mirror of
https://github.com/BenjiTrapp/transportable-detonation-chamber
synced 2026-08-09 12:01:14 +00:00
Added hunt sleeping beacons
This commit is contained in:
@@ -99,6 +99,7 @@ A single-page dark-themed interface that aggregates telemetry from all engines:
|
||||
- **RWX Section Flagging**: Read+Write+Execute permissions highlighted (PE and ELF)
|
||||
- **TLS Callback Detection**: Anti-debug indicator (PE)
|
||||
- **Entropy Visualization**: Per-section Shannon entropy with color coding (red >= 7.0 = packed/encrypted)
|
||||
- **Hunt-Sleeping-Beacons**: Callstack scanner for identifying sleeping C2 beacons (unbacked memory, module stomping, APC/Timer sleepmasks, return address spoofing)
|
||||
|
||||
### Developer Experience
|
||||
|
||||
@@ -156,6 +157,8 @@ A single-page dark-themed interface that aggregates telemetry from all engines:
|
||||
| **Fibratus** | 8180 | Kernel ETW telemetry & behavior rules | Go |
|
||||
| **Rustinel** | — | Sigma/YARA/IOC real-time detection | Rust |
|
||||
| **Sysmon** | — | Windows event logging | Sysinternals |
|
||||
| **Hunt-Sleeping-Beacons** | — | Sleeping C2 beacon callstack scanner | C++ / MSVC |
|
||||
| **theZoo-WebUI** | 8888 | Malware sample browser | PHP |
|
||||
| **Detonator** | 5000/8000 | Orchestration UI + REST API | Python |
|
||||
|
||||
---
|
||||
@@ -374,6 +377,29 @@ make submit FILE=./samples/mimikatz.exe TARGET=both
|
||||
3. Click **ELF Analysis** button
|
||||
4. Review: ELF header, security audit (PIE/NX/RELRO/canary/Fortify), sections, segments, dynamic libraries, suspicious symbol imports
|
||||
|
||||
### Hunt-Sleeping-Beacons
|
||||
|
||||
Scan running processes for sleeping C2 beacons (RDP or SSH into VM):
|
||||
|
||||
```powershell
|
||||
# Scan all processes
|
||||
Hunt-Sleeping-Beacons.exe
|
||||
|
||||
# Scan a specific PID (e.g., after detonation)
|
||||
Hunt-Sleeping-Beacons.exe -p 1234
|
||||
|
||||
# Include .NET processes (more false positives)
|
||||
Hunt-Sleeping-Beacons.exe --dotnet
|
||||
|
||||
# Show command lines for suspicious processes
|
||||
Hunt-Sleeping-Beacons.exe --commandline
|
||||
|
||||
# Shortcut alias
|
||||
hsb --commandline
|
||||
```
|
||||
|
||||
Detections include: unbacked memory in callstacks, non-executable memory pages, module stomping (SharedOriginal check), suspicious APC dispatchers, timer-based sleepmask callbacks, abnormal intermodular calls (module proxying), and return address spoofing (jmp gadget patterns).
|
||||
|
||||
---
|
||||
|
||||
## API Reference
|
||||
@@ -517,6 +543,8 @@ transportable-detonation-chamber/
|
||||
│ ├── install-detection-rules.ps1 # Sigma + YARA rules
|
||||
│ ├── install-detonator.ps1 # Detonator + DetonatorAgent
|
||||
│ ├── install-litterbox.ps1 # LitterBox sandbox
|
||||
│ ├── install-thezoo.ps1 # theZoo malware repository + WebUI
|
||||
│ ├── install-hunt-sleeping-beacons.ps1 # Hunt-Sleeping-Beacons (VS Build Tools + compile)
|
||||
│ ├── install-webui.ps1 # Web UI deployment
|
||||
│ └── configure-services.ps1 # Service registration (runs on every boot)
|
||||
│
|
||||
@@ -533,6 +561,9 @@ C:\DetonatorAgent\ .NET 8 execution agent
|
||||
C:\LitterBox\ Analysis sandbox
|
||||
C:\tools\ThreatCheck\ AV signature scanner
|
||||
C:\tools\DefenderCheck\ Defender evasion tester
|
||||
C:\tools\Hunt-Sleeping-Beacons\ Sleeping beacon scanner (callstack analysis)
|
||||
C:\tools\Hunt-Sleeping-Beacons-src\ HSB source code + VS solution
|
||||
C:\tools\theZoo-WebUI\ theZoo malware sample browser (PHP, :8888)
|
||||
C:\tools\detection-rules\ Sigma + YARA + IOC rules
|
||||
C:\Users\vagrant\Desktop\infected\ Malware samples (Defender-excluded)
|
||||
```
|
||||
@@ -561,6 +592,7 @@ Expected output:
|
||||
LitterBox Running
|
||||
Fibratus Running
|
||||
Sysmon Running
|
||||
theZoo-WebUI Running
|
||||
```
|
||||
|
||||
### Services not starting
|
||||
@@ -658,3 +690,6 @@ make install # or: .\make.ps1 install
|
||||
- [rabbitstack/fibratus](https://github.com/rabbitstack/fibratus) — ETW detection engine
|
||||
- [Karib0u/rustinel](https://github.com/Karib0u/rustinel) — Sigma/YARA EDR agent
|
||||
- [BlackSnufkin/LitterBox](https://github.com/BlackSnufkin/LitterBox) — Payload analysis sandbox
|
||||
- [thefLink/Hunt-Sleeping-Beacons](https://github.com/thefLink/Hunt-Sleeping-Beacons) — Sleeping beacon callstack scanner
|
||||
- [ytisf/theZoo](https://github.com/ytisf/theZoo) — Malware sample repository
|
||||
- [kawaiipantsu/theZoo-WebUI](https://github.com/kawaiipantsu/theZoo-WebUI) — theZoo web frontend
|
||||
|
||||
Vendored
+5
@@ -103,6 +103,11 @@ Vagrant.configure("2") do |config|
|
||||
path: "scripts/install-thezoo.ps1",
|
||||
privileged: true
|
||||
|
||||
config.vm.provision "hunt-sleeping-beacons",
|
||||
type: "shell",
|
||||
path: "scripts/install-hunt-sleeping-beacons.ps1",
|
||||
privileged: true
|
||||
|
||||
config.vm.provision "webui",
|
||||
type: "shell",
|
||||
path: "scripts/install-webui.ps1",
|
||||
|
||||
@@ -136,6 +136,11 @@ Vagrant.configure("2") do |config|
|
||||
path: "scripts/install-thezoo.ps1",
|
||||
privileged: true
|
||||
|
||||
config.vm.provision "hunt-sleeping-beacons",
|
||||
type: "shell",
|
||||
path: "scripts/install-hunt-sleeping-beacons.ps1",
|
||||
privileged: true
|
||||
|
||||
config.vm.provision "webui",
|
||||
type: "shell",
|
||||
path: "scripts/install-webui.ps1",
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
$cred = New-Object PSCredential('vagrant', (ConvertTo-SecureString 'vagrant' -AsPlainText -Force))
|
||||
$result = Invoke-Command -ComputerName 172.17.251.7 -Credential $cred -ScriptBlock {
|
||||
# Check if VS installer is still running
|
||||
$installer = Get-Process -Name "vs_installer*","vs_setup*","setup" -ErrorAction SilentlyContinue
|
||||
if ($installer) {
|
||||
Write-Output "VS Installer still running: $($installer.Name -join ', ')"
|
||||
} else {
|
||||
Write-Output "No VS installer processes running"
|
||||
}
|
||||
|
||||
# Check if MSBuild exists now
|
||||
$paths = @(
|
||||
'C:\Program Files\Microsoft Visual Studio\2022\BuildTools\MSBuild\Current\Bin\MSBuild.exe',
|
||||
'C:\Program Files (x86)\Microsoft Visual Studio\2022\BuildTools\MSBuild\Current\Bin\MSBuild.exe'
|
||||
)
|
||||
foreach ($p in $paths) {
|
||||
if (Test-Path $p) { Write-Output "MSBUILD_FOUND: $p"; return }
|
||||
}
|
||||
Write-Output "MSBUILD: NOT_FOUND"
|
||||
|
||||
# Check choco install log
|
||||
$chocoLog = Get-Content "C:\ProgramData\chocolatey\logs\chocolatey.log" -Tail 20 -ErrorAction SilentlyContinue
|
||||
if ($chocoLog) {
|
||||
Write-Output "=== Last 20 lines of choco log ==="
|
||||
$chocoLog | ForEach-Object { Write-Output $_ }
|
||||
}
|
||||
}
|
||||
$result | ForEach-Object { Write-Host $_ }
|
||||
@@ -0,0 +1,228 @@
|
||||
# install-hunt-sleeping-beacons.ps1
|
||||
# Installs Hunt-Sleeping-Beacons - a callstack scanner for identifying sleeping C2 beacons
|
||||
#
|
||||
# Source: https://github.com/thefLink/Hunt-Sleeping-Beacons
|
||||
# Requires: Visual Studio Build Tools 2022 (C++ Desktop workload)
|
||||
#
|
||||
# The tool scans process callstacks to identify IOCs indicating:
|
||||
# - Unbacked/private memory in callstacks
|
||||
# - Non-executable memory pages
|
||||
# - Module stomping (copy-on-write detection)
|
||||
# - Suspicious APC-based sleepmasks
|
||||
# - Timer-based sleepmasks (enumerating timer callbacks)
|
||||
# - Abnormal intermodular calls (module proxying)
|
||||
# - Return address spoofing
|
||||
#
|
||||
# Run as Administrator
|
||||
|
||||
$ErrorActionPreference = "Continue"
|
||||
Set-StrictMode -Version Latest
|
||||
|
||||
Write-Host "=== Installing Hunt-Sleeping-Beacons ===" -ForegroundColor Cyan
|
||||
|
||||
$ToolRoot = "C:\tools\Hunt-Sleeping-Beacons"
|
||||
$SourceDir = "C:\tools\Hunt-Sleeping-Beacons-src"
|
||||
$RepoUrl = "https://github.com/thefLink/Hunt-Sleeping-Beacons.git"
|
||||
|
||||
# --- Detect architecture ---
|
||||
$arch = if ([System.Environment]::Is64BitOperatingSystem) {
|
||||
$procArch = $env:PROCESSOR_ARCHITECTURE
|
||||
if ($procArch -eq "ARM64") { "ARM64" } else { "x64" }
|
||||
} else { "x86" }
|
||||
Write-Host "[*] Detected architecture: $arch" -ForegroundColor Yellow
|
||||
|
||||
# --- Install Visual Studio Build Tools 2022 (C++ workload) ---
|
||||
$msbuildPaths = @(
|
||||
"C:\Program Files\Microsoft Visual Studio\2022\BuildTools\MSBuild\Current\Bin\MSBuild.exe",
|
||||
"C:\Program Files (x86)\Microsoft Visual Studio\2022\BuildTools\MSBuild\Current\Bin\MSBuild.exe",
|
||||
"C:\Program Files\Microsoft Visual Studio\2022\Community\MSBuild\Current\Bin\MSBuild.exe",
|
||||
"C:\Program Files\Microsoft Visual Studio\2022\Enterprise\MSBuild\Current\Bin\MSBuild.exe",
|
||||
"C:\Program Files\Microsoft Visual Studio\2022\Professional\MSBuild\Current\Bin\MSBuild.exe"
|
||||
)
|
||||
|
||||
$msbuildExe = $null
|
||||
foreach ($p in $msbuildPaths) {
|
||||
if (Test-Path $p) { $msbuildExe = $p; break }
|
||||
}
|
||||
|
||||
if (-not $msbuildExe) {
|
||||
Write-Host "[*] Installing Visual Studio Build Tools 2022 (C++ Desktop workload)..." -ForegroundColor Yellow
|
||||
Write-Host " This may take 10-20 minutes on first install." -ForegroundColor DarkGray
|
||||
|
||||
# Install via Chocolatey with C++ workload
|
||||
choco install visualstudio2022buildtools -y --no-progress --package-parameters `
|
||||
"--add Microsoft.VisualStudio.Workload.VCTools --add Microsoft.VisualStudio.Component.VC.Tools.x86.x64 --add Microsoft.VisualStudio.Component.VC.Tools.ARM64 --add Microsoft.VisualStudio.Component.Windows11SDK.22621 --includeRecommended --passive --norestart"
|
||||
|
||||
if ($LASTEXITCODE -ne 0) {
|
||||
Write-Host "[!] Chocolatey install returned non-zero, trying direct VS installer..." -ForegroundColor Yellow
|
||||
# Fallback: download and run VS Build Tools installer directly
|
||||
$vsInstallerUrl = "https://aka.ms/vs/17/release/vs_buildtools.exe"
|
||||
$vsInstaller = "$env:TEMP\vs_buildtools.exe"
|
||||
Invoke-WebRequest -Uri $vsInstallerUrl -OutFile $vsInstaller -UseBasicParsing
|
||||
Start-Process -FilePath $vsInstaller -ArgumentList `
|
||||
"--quiet", "--wait", "--norestart", `
|
||||
"--add", "Microsoft.VisualStudio.Workload.VCTools", `
|
||||
"--add", "Microsoft.VisualStudio.Component.VC.Tools.x86.x64", `
|
||||
"--add", "Microsoft.VisualStudio.Component.VC.Tools.ARM64", `
|
||||
"--add", "Microsoft.VisualStudio.Component.Windows11SDK.22621", `
|
||||
"--includeRecommended" `
|
||||
-Wait -NoNewWindow
|
||||
Remove-Item $vsInstaller -Force -ErrorAction SilentlyContinue
|
||||
}
|
||||
|
||||
# Re-check for MSBuild
|
||||
foreach ($p in $msbuildPaths) {
|
||||
if (Test-Path $p) { $msbuildExe = $p; break }
|
||||
}
|
||||
|
||||
if (-not $msbuildExe) {
|
||||
Write-Host "[!] MSBuild not found after installation. Build will be skipped." -ForegroundColor Red
|
||||
Write-Host " You can manually build after installing Visual Studio Build Tools 2022." -ForegroundColor DarkGray
|
||||
} else {
|
||||
Write-Host "[+] Visual Studio Build Tools installed: $msbuildExe" -ForegroundColor Green
|
||||
}
|
||||
} else {
|
||||
Write-Host "[+] MSBuild already available: $msbuildExe" -ForegroundColor Green
|
||||
}
|
||||
|
||||
# --- Clone the repository ---
|
||||
if (-not (Test-Path "$SourceDir\src\Hunt-Sleeping-Beacons.sln")) {
|
||||
Write-Host "[*] Cloning Hunt-Sleeping-Beacons..." -ForegroundColor Yellow
|
||||
if (Test-Path $SourceDir) { Remove-Item $SourceDir -Recurse -Force }
|
||||
git clone $RepoUrl $SourceDir 2>&1 | Out-Null
|
||||
if ($LASTEXITCODE -ne 0) {
|
||||
Write-Host "[!] Failed to clone Hunt-Sleeping-Beacons" -ForegroundColor Red
|
||||
exit 1
|
||||
}
|
||||
Write-Host "[+] Repository cloned to $SourceDir" -ForegroundColor Green
|
||||
} else {
|
||||
Write-Host "[+] Hunt-Sleeping-Beacons source already present at $SourceDir" -ForegroundColor Green
|
||||
Push-Location $SourceDir
|
||||
git pull --ff-only 2>&1 | Out-Null
|
||||
Pop-Location
|
||||
}
|
||||
|
||||
# --- Build the project ---
|
||||
$buildSuccess = $false
|
||||
if ($msbuildExe) {
|
||||
Write-Host "[*] Building Hunt-Sleeping-Beacons (Release|$arch)..." -ForegroundColor Yellow
|
||||
|
||||
$slnFile = "$SourceDir\src\Hunt-Sleeping-Beacons.sln"
|
||||
$platform = $arch # x64, ARM64, or x86 (matches solution config)
|
||||
|
||||
# Run MSBuild
|
||||
$buildArgs = @(
|
||||
$slnFile,
|
||||
"/p:Configuration=Release",
|
||||
"/p:Platform=$platform",
|
||||
"/m",
|
||||
"/verbosity:minimal",
|
||||
"/nologo"
|
||||
)
|
||||
|
||||
& $msbuildExe @buildArgs
|
||||
if ($LASTEXITCODE -eq 0) {
|
||||
$buildSuccess = $true
|
||||
Write-Host "[+] Build succeeded" -ForegroundColor Green
|
||||
} else {
|
||||
Write-Host "[!] Build failed with exit code $LASTEXITCODE" -ForegroundColor Red
|
||||
Write-Host " Attempting NuGet restore and retry..." -ForegroundColor Yellow
|
||||
|
||||
# Try restoring NuGet packages first
|
||||
& $msbuildExe $slnFile /t:Restore /p:Configuration=Release /p:Platform=$platform /verbosity:minimal /nologo 2>&1 | Out-Null
|
||||
& $msbuildExe @buildArgs
|
||||
if ($LASTEXITCODE -eq 0) {
|
||||
$buildSuccess = $true
|
||||
Write-Host "[+] Build succeeded after restore" -ForegroundColor Green
|
||||
} else {
|
||||
Write-Host "[!] Build failed. Source is available at $SourceDir for manual compilation." -ForegroundColor Red
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# --- Deploy built binary ---
|
||||
if (-not (Test-Path $ToolRoot)) {
|
||||
New-Item $ToolRoot -ItemType Directory -Force | Out-Null
|
||||
}
|
||||
|
||||
if ($buildSuccess) {
|
||||
# Find the built executable
|
||||
$outputDirs = @(
|
||||
"$SourceDir\src\Hunt-Sleeping-Beacons\$platform\Release",
|
||||
"$SourceDir\src\$platform\Release",
|
||||
"$SourceDir\src\Hunt-Sleeping-Beacons\Release",
|
||||
"$SourceDir\x64\Release",
|
||||
"$SourceDir\ARM64\Release"
|
||||
)
|
||||
|
||||
$builtExe = $null
|
||||
foreach ($dir in $outputDirs) {
|
||||
$candidate = Join-Path $dir "Hunt-Sleeping-Beacons.exe"
|
||||
if (Test-Path $candidate) { $builtExe = $candidate; break }
|
||||
# Also check with different casing
|
||||
$candidates = Get-ChildItem $dir -Filter "*.exe" -ErrorAction SilentlyContinue
|
||||
if ($candidates) {
|
||||
$builtExe = $candidates[0].FullName
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
if ($builtExe) {
|
||||
Copy-Item $builtExe "$ToolRoot\Hunt-Sleeping-Beacons.exe" -Force
|
||||
Write-Host "[+] Binary deployed: $ToolRoot\Hunt-Sleeping-Beacons.exe" -ForegroundColor Green
|
||||
} else {
|
||||
Write-Host "[!] Could not locate built executable in expected output directories" -ForegroundColor Yellow
|
||||
Write-Host " Searching recursively..." -ForegroundColor DarkGray
|
||||
$found = Get-ChildItem $SourceDir -Filter "Hunt-Sleeping-Beacons.exe" -Recurse -ErrorAction SilentlyContinue | Select-Object -First 1
|
||||
if ($found) {
|
||||
Copy-Item $found.FullName "$ToolRoot\Hunt-Sleeping-Beacons.exe" -Force
|
||||
Write-Host "[+] Binary found and deployed: $ToolRoot\Hunt-Sleeping-Beacons.exe" -ForegroundColor Green
|
||||
} else {
|
||||
Write-Host "[!] No executable found after build. Check build output manually." -ForegroundColor Red
|
||||
}
|
||||
}
|
||||
} else {
|
||||
Write-Host "[!] Build was skipped or failed. Source available at: $SourceDir" -ForegroundColor Yellow
|
||||
Write-Host " To build manually: msbuild $SourceDir\src\Hunt-Sleeping-Beacons.sln /p:Configuration=Release /p:Platform=$arch" -ForegroundColor DarkGray
|
||||
}
|
||||
|
||||
# --- Add to PATH ---
|
||||
$currentPath = [Environment]::GetEnvironmentVariable("Path", "Machine")
|
||||
if ($currentPath -notlike "*$ToolRoot*") {
|
||||
[Environment]::SetEnvironmentVariable("Path", "$ToolRoot;$currentPath", "Machine")
|
||||
$env:Path = "$ToolRoot;$env:Path"
|
||||
Write-Host "[+] Added $ToolRoot to system PATH" -ForegroundColor Green
|
||||
}
|
||||
|
||||
# --- Create a convenience batch wrapper (for use without full path) ---
|
||||
$wrapperContent = @"
|
||||
@echo off
|
||||
REM Hunt-Sleeping-Beacons wrapper
|
||||
REM Usage: hsb [options]
|
||||
REM -p / --pid {PID} Scan a specific process
|
||||
REM --dotnet Include .NET processes (prone to false positives)
|
||||
REM --commandline Show command lines for suspicious processes
|
||||
REM -h / --help Show help
|
||||
"$ToolRoot\Hunt-Sleeping-Beacons.exe" %*
|
||||
"@
|
||||
Set-Content "$ToolRoot\hsb.bat" $wrapperContent -Force
|
||||
Write-Host "[+] Created shortcut: hsb.bat (use 'hsb' from any directory)" -ForegroundColor Green
|
||||
|
||||
# --- Verify installation ---
|
||||
Write-Host ""
|
||||
Write-Host "=== Hunt-Sleeping-Beacons Installation Complete ===" -ForegroundColor Cyan
|
||||
Write-Host " Binary: $ToolRoot\Hunt-Sleeping-Beacons.exe" -ForegroundColor White
|
||||
Write-Host " Source: $SourceDir" -ForegroundColor White
|
||||
Write-Host " Shortcut: hsb (from any directory)" -ForegroundColor White
|
||||
Write-Host ""
|
||||
Write-Host " Usage:" -ForegroundColor White
|
||||
Write-Host " Hunt-Sleeping-Beacons.exe # Scan all processes" -ForegroundColor DarkGray
|
||||
Write-Host " Hunt-Sleeping-Beacons.exe -p 1234 # Scan specific PID" -ForegroundColor DarkGray
|
||||
Write-Host " Hunt-Sleeping-Beacons.exe --commandline # Show cmdlines" -ForegroundColor DarkGray
|
||||
Write-Host ""
|
||||
|
||||
if (Test-Path "$ToolRoot\Hunt-Sleeping-Beacons.exe") {
|
||||
Write-Host "[+] Hunt-Sleeping-Beacons ready to use" -ForegroundColor Green
|
||||
} else {
|
||||
Write-Host "[!] Binary not present - manual build required (see source dir above)" -ForegroundColor Yellow
|
||||
}
|
||||
+126
-1
@@ -2352,6 +2352,128 @@ async function viewLitterboxResult(hash) {
|
||||
setDetailBody(html);
|
||||
}
|
||||
|
||||
async function viewDetonationResult(lbHash, sha256, pid, filename) {
|
||||
const displayHash = sha256 || lbHash || 'unknown';
|
||||
pushDetailHistory('detonation-result', displayHash);
|
||||
setDetailHeader('Analysis', 'background:rgba(167,139,250,0.15);color:var(--accent-purple)', 'Detonation Results', (filename || displayHash.substring(0, 12) + '...'));
|
||||
setDetailBody('<div class="muted">Fetching analysis results...</div>');
|
||||
showDetail();
|
||||
|
||||
let html = '';
|
||||
|
||||
// --- Fetch Fibratus/Rustinel alerts via /api/detonation/results ---
|
||||
let fibratusAlerts = [];
|
||||
let fibratusCount = 0;
|
||||
try {
|
||||
const params = new URLSearchParams();
|
||||
if (sha256) params.set('sha256', sha256);
|
||||
if (pid) params.set('pid', pid);
|
||||
if (lbHash) params.set('litterbox_hash', lbHash);
|
||||
if (filename) params.set('filename', filename);
|
||||
const resp = await fetch(`/api/detonation/results?${params}`);
|
||||
if (resp.ok) {
|
||||
const data = await resp.json();
|
||||
fibratusAlerts = data.fibratus_alerts || [];
|
||||
fibratusCount = data.fibratus_alert_count || fibratusAlerts.length;
|
||||
}
|
||||
} catch (e) {}
|
||||
|
||||
// --- Fetch LitterBox results (if hash available) ---
|
||||
let staticData = null, dynamicData = null, fileInfo = null;
|
||||
if (lbHash) {
|
||||
try {
|
||||
const resp = await fetch(`/api/litterbox/results/static/${encodeURIComponent(lbHash)}`);
|
||||
if (resp.ok) staticData = await resp.json();
|
||||
} catch (e) {}
|
||||
try {
|
||||
const resp = await fetch(`/api/litterbox/results/dynamic/${encodeURIComponent(lbHash)}`);
|
||||
if (resp.ok) dynamicData = await resp.json();
|
||||
} catch (e) {}
|
||||
try {
|
||||
const resp = await fetch(`/api/litterbox/results/info/${encodeURIComponent(lbHash)}`);
|
||||
if (resp.ok) fileInfo = await resp.json();
|
||||
} catch (e) {}
|
||||
}
|
||||
|
||||
// --- File info section ---
|
||||
html += `<div class="detail-fields">`;
|
||||
if (fileInfo) {
|
||||
if (fileInfo.filename || fileInfo.name || filename) html += `<div class="detail-field"><span class="field-label">Filename</span><span class="field-value">${escapeHtml(fileInfo.filename || fileInfo.name || filename)}</span></div>`;
|
||||
if (fileInfo.sha256 || sha256) html += `<div class="detail-field"><span class="field-label">SHA-256</span><span class="field-value mono" style="font-size:10px;word-break:break-all">${escapeHtml(fileInfo.sha256 || sha256)}</span></div>`;
|
||||
if (fileInfo.md5) html += `<div class="detail-field"><span class="field-label">MD5</span><span class="field-value mono" style="font-size:10px">${escapeHtml(fileInfo.md5)}</span></div>`;
|
||||
if (fileInfo.size !== undefined) html += `<div class="detail-field"><span class="field-label">Size</span><span class="field-value">${formatSize(fileInfo.size)}</span></div>`;
|
||||
if (fileInfo.file_type || fileInfo.type) html += `<div class="detail-field"><span class="field-label">Type</span><span class="field-value">${escapeHtml(fileInfo.file_type || fileInfo.type)}</span></div>`;
|
||||
if (pid) html += `<div class="detail-field"><span class="field-label">PID</span><span class="field-value">${escapeHtml(pid)}</span></div>`;
|
||||
if (fileInfo.score !== undefined) html += `<div class="detail-field"><span class="field-label">Score</span><span class="field-value" style="color:${fileInfo.score >= 7 ? 'var(--accent-red)' : fileInfo.score >= 4 ? '#fbbf24' : 'var(--accent-green)'};font-weight:700">${fileInfo.score}/10</span></div>`;
|
||||
} else {
|
||||
if (filename) html += `<div class="detail-field"><span class="field-label">Filename</span><span class="field-value">${escapeHtml(filename)}</span></div>`;
|
||||
if (sha256) html += `<div class="detail-field"><span class="field-label">SHA-256</span><span class="field-value mono" style="font-size:10px;word-break:break-all">${escapeHtml(sha256)}</span></div>`;
|
||||
if (pid) html += `<div class="detail-field"><span class="field-label">PID</span><span class="field-value">${escapeHtml(pid)}</span></div>`;
|
||||
}
|
||||
html += `</div>`;
|
||||
|
||||
// --- Fibratus / Rustinel Alerts Section ---
|
||||
html += '<div class="detail-section"><div class="detail-section-title">FIBRATUS / RUSTINEL ALERTS';
|
||||
if (fibratusCount > 0) html += ` <span class="badge badge-red" style="margin-left:6px;">${fibratusCount}</span>`;
|
||||
html += '</div>';
|
||||
if (fibratusAlerts.length > 0) {
|
||||
html += '<div class="det-alerts-list" style="padding:0 8px 8px;">';
|
||||
fibratusAlerts.slice(0, 30).forEach(alert => {
|
||||
const sev = (alert.severity || 'unknown').toLowerCase();
|
||||
const ruleName = alert.rule_name || 'Unknown Rule';
|
||||
const procName = alert.process_name || '';
|
||||
const engine = alert.engine || '';
|
||||
const alertPid = alert.pid || '';
|
||||
const ts = alert.timestamp ? new Date(alert.timestamp).toLocaleTimeString('en-GB', {hour12:false}) : '';
|
||||
html += `<div class="det-alert-item sev-${sev}">
|
||||
<span class="det-alert-sev">${sev.toUpperCase()}</span>
|
||||
<span class="det-alert-rule">${escapeHtml(ruleName)}</span>
|
||||
<span class="det-alert-proc">${escapeHtml(procName)}${alertPid ? ' (PID:' + alertPid + ')' : ''}</span>
|
||||
${engine ? '<span class="det-alert-engine">' + escapeHtml(engine) + '</span>' : ''}
|
||||
${ts ? '<span class="det-alert-ts" style="color:var(--text-muted);font-size:10px;margin-left:auto;">' + ts + '</span>' : ''}
|
||||
</div>`;
|
||||
});
|
||||
if (fibratusCount > 30) {
|
||||
html += `<div class="muted" style="padding:6px 0;font-size:10px;">... and ${fibratusCount - 30} more alerts</div>`;
|
||||
}
|
||||
html += '</div>';
|
||||
} else {
|
||||
html += `<div class="muted" style="padding:8px;font-size:11px;">No Fibratus/Rustinel alerts matched for this sample.</div>`;
|
||||
}
|
||||
html += '</div>';
|
||||
|
||||
// --- Static analysis results ---
|
||||
if (lbHash) {
|
||||
html += '<div class="detail-section"><div class="detail-section-title">STATIC ANALYSIS (LitterBox)</div>';
|
||||
if (staticData && !staticData.error) {
|
||||
html += '<div class="lb-result-content">';
|
||||
html += renderLbStaticResults(staticData);
|
||||
html += '</div>';
|
||||
} else {
|
||||
html += `<div class="muted" style="padding:8px;font-size:11px;">${staticData?.error ? escapeHtml(staticData.error) : 'No static analysis results available.'}</div>`;
|
||||
}
|
||||
html += '</div>';
|
||||
|
||||
// --- Dynamic analysis results ---
|
||||
html += '<div class="detail-section"><div class="detail-section-title">DYNAMIC ANALYSIS (LitterBox)</div>';
|
||||
if (dynamicData && !dynamicData.error) {
|
||||
html += '<div class="lb-result-content">';
|
||||
html += renderLbDynamicResults(dynamicData);
|
||||
html += '</div>';
|
||||
} else {
|
||||
html += `<div class="muted" style="padding:8px;font-size:11px;">${dynamicData?.error ? escapeHtml(dynamicData.error) : 'No dynamic analysis results available.'}</div>`;
|
||||
}
|
||||
html += '</div>';
|
||||
}
|
||||
|
||||
// Link to LitterBox UI
|
||||
if (lbHash) {
|
||||
html += `<div style="margin-top:12px;"><a href="http://localhost:1337" target="_blank" class="btn btn-sm" style="color:var(--accent-purple);border-color:rgba(167,139,250,0.3);">Open in LitterBox UI</a></div>`;
|
||||
}
|
||||
|
||||
setDetailBody(html);
|
||||
}
|
||||
|
||||
function renderLbStaticResults(data) {
|
||||
let html = '';
|
||||
|
||||
@@ -3330,7 +3452,10 @@ async function refreshSubmissions() {
|
||||
// Add LitterBox results button if submission went to LitterBox
|
||||
const lbHash = sub.litterbox_hash || sub.sha256;
|
||||
if (lbHash && (sub.target === 'litterbox' || sub.target === 'both' || sub.litterbox_status === 'success')) {
|
||||
actions += ` <button class="btn btn-xs btn-lb-results" onclick="viewLitterboxResult('${escapeHtml(lbHash)}')" title="View LitterBox scan results">Results</button>`;
|
||||
actions += ` <button class="btn btn-xs btn-lb-results" onclick="viewDetonationResult('${escapeHtml(lbHash)}', '${escapeHtml(sub.sha256 || '')}', '${escapeHtml(sub.agent_pid || '')}', '${escapeHtml(sub.filename || '')}')" title="View analysis results (LitterBox + Fibratus)">Results</button>`;
|
||||
} else if (sub.sha256 || sub.agent_pid) {
|
||||
// Even without LitterBox, show results button for Fibratus/Rustinel alerts
|
||||
actions += ` <button class="btn btn-xs btn-lb-results" onclick="viewDetonationResult('', '${escapeHtml(sub.sha256 || '')}', '${escapeHtml(sub.agent_pid || '')}', '${escapeHtml(sub.filename || '')}')" title="View Fibratus/Rustinel alerts">Results</button>`;
|
||||
}
|
||||
|
||||
html += `<tr>`;
|
||||
|
||||
@@ -766,6 +766,6 @@ C:\Users\vagrant\Desktop\infected\ Malware samples (Defender-excluded)</pre>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<script src="/static/js/app.js?v=9"></script>
|
||||
<script src="/static/js/app.js?v=10"></script>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
Reference in New Issue
Block a user