHITECTURE
if ($procArch -eq "ARM64") { "ARM64" } else { "x64" }
} else { "x86" }
Write-Host "[*] Detected architecture: $arch" -ForegroundColor Yellow
# --- Install Visual Studio Build Tools 2022 (C++ workload) ---
$msbuildPaths = @(
"C:\Program Files\Microsoft Visual Studio\2022\BuildTools\MSBuild\Current\Bin\MSBuild.exe",
"C:\Program Files (x86)\Microsoft Visual Studio\2022\BuildTools\MSBuild\Current\Bin\MSBuild.exe",
"C:\Program Files\Microsoft Visual Studio\2022\Community\MSBuild\Current\Bin\MSBuild.exe",
"C:\Program Files\Microsoft Visual Studio\2022\Enterprise\MSBuild\Current\Bin\MSBuild.exe",
"C:\Program Files\Microsoft Visual Studio\2022\Professional\MSBuild\Current\Bin\MSBuild.exe"
)
$msbuildExe = $null
foreach ($p in $msbuildPaths) {
if (Test-Path $p) { $msbuildExe = $p; break }
}
if (-not $msbuildExe) {
Write-Host "[*] Installing Visual Studio Build Tools 2022 (C++ Desktop workload)..." -ForegroundColor Yellow
Write-Host " This may take 10-20 minutes on first install." -ForegroundColor DarkGray
# Install via Chocolatey with C++ workload
choco install visualstudio2022buildtools -y --no-progress --package-parameters `
"--add Microsoft.VisualStudio.Workload.VCTools --add Microsoft.VisualStudio.Component.VC.Tools.x86.x64 --add Microsoft.VisualStudio.Component.VC.Tools.ARM64 --add Microsoft.VisualStudio.Component.Windows11SDK.22621 --includeRecommended --passive --norestart"
if ($LASTEXITCODE -ne 0) {
Write-Host "[!] Chocolatey install returned non-zero, trying direct VS installer..." -ForegroundColor Yellow
# Fallback: download and run VS Build Tools installer directly
$vsInstallerUrl = "https://aka.ms/vs/17/release/vs_buildtools.exe"
$vsInstaller = "$env:TEMP\vs_buildtools.exe"
Invoke-WebRequest -Uri $vsInstallerUrl -OutFile $vsInstaller -UseBasicParsing
Start-Process -FilePath $vsInstaller -ArgumentList `
"--quiet", "--wait", "--norestart", `
"--add", "Microsoft.VisualStudio.Workload.VCTools", `
"--add", "Microsoft.VisualStudio.Component.VC.Tools.x86.x64", `
"--add", "Microsoft.VisualStudio.Component.VC.Tools.ARM64", `
"--add", "Microsoft.VisualStudio.Component.Windows11SDK.22621", `
"--includeRecommended" `
-Wait -NoNewWindow
Remove-Item $vsInstaller -Force -ErrorAction SilentlyContinue
}
# Re-check for MSBuild
foreach ($p in $msbuildPaths) {
if (Test-Path $p) { $msbuildExe = $p; break }
}
if (-not $msbuildExe) {
Write-Host "[!] MSBuild not found after installation. Build will be skipped." -ForegroundColor Red
Write-Host " You can manually build after installing Visual Studio Build Tools 2022." -ForegroundColor DarkGray
} else {
Write-Host "[+] Visual Studio Build Tools installed: $msbuildExe" -ForegroundColor Green
}
} else {
Write-Host "[+] MSBuild already available: $msbuildExe" -ForegroundColor Green
}
# --- Clone the repository ---
if (-not (Test-Path "$SourceDir\src\Hunt-Sleeping-Beacons.sln")) {
Write-Host "[*] Cloning Hunt-Sleeping-Beacons..." -ForegroundColor Yellow
if (Test-Path $SourceDir) { Remove-Item $SourceDir -Recurse -Force }
git clone $RepoUrl $SourceDir 2>&1 | Out-Null
if ($LASTEXITCODE -ne 0) {
Write-Host "[!] Failed to clone Hunt-Sleeping-Beacons" -ForegroundColor Red
exit 1
}
Write-Host "[+] Repository cloned to $SourceDir" -ForegroundColor Green
} else {
Write-Host "[+] Hunt-Sleeping-Beacons source already present at $SourceDir" -ForegroundColor Green
Push-Location $SourceDir
git pull --ff-only 2>&1 | Out-Null
Pop-Location
}
# --- Build the project ---
$buildSuccess = $false
if ($msbuildExe) {
Write-Host "[*] Building Hunt-Sleeping-Beacons (Release|$arch)..." -ForegroundColor Yellow
$slnFile = "$SourceDir\src\Hunt-Sleeping-Beacons.sln"
$platform = $arch # x64, ARM64, or x86 (matches solution config)
# Run MSBuild
$buildArgs = @(
$slnFile,
"/p:Configuration=Release",
"/p:Platform=$platform",
"/m",
"/verbosity:minimal",
"/nologo"
)
& $msbuildExe @buildArgs
if ($LASTEXITCODE -eq 0) {
$buildSuccess = $true
Write-Host "[+] Build succeeded" -ForegroundColor Green
} else {
Write-Host "[!] Build failed with exit code $LASTEXITCODE" -ForegroundColor Red
Write-Host " Attempting NuGet restore and retry..." -ForegroundColor Yellow
# Try restoring NuGet packages first
& $msbuildExe $slnFile /t:Restore /p:Configuration=Release /p:Platform=$platform /verbosity:minimal /nologo 2>&1 | Out-Null
& $msbuildExe @buildArgs
if ($LASTEXITCODE -eq 0) {
$buildSuccess = $true
Write-Host "[+] Build succeeded after restore" -ForegroundColor Green
} else {
Write-Host "[!] Build failed. Source is available at $SourceDir for manual compilation." -ForegroundColor Red
}
}
}
# --- Deploy built binary ---
if (-not (Test-Path $ToolRoot)) {
New-Item $ToolRoot -ItemType Directory -Force | Out-Null
}
if ($buildSuccess) {
# Find the built executable
$outputDirs = @(
"$SourceDir\src\Hunt-Sleeping-Beacons\$platform\Release",
"$SourceDir\src\$platform\Release",
"$SourceDir\src\Hunt-Sleeping-Beacons\Release",
"$SourceDir\x64\Release",
"$SourceDir\ARM64\Release"
)
$builtExe = $null
foreach ($dir in $outputDirs) {
$candidate = Join-Path $dir "Hunt-Sleeping-Beacons.exe"
if (Test-Path $candidate) { $builtExe = $candidate; break }
# Also check with different casing
$candidates = Get-ChildItem $dir -Filter "*.exe" -ErrorAction SilentlyContinue
if ($candidates) {
$builtExe = $candidates[0].FullName
break
}
}
if ($builtExe) {
Copy-Item $builtExe "$ToolRoot\Hunt-Sleeping-Beacons.exe" -Force
Write-Host "[+] Binary deployed: $ToolRoot\Hunt-Sleeping-Beacons.exe" -ForegroundColor Green
} else {
Write-Host "[!] Could not locate built executable in expected output directories" -ForegroundColor Yellow
Write-Host " Searching recursively..." -ForegroundColor DarkGray
$found = Get-ChildItem $SourceDir -Filter "Hunt-Sleeping-Beacons.exe" -Recurse -ErrorAction SilentlyContinue | Select-Object -First 1
if ($found) {
Copy-Item $found.FullName "$ToolRoot\Hunt-Sleeping-Beacons.exe" -Force
Write-Host "[+] Binary found and deployed: $ToolRoot\Hunt-Sleeping-Beacons.exe" -ForegroundColor Green
} else {
Write-Host "[!] No executable found after build. Check build output manually." -ForegroundColor Red
}
}
} else {
Write-Host "[!] Build was skipped or failed. Source available at: $SourceDir" -ForegroundColor Yellow
Write-Host " To build manually: msbuild $SourceDir\src\Hunt-Sleeping-Beacons.sln /p:Configuration=Release /p:Platform=$arch" -ForegroundColor DarkGray
}
# --- Add to PATH ---
$currentPath = [Environment]::GetEnvironmentVariable("Path", "Machine")
if ($currentPath -notlike "*$ToolRoot*") {
[Environment]::SetEnvironmentVariable("Path", "$ToolRoot;$currentPath", "Machine")
$env:Path = "$ToolRoot;$env:Path"
Write-Host "[+] Added $ToolRoot to system PATH" -ForegroundColor Green
}
# --- Create a convenience batch wrapper (for use without full path) ---
$wrapperContent = @"
@echo off
REM Hunt-Sleeping-Beacons wrapper
REM Usage: hsb [options]
REM -p / --pid {PID} Scan a specific process
REM --dotnet Include .NET processes (prone to false positives)
REM --commandline Show command lines for suspicious processes
REM -h / --help Show help
"$ToolRoot\Hunt-Sleeping-Beacons.exe" %*
"@
Set-Content "$ToolRoot\hsb.bat" $wrapperContent -Force
Write-Host "[+] Created shortcut: hsb.bat (use 'hsb' from any directory)" -ForegroundColor Green
# --- Verify installation ---
Write-Host ""
Write-Host "=== Hunt-Sleeping-Beacons Installation Complete ===" -ForegroundColor Cyan
Write-Host " Binary: $ToolRoot\Hunt-Sleeping-Beacons.exe" -ForegroundColor White
Write-Host " Source: $SourceDir" -ForegroundColor White
Write-Host " Shortcut: hsb (from any directory)" -ForegroundColor White
Write-Host ""
Write-Host " Usage:" -ForegroundColor White
Write-Host " Hunt-Sleeping-Beacons.exe # Scan all processes" -ForegroundColor DarkGray
Write-Host " Hunt-Sleeping-Beacons.exe -p 1234 # Scan specific PID" -ForegroundColor DarkGray
Write-Host " Hunt-Sleeping-Beacons.exe --commandline # Show cmdlines" -ForegroundColor DarkGray
Write-Host ""
if (Test-Path "$ToolRoot\Hunt-Sleeping-Beacons.exe") {
Write-Host "[+] Hunt-Sleeping-Beacons ready to use" -ForegroundColor Green
} else {
Write-Host "[!] Binary not present - manual build required (see source dir above)" -ForegroundColor Yellow
}
+126 -1
View File
@@ -2352,6 +2352,128 @@ async function viewLitterboxResult(hash) {
setDetailBody(html);
}
async function viewDetonationResult(lbHash, sha256, pid, filename) {
const displayHash = sha256 || lbHash || 'unknown';
pushDetailHistory('detonation-result', displayHash);
setDetailHeader('Analysis', 'background:rgba(167,139,250,0.15);color:var(--accent-purple)', 'Detonation Results', (filename || displayHash.substring(0, 12) + '...'));
setDetailBody('<div class="muted">Fetching analysis results...</div>');
showDetail();
let html = '';
// --- Fetch Fibratus/Rustinel alerts via /api/detonation/results ---
let fibratusAlerts = [];
let fibratusCount = 0;
try {
const params = new URLSearchParams();
if (sha256) params.set('sha256', sha256);
if (pid) params.set('pid', pid);
if (lbHash) params.set('litterbox_hash', lbHash);
if (filename) params.set('filename', filename);
const resp = await fetch(`/api/detonation/results?${params}`);
if (resp.ok) {
const data = await resp.json();
fibratusAlerts = data.fibratus_alerts || [];
fibratusCount = data.fibratus_alert_count || fibratusAlerts.length;
}
} catch (e) {}
// --- Fetch LitterBox results (if hash available) ---
let staticData = null, dynamicData = null, fileInfo = null;
if (lbHash) {
try {
const resp = await fetch(`/api/litterbox/results/static/${encodeURIComponent(lbHash)}`);
if (resp.ok) staticData = await resp.json();
} catch (e) {}
try {
const resp = await fetch(`/api/litterbox/results/dynamic/${encodeURIComponent(lbHash)}`);
if (resp.ok) dynamicData = await resp.json();
} catch (e) {}
try {
const resp = await fetch(`/api/litterbox/results/info/${encodeURIComponent(lbHash)}`);
if (resp.ok) fileInfo = await resp.json();
} catch (e) {}
}
// --- File info section ---
html += `<div class="detail-fields">`;
if (fileInfo) {
if (fileInfo.filename || fileInfo.name || filename) html += `<div class="detail-field"><span class="field-label">Filename</span><span class="field-value">${escapeHtml(fileInfo.filename || fileInfo.name || filename)}</span></div>`;
if (fileInfo.sha256 || sha256) html += `<div class="detail-field"><span class="field-label">SHA-256</span><span class="field-value mono" style="font-size:10px;word-break:break-all">${escapeHtml(fileInfo.sha256 || sha256)}</span></div>`;
if (fileInfo.md5) html += `<div class="detail-field"><span class="field-label">MD5</span><span class="field-value mono" style="font-size:10px">${escapeHtml(fileInfo.md5)}</span></div>`;
if (fileInfo.size !== undefined) html += `<div class="detail-field"><span class="field-label">Size</span><span class="field-value">${formatSize(fileInfo.size)}</span></div>`;
if (fileInfo.file_type || fileInfo.type) html += `<div class="detail-field"><span class="field-label">Type</span><span class="field-value">${escapeHtml(fileInfo.file_type || fileInfo.type)}</span></div>`;
if (pid) html += `<div class="detail-field"><span class="field-label">PID</span><span class="field-value">${escapeHtml(pid)}</span></div>`;
if (fileInfo.score !== undefined) html += `<div class="detail-field"><span class="field-label">Score</span><span class="field-value" style="color:${fileInfo.score >= 7 ? 'var(--accent-red)' : fileInfo.score >= 4 ? '#fbbf24' : 'var(--accent-green)'};font-weight:700">${fileInfo.score}/10</span></div>`;
} else {
if (filename) html += `<div class="detail-field"><span class="field-label">Filename</span><span class="field-value">${escapeHtml(filename)}</span></div>`;
if (sha256) html += `<div class="detail-field"><span class="field-label">SHA-256</span><span class="field-value mono" style="font-size:10px;word-break:break-all">${escapeHtml(sha256)}</span></div>`;
if (pid) html += `<div class="detail-field"><span class="field-label">PID</span><span class="field-value">${escapeHtml(pid)}</span></div>`;
}
html += `</div>`;
// --- Fibratus / Rustinel Alerts Section ---
html += '<div class="detail-section"><div class="detail-section-title">FIBRATUS / RUSTINEL ALERTS';
if (fibratusCount > 0) html += ` <span class="badge badge-red" style="margin-left:6px;">${fibratusCount}</span>`;
html += '</div>';
if (fibratusAlerts.length > 0) {
html += '<div class="det-alerts-list" style="padding:0 8px 8px;">';
fibratusAlerts.slice(0, 30).forEach(alert => {
const sev = (alert.severity || 'unknown').toLowerCase();
const ruleName = alert.rule_name || 'Unknown Rule';
const procName = alert.process_name || '';
const engine = alert.engine || '';
const alertPid = alert.pid || '';
const ts = alert.timestamp ? new Date(alert.timestamp).toLocaleTimeString('en-GB', {hour12:false}) : '';
html += `<div class="det-alert-item sev-${sev}">
<span class="det-alert-sev">${sev.toUpperCase()}</span>
<span class="det-alert-rule">${escapeHtml(ruleName)}</span>
<span class="det-alert-proc">${escapeHtml(procName)}${alertPid ? ' (PID:' + alertPid + ')' : ''}</span>
${engine ? '<span class="det-alert-engine">' + escapeHtml(engine) + '</span>' : ''}
${ts ? '<span class="det-alert-ts" style="color:var(--text-muted);font-size:10px;margin-left:auto;">' + ts + '</span>' : ''}
</div>`;
});
if (fibratusCount > 30) {
html += `<div class="muted" style="padding:6px 0;font-size:10px;">... and ${fibratusCount - 30} more alerts</div>`;
}
html += '</div>';
} else {
html += `<div class="muted" style="padding:8px;font-size:11px;">No Fibratus/Rustinel alerts matched for this sample.</div>`;
}
html += '</div>';
// --- Static analysis results ---
if (lbHash) {
html += '<div class="detail-section"><div class="detail-section-title">STATIC ANALYSIS (LitterBox)</div>';
if (staticData && !staticData.error) {
html += '<div class="lb-result-content">';
html += renderLbStaticResults(staticData);
html += '</div>';
} else {
html += `<div class="muted" style="padding:8px;font-size:11px;">${staticData?.error ? escapeHtml(staticData.error) : 'No static analysis results available.'}</div>`;
}
html += '</div>';
// --- Dynamic analysis results ---
html += '<div class="detail-section"><div class="detail-section-title">DYNAMIC ANALYSIS (LitterBox)</div>';
if (dynamicData && !dynamicData.error) {
html += '<div class="lb-result-content">';
html += renderLbDynamicResults(dynamicData);
html += '</div>';
} else {
html += `<div class="muted" style="padding:8px;font-size:11px;">${dynamicData?.error ? escapeHtml(dynamicData.error) : 'No dynamic analysis results available.'}</div>`;
}
html += '</div>';
}
// Link to LitterBox UI
if (lbHash) {
html += `<div style="margin-top:12px;"><a href="http://localhost:1337" target="_blank" class="btn btn-sm" style="color:var(--accent-purple);border-color:rgba(167,139,250,0.3);">Open in LitterBox UI</a></div>`;
}
setDetailBody(html);
}
function renderLbStaticResults(data) {
let html = '';
@@ -3330,7 +3452,10 @@ async function refreshSubmissions() {
// Add LitterBox results button if submission went to LitterBox
const lbHash = sub.litterbox_hash || sub.sha256;
if (lbHash && (sub.target === 'litterbox' || sub.target === 'both' || sub.litterbox_status === 'success')) {
actions += ` <button class="btn btn-xs btn-lb-results" onclick="viewLitterboxResult('${escapeHtml(lbHash)}')" title="View LitterBox scan results">Results</button>`;
actions += ` <button class="btn btn-xs btn-lb-results" onclick="viewDetonationResult('${escapeHtml(lbHash)}', '${escapeHtml(sub.sha256 || '')}', '${escapeHtml(sub.agent_pid || '')}', '${escapeHtml(sub.filename || '')}')" title="View analysis results (LitterBox + Fibratus)">Results</button>`;
} else if (sub.sha256 || sub.agent_pid) {
// Even without LitterBox, show results button for Fibratus/Rustinel alerts
actions += ` <button class="btn btn-xs btn-lb-results" onclick="viewDetonationResult('', '${escapeHtml(sub.sha256 || '')}', '${escapeHtml(sub.agent_pid || '')}', '${escapeHtml(sub.filename || '')}')" title="View Fibratus/Rustinel alerts">Results</button>`;
}
html += `<tr>`;
+1 -1
View File
@@ -766,6 +766,6 @@ C:\Users\vagrant\Desktop\infected\ Malware samples (Defender-excluded)</pre>
</div>
</div>
<script src="/static/js/app.js?v=9"></script>
<script src="/static/js/app.js?v=10"></script>
</body>
</html>