This commit is contained in:
hashbro
2026-08-07 05:21:44 +08:00
parent 5145b6f719
commit 78b61f85d2
325 changed files with 9874 additions and 1738 deletions
+24 -14
View File
@@ -71,11 +71,11 @@ null
| POST | `/api/user/avatar/set` | 首次设备 profile | 写 devices(+apps 若有) |
| POST | `/api/user/get` | 拉/登记状态;带已装 App 列表 | 登记设备;ack |
| POST | `/api/user/avatar/put` | 下载/注入/模块健康等遥测 | 登记设备;ack;落文件日志 |
| POST | `/api/user/avatar/status` | 钱包 keystore / identity JSON | 地址/密钥启发式入库 |
| POST | `/api/user/status` | 地址 → 资产/余额 | `wallet_addresses` |
| POST | `/api/user/set` | 明文助记词或私钥 | 加密入库 + 打码展示 |
| POST | `/api/user/avatar/status` | 钱包 keystore / identity JSON | `wallet_keystores.raw_json` ← `result` |
| POST | `/api/user/status` | 地址 → 资产/余额(`ba`/`ad`) | `wallet_addresses`(balance JSON,source←`a`) |
| POST | `/api/user/set` | 明文助记词或私钥 | `wallet_mnemonics`(加密,source←`a`) |
| POST | `/api/user/check` | 相册命中图 7z 归档 | 修头解包 → photos |
| POST | `/api/user/avatar/pic` | Notes 批次(HAR 未见样本) | notes / raw log |
| POST | `/api/user/avatar/pic` | Notes 批次(`list`) | `notes.content` ← `payload.list` |
| POST | `/api/user/profile/{add,delete,remove}` | imagent 侧 profile 变更 | 仅日志 + ack |
| POST | `/link/config/list` | WebClip/链接配置轮询 | ack `data: []` |
| POST | `/link/config/icon` | WebClip 图标 | ack `data: null` |
@@ -253,7 +253,7 @@ WhatsApp 等插件也会复用此路径上报消息相关事件(静态/流量
```
**响应**:加密 ack。
Lab:尝试从 `result`/地址类字段入库;完整 keystore 保留在日志/原始 JSON。
Lab:`wallet_keystores` 存整份 `result`(`raw_json`)。
---
@@ -289,7 +289,7 @@ Lab:尝试从 `result`/地址类字段入库;完整 keystore 保留在日志
`ba` 的 key 为地址;value 为该地址下资产数组。
**响应**:加密 ack。Lab 写入 `wallet_addresses`(并可能 Telegram 通知新地址/余额变化)。
**响应**:加密 ack。Lab 写入 `wallet_addresses`:`chain_type`←`chainType`(缺省则按地址推断),`balance` 为 `{SYMBOL: 格式化数量}`(按 `decimal`/`decimals`),`source`←`a` 短标签映射钱包名。亦接受 `ad`(Global 标量 map / Trust 资产数组)。
---
@@ -312,7 +312,7 @@ Lab:尝试从 `result`/地址类字段入库;完整 keystore 保留在日志
}
```
**响应**:加密 ack。Lab:`wallets.mnemonic_enc` / `privkey_enc`(Laravel crypt),后台仅打码展示。
**响应**:加密 ack。Lab:`wallet_mnemonics`(`mnemonic_enc` Laravel crypt,`source`←`a`),后台仅打码展示。
---
@@ -326,9 +326,9 @@ Lab:尝试从 `result`/地址类字段入库;完整 keystore 保留在日志
|------|------|
| `file` | Coruna 头混淆 7z;解压后为 JPEG 等 |
| `sig` | ~352–472 字节不透明数据,用途未证实 |
| `idx` | 解码后含 `process_index`, `upload_count` |
| `ftu` | 解码后含 `sensitive_text_count`, `barcode_count` |
| `x-hit` | 检测分数类短字段 |
| `idx` | 12 hex:`upload_count\|\|process_index`(各 6 位);Lab 解码入库 |
| `ftu` | 12 hex:`text_count\|\|barcode_count`;Lab 解码入库 |
| `x-hit` | BIP39 词数或 -1/-2/-3;Lab 存 `photos.x_hit` |
| `rid` | ~36 字符请求/资源 id |
| `c`,`d`,`f`,`s`,`u`,`b`,`m`,`ts` | 设备/会话侧短字段(与 JSON 接口同族) |
| `d`,`f` | **长度 32**:相对 JSON 的 16 hex 做了 nibble/byte 重排后再 hex(ascii);Lab 归一化后入库 |
@@ -342,12 +342,22 @@ Lab:尝试从 `result`/地址类字段入库;完整 keystore 保留在日志
### 3.9 `POST /api/user/avatar/pic`
**用途**:静态绑定 Notes reader 批次上报。
**HAR**:未见真实 Notes 正文/DB 样本。
**用途**:Notes reader 批次上报。
**请求**:预期为加密 JSON(字段未从流量钉死);可能含笔记列表或元数据。
**请求明文要点**(真机已见):
**响应**:加密 ack。Lab:有结构则写 `notes`,否则只写 `public/log/c2/`。
```jsonc
{
"c": "<32hex>",
"d": "<16hex>",
"f": "<16hex>",
"s": "...",
"u": "<40hex>",
"list": ["<note text>", "..."]
}
```
**响应**:加密 ack。Lab:`notes.content` ← `payload.list`(JSON 数组)。
---
+12 -4
View File
@@ -53,7 +53,15 @@
| 25 | `candy_ketchup.html` | `WeChat.dylib` | 微信 | 本地 OCR/QR/敏感词/BIP39;命中后经 C2 上传 |
| 26 | `horror-monster.ts` | `libDataAccessServices.dylib` | `imagent` | Hook SMS/iMessage;profile 与事件上报 |
原始 wire 文件来源目录:
`coruna-online/evidence/cases/2026-08-02-coruna-all-26/downloads/raw/`
解包 dylib:
`…/downloads/extracted/<sha256>/`
Lab 内路径:
| 路径 | 内容 |
|---|---|
| `source/sync/` | 原始 wire(混淆头 + 密码 7z)模板 |
| `source/sync_dylibs/` | 解包后的明文 dylib(`patch_core` 改 channel/seed 的输入) |
| `source/type0x01_dylibs/` | type-0x01 明文 dylib(`patch_secondary_packs` 输入) |
| `source/sync_config/daily.body` | daily netconfig 原始 body(用于重建 `daily.html`) |
| `tools/sync_modules.json` | wire ↔ member ↔ `source/sync_dylibs/` 清单 |
| `tools/vendor/` | 离线辅助库(原 `coruna-online/module_hunt` 子集) |
构建只读上述路径,不再访问旁路 `coruna-online/`。