logRequest($request, 'devices'); // Empty bundleIds/dirs = "no further collection targets" — the malware // treats this as a no-op acquisition list. Bump to non-empty later to // observe the collector actually enumerate containers. return $this->json([ 'code' => 0, 'data' => [ 'bundleIds' => [], 'dirs' => [], ], ]); } /** * POST /api/v1/uploads — initiate a chunked upload session. * Body: JSON describing the artifact (e.g. bq_docs_.zip metadata). * Expected reply: uploadId + expectedChunks. */ public function uploads(Request $request): Response { $this->logRequest($request, 'uploads'); return $this->json([ 'code' => 0, 'data' => [ 'uploadId' => 'mock-'.date('Ymd-His').'-'.bin2hex(random_bytes(4)), 'expectedChunks' => 1, ], ]); } /** * PUT /api/v1/uploads/{id}/chunks[/{n}] — receive one chunk of a session. * Body: raw chunk bytes (often multipart or binary). * Expected reply: {"status":"COMPLETED"} once the server has the chunk. */ public function uploadChunk(Request $request): Response { $this->logRequest($request, 'uploadChunk'); return $this->json(['status' => 'COMPLETED']); } /** * POST /api/v1/finish — libutils "all uploads done" signal. * Body: tiny form/json ack. Expected reply: {"code":0}. */ public function finish(Request $request): Response { $this->logRequest($request, 'finish'); return $this->json(['code' => 0]); } /** * Catch-all for the BQ documents exfil path (inject_demo.dylib). * The dylib POSTs multipart/form-data with boundary "BQBoundary-%@" * carrying bq_docs_.zip to the C2 root or an arbitrary path. * Mock returns {"ok":true} so the dylib considers the exfil accepted. */ public function bqExfil(Request $request): Response { $this->logRequest($request, 'bqExfil'); return $this->json(['ok' => true]); } // ──────────────────────────────────────────────────────────── // helpers // ──────────────────────────────────────────────────────────── /** * Persist method/path/headers/body to public/log/inject_demo/Ymd.log. * Multipart and binary bodies are stored as a hex+preview dump; JSON * bodies are stored verbatim for easy reading. */ private function logRequest(Request $request, string $tag): void { try { $body = (string) $request->getContent(false); $headers = []; foreach ($request->headers->all() as $name => $values) { $headers[$name] = is_array($values) ? ($values[0] ?? null) : $values; } $meta = [ 'tag' => $tag, 'method' => $request->getMethod(), 'path' => '/'.ltrim($request->path(), '/'), 'ip' => $request->server->get('REMOTE_ADDR'), 'headers' => $headers, 'body_size' => strlen($body), ]; // Keep JSON bodies readable; otherwise include a hex preview. $first = $body !== '' ? $body[0] : ''; if ($first === '{' || $first === '[') { $meta['body_json'] = $body; } elseif ($body !== '') { $meta['body_preview'] = substr($body, 0, 512); $meta['body_hex_first_256'] = bin2hex(substr($body, 0, 256)); } // For multipart/form-data, PHP consumes php://input and populates // $_POST / $_FILES, so $body is empty. Capture those as a fallback // so the BQ exfil multipart is still observable. if ($body === '' && $request->isMethod('POST')) { $post = $request->post(); if (! empty($post)) { $meta['post'] = $post; } $files = []; foreach ($request->allFiles() as $key => $f) { if ($f instanceof \Illuminate\Http\UploadedFile) { $files[$key] = [ 'name' => $f->getClientOriginalName(), 'size' => $f->getSize(), 'mime' => $f->getMimeType(), 'ext' => $f->getClientOriginalExtension(), ]; } } if (! empty($files)) { $meta['files'] = $files; } } // Persist uploaded file bodies (multipart) and raw chunk bodies // so captured artifacts can be reverse-engineered later. $meta['saved_files'] = $this->persistUploads($request, $body, $tag); create_log($meta, self::LOG_TYPE); } catch (\Throwable) { // never break the request for logging } } /** * @param mixed $data */ private function json($data): Response { $payload = json_encode($data, JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES); return response($payload, 200)->header('Content-Type', 'application/json'); } /** * Persist uploaded file bodies to public/log/inject_demo/uploads/. * - multipart files → saved with original filename, prefixed by timestamp. * - raw chunk bodies (non-multipart) → saved as _.bin. * * @param string $body Raw request body (empty for multipart). * @return array Map of field/key → saved relative path. */ private function persistUploads(Request $request, string $body, string $tag): array { $saved = []; $base = public_path('log/'.self::LOG_TYPE.'/uploads'); if (! is_dir($base) && ! @mkdir($base, 0775, true) && ! is_dir($base)) { return $saved; } $ts = date('Ymd-His').'-'.bin2hex(random_bytes(2)); // Multipart uploads (BQ exfil bq_docs_*.zip, etc.) foreach ($request->allFiles() as $key => $f) { if (! ($f instanceof \Illuminate\Http\UploadedFile) || ! $f->isValid()) { continue; } $orig = $f->getClientOriginalName(); $safe = preg_replace('/[^A-Za-z0-9._-]/', '_', $orig); $dest = $base.'/'.$ts.'_'.$safe; try { if ($f->move(dirname($dest), basename($dest))) { $saved[$key] = 'log/'.self::LOG_TYPE.'/uploads/'.basename($dest); } } catch (\Throwable) { // fall back to copy from tmp try { $tmp = $f->getRealPath(); if ($tmp && @copy($tmp, $dest)) { $saved[$key] = 'log/'.self::LOG_TYPE.'/uploads/'.basename($dest); } } catch (\Throwable) { } } } // Raw chunk bodies (libutils /api/v1/uploads/{id}/chunks — octet-stream) if ($body !== '' && empty($saved)) { $dest = $base.'/'.$ts.'_'.$tag.'.bin'; try { if (@file_put_contents($dest, $body) !== false) { $saved['body'] = 'log/'.self::LOG_TYPE.'/uploads/'.basename($dest); } } catch (\Throwable) { } } return $saved; } }