init
This commit is contained in:
+72
-77
@@ -1,105 +1,100 @@
|
||||
# coruna-lab 工具:DGA seed 替换
|
||||
# coruna-lab 工具:DGA seed / 固定域名
|
||||
|
||||
## 新建 / 刷新工作树(推荐)
|
||||
## 推荐:固定域名列表(多域名探测)
|
||||
|
||||
`source/web` + `source/sync` 为 campaign 原样模板。脚本会复制到 **coruna-lab 根目录** 再打补丁:
|
||||
植入体本身已有「候选列表里哪个可用用哪个」。脚本把 Deployment / Reporting 的 DGA 生成替换为你给的域名列表,并同步改:
|
||||
|
||||
- core(`erupt_flee.js` + `daily.html` 的 sha256/size)
|
||||
- 全部 type0x01 二级包(10 个 `.min.js`)
|
||||
|
||||
```bash
|
||||
cd coruna-lab
|
||||
# 需 py7zr + pycryptodome(macOS 可用 /usr/bin/python3;Homebrew python 建议 venv)
|
||||
pip3 install py7zr pycryptodome
|
||||
|
||||
python3 tools/new_project.py
|
||||
python3 tools/new_project.py \
|
||||
--deployment-domains 'www.dep1.example,www.dep2.example' \
|
||||
--reporting-domains 'www.rep1.example,www.rep2.example,www.rep3.example'
|
||||
```
|
||||
|
||||
等价于:
|
||||
|
||||
1. `source/web` → `coruna-lab/web`(覆盖)
|
||||
2. `source/sync` → `coruna-lab/sync`(覆盖)
|
||||
3. `python3 tools/patch_all.py --apply --root .`
|
||||
|
||||
产物:
|
||||
|
||||
- `web/…`、`sync/` — 可服务树(二级包 + daily/erupt 已换 seed)
|
||||
- `out/seeds.json` — 本次 seed
|
||||
- `out/domains.json` — Deployment / Reporting 候选域名
|
||||
|
||||
常用选项:
|
||||
也支持重复传参:
|
||||
|
||||
```bash
|
||||
python3 tools/new_project.py --skip-patch # 只复制,不打补丁
|
||||
python3 tools/new_project.py \
|
||||
--deployment-domains www.dep1.example \
|
||||
--deployment-domains www.dep2.example \
|
||||
--reporting-domains www.rep1.example \
|
||||
--reporting-domains www.rep2.example
|
||||
```
|
||||
|
||||
产物(`new_project.py` 写入 `server/public/`):
|
||||
|
||||
- `server/public/web/…`、`server/public/sync/` — 可直接由 Laravel public 提供
|
||||
- `server/public/out/seeds.json` — 内部仍写入 seed(供池身份匹配)
|
||||
- `server/public/out/domains.json` — 最终生效的域名列表
|
||||
- `server/public/out/sync/MANIFEST.json` — core sha/size + domains
|
||||
|
||||
约束:
|
||||
|
||||
- 每池最多 **8** 个域名,单域名 ≤ 63 ASCII
|
||||
- 可写 `https://host`(会自动去掉 scheme/path/port)
|
||||
- 部署后把这些域名 DNS/hosts 指到你的 lab server(443)
|
||||
- Deployment 需响应 `/sync/daily.html`;Reporting 需 `/api/user/query` → `OK`
|
||||
- `daily.html` 打到 **Deployment 域名**(不是投递站 `/web/...`);type-0x01 起来后才会请求
|
||||
- 固定域名 shellcode 曾有 callee-saved 寄存器未保存的 bug(会在探测前崩);请用当前 `tools/_domain_patch.py` 重新 `--apply` 后再部署 `web/` + `sync/`
|
||||
- macOS 建议用 `/usr/bin/python3`(需 `py7zr` + `pycryptodome`);Homebrew 3.14 常缺 `Crypto`
|
||||
|
||||
---
|
||||
|
||||
## 仅重建(已有 server/public web/sync)
|
||||
|
||||
```bash
|
||||
# 若尚无 web/ + sync/,--apply 会自动从 source/ 复制一份
|
||||
python3 tools/patch_all.py --apply --root server/public \
|
||||
--deployment-domains 'www.dep1.example,www.dep2.example' \
|
||||
--reporting-domains 'www.rep1.example,www.rep2.example'
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## 旧模式:只换 DGA seed(算域名)
|
||||
|
||||
不传 `--*-domains` 时行为与以前相同:随机/指定 seed,DGA 生成候选域名。
|
||||
|
||||
```bash
|
||||
python3 tools/new_project.py
|
||||
# 或
|
||||
python3 tools/new_project.py \
|
||||
--deployment-seed 09d0b8d58a71653cd1c89c64c866f2e6 \
|
||||
--reporting-seed 2d2aebba0bf3d7d694194a7ab93b0a96
|
||||
```
|
||||
|
||||
---
|
||||
### Seed 格式
|
||||
|
||||
## 仅重建(已有根目录 web/sync)
|
||||
|
||||
```bash
|
||||
python3 tools/patch_all.py --root .
|
||||
# 写入根目录 web/ + sync/:
|
||||
python3 tools/patch_all.py --apply --root .
|
||||
```
|
||||
|
||||
`--apply` **必须**带 `--root`,且不会写入 `source/`。
|
||||
|
||||
也可手动指定 seed:`--deployment-seed … --reporting-seed …`。
|
||||
- ASCII,长度 ≤ 32(二进制槽位定长 32)
|
||||
- 推荐正好 32 个十六进制字符
|
||||
- Deployment / Reporting 各一个
|
||||
|
||||
---
|
||||
|
||||
## 当前(原 campaign)seed
|
||||
|
||||
需要提供 **2 个** seed(Deployment + Reporting),不是一个。
|
||||
|
||||
| 角色 | 原 seed(正好 32 字符 hex) |
|
||||
|------|-----------------------------|
|
||||
| Deployment(dev)DGA | `09d0b8d58a71653cd1c89c64c866f2e6` |
|
||||
| Reporting DGA | `2d2aebba0bf3d7d694194a7ab93b0a96` |
|
||||
|
||||
### 格式要求
|
||||
|
||||
- ASCII,**长度 ≤ 32**(二进制槽位定长 32;更长会破坏相邻字符串)
|
||||
- **推荐正好 32 个十六进制字符**(与原样一致)
|
||||
- 短于 32 可以,脚本会在槽位内用 `NUL` 填充
|
||||
- Deployment / Reporting **各提供一个**,彼此独立
|
||||
|
||||
依赖:
|
||||
|
||||
```bash
|
||||
pip3 install py7zr pycryptodome
|
||||
```
|
||||
|
||||
源 dylib 仍读自 `coruna-online/`;未 `--apply` 时产物写到 `out/`(或 `<root>/out/`)。
|
||||
`--apply` 覆盖的是 **工作树** 的 `web/…/*.min.js`(二级)与 `sync/{daily.html,erupt_flee.js}`。
|
||||
|
||||
---
|
||||
|
||||
## 1. 二级包:改 seed → 重打 10 个 `.min.js`
|
||||
## 分步脚本
|
||||
|
||||
```bash
|
||||
# 二级包 type0x01
|
||||
python3 tools/patch_secondary_packs.py \
|
||||
--deployment-seed <32hex> \
|
||||
--reporting-seed <32hex> \
|
||||
--root . \
|
||||
--apply
|
||||
```
|
||||
--deployment-seed <32hex> --reporting-seed <32hex> \
|
||||
--deployment-domains 'a.com,b.com' --reporting-domains 'c.com,d.com' \
|
||||
--root . --apply
|
||||
|
||||
## 2. Core / daily
|
||||
|
||||
```bash
|
||||
# core + daily 校验
|
||||
python3 tools/patch_core.py \
|
||||
--deployment-seed <32hex> \
|
||||
--reporting-seed <32hex> \
|
||||
--root . \
|
||||
--apply
|
||||
```
|
||||
--deployment-seed <32hex> --reporting-seed <32hex> \
|
||||
--deployment-domains 'a.com,b.com' --reporting-domains 'c.com,d.com' \
|
||||
--root . --apply
|
||||
|
||||
## 3. 只算域名
|
||||
|
||||
```bash
|
||||
# 只算 DGA 域名(固定域名模式不需要)
|
||||
python3 tools/compute_dga_domains.py \
|
||||
--deployment-seed <32hex> \
|
||||
--reporting-seed <32hex> \
|
||||
-n 5
|
||||
--deployment-seed <32hex> --reporting-seed <32hex> -n 5
|
||||
```
|
||||
|
||||
源 dylib 仍读自 `coruna-online/`;`--apply` 写入工作树 `web/` + `sync/`(不会写 `source/`)。
|
||||
|
||||
Reference in New Issue
Block a user