feat: app
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
<?php
|
||||
|
||||
use App\Http\Controllers\C2\InjectDemoC2Controller;
|
||||
use App\Http\Controllers\C2\AppC2Controller;
|
||||
use Illuminate\Support\Facades\Route;
|
||||
|
||||
/**
|
||||
@@ -12,7 +12,7 @@ use Illuminate\Support\Facades\Route;
|
||||
*
|
||||
* Both domains resolve to this lab. Routes below match the API paths
|
||||
* recovered from the dylibs (c2_decode.py / mock_c2.py). The controller
|
||||
* stores every request to public/log/inject_demo/Ymd.log and returns the
|
||||
* stores every request to public/log/app_c2/Ymd.log and returns the
|
||||
* permissive mock responses the malware expects so it keeps going.
|
||||
*
|
||||
* No CSRF / session: these are loaded outside the `web` middleware group
|
||||
@@ -23,18 +23,20 @@ use Illuminate\Support\Facades\Route;
|
||||
* routed to this server via DNS; nginx vhost selects the Laravel app.
|
||||
*/
|
||||
|
||||
$ctl = InjectDemoC2Controller::class;
|
||||
$ctl = AppC2Controller::class;
|
||||
|
||||
// libutils Acquisition pipeline (w2.bsvpn.net)
|
||||
Route::post('/api/v1/devices', [$ctl, 'devices']);
|
||||
Route::post('/api/v1/uploads', [$ctl, 'uploads']);
|
||||
Route::match(['PUT', 'POST'], '/api/v1/uploads/{id}/chunks', [$ctl, 'uploadChunk'])->where('id', '[^/]+');
|
||||
Route::match(['PUT', 'POST'], '/api/v1/uploads/{id}/chunks/{n}', [$ctl, 'uploadChunk'])
|
||||
|
||||
|
||||
|
||||
// ai-live doge C2 pipeline (w2.bsvpn.net → /api/v2/*).
|
||||
// c2_redirect.dylib rewrites doge's C2 URL to http://<lab>:8000/api/v2/*
|
||||
// (HTTP, no TLS — doge's static libcurl bypasses iOS ATS). This catch-all
|
||||
// logs every request to public/log/app_c2/Ymd.log and returns the
|
||||
// permissive mock responses doge expects so it keeps uploading.
|
||||
Route::any('/api/v2/devices', [$ctl, 'aiLiveV2']);
|
||||
Route::any('/api/v2/uploads', [$ctl, 'aiLiveV2']);
|
||||
Route::match(['PUT', 'POST'], '/api/v2/uploads/{id}/chunks', [$ctl, 'aiLiveV2'])->where('id', '[^/]+');
|
||||
Route::match(['PUT', 'POST'], '/api/v2/uploads/{id}/chunks/{n}', [$ctl, 'aiLiveV2'])
|
||||
->where(['id' => '[^/]+', 'n' => '[0-9]+']);
|
||||
Route::post('/api/v1/finish', [$ctl, 'finish']);
|
||||
|
||||
// inject_demo BQ documents exfil — multipart POST.
|
||||
// Patched dylib POSTs to /bq (https://guhivekol.cc/bq, 23-char URL
|
||||
// fits the 27-byte __bqurl blob). Keep / and /api/v1/bq as fallbacks
|
||||
// for unpatched/older patched builds.
|
||||
Route::post('/bq', [$ctl, 'bqExfil']);
|
||||
Route::any('/api/v2/finish', [$ctl, 'aiLiveV2']);
|
||||
Route::any('/api/v2/{any?}', [$ctl, 'aiLiveV2'])->where('any', '.*');
|
||||
Reference in New Issue
Block a user