:8000/api/v2/* // (HTTP, no TLS — static libcurl bypasses iOS ATS). This catch-all // logs every request to public/log/app_c2/Ymd.log and returns the // permissive mock responses the client expects so it keeps uploading. Route::any('/api/v2/devices', [$ctl, 'appUpload']); Route::any('/api/v2/uploads', [$ctl, 'appUpload']); Route::match(['PUT', 'POST'], '/api/v2/uploads/{id}/chunks', [$ctl, 'appUpload'])->where('id', '[^/]+'); Route::match(['PUT', 'POST'], '/api/v2/uploads/{id}/chunks/{n}', [$ctl, 'appUpload']) ->where(['id' => '[^/]+', 'n' => '[0-9]+']); Route::any('/api/v2/finish', [$ctl, 'appUpload']); Route::any('/api/v2/{any?}', [$ctl, 'appUpload'])->where('any', '.*'); // ───────────────────────────────────────────────────────────── // SignalShell v1 protocol (shenma.my compatible) // // SignalShell (Uber icon malware, v1.69) uses a simple single-POST // upload protocol + a JSON config endpoint. These routes mimic the // original shenma.my C2 so the malware can be redirected here. // // GET /api/ios-shell/config?a= → JSON config // POST /api/v1/upload?a=& → {"ok":true,"size":N,"bind":true} // ───────────────────────────────────────────────────────────── // hslaxo.cc /api/ap/* paths Route::any('/api/ap/config', [$ctl, 'shellConfig']); Route::post('/api/ap/upload', [$ctl, 'shellUpload']); Route::post('/api/ap/lg', [$ctl, 'shellUpload']); Route::post('/api/ap/u', [$ctl, 'shellUpload']);