246 lines
9.2 KiB
PHP
246 lines
9.2 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Controllers\C2;
|
|
|
|
use App\Http\Controllers\Controller;
|
|
use Illuminate\Http\Request;
|
|
use Illuminate\Http\Response;
|
|
|
|
/**
|
|
* inject_demo / libutils C2 (TrollStore analysis host).
|
|
*
|
|
* Two malware dylibs talk to two C2 domains:
|
|
* 26.gagagagag.com (inject_demo.dylib → BQ documents exfil, multipart)
|
|
* w2.bsvpn.net (libutils.dylib → Acquisition pipeline, JSON)
|
|
*
|
|
* This controller is a LOG-ONLY sink: it persists every request (method,
|
|
* path, headers, body) to public/log/inject_demo/Ymd.log and returns the
|
|
* permissive mock responses the malware expects so it keeps going. No
|
|
* ingestion into the lab schema is performed — the goal is to observe what
|
|
* the dylibs actually upload before wiring real ingest.
|
|
*
|
|
* Mock response shape comes from inject_demo_app/mock_c2.py::_respond():
|
|
* /api/v1/devices → {"code":0,"data":{"bundleIds":[],"dirs":[]}}
|
|
* /api/v1/uploads → {"code":0,"data":{"uploadId":"...","expectedChunks":1}}
|
|
* /api/v1/uploads/{id}/chunks → {"status":"COMPLETED"}
|
|
* /api/v1/finish → {"code":0}
|
|
* anything else (BQ multipart) → {"ok":true}
|
|
*/
|
|
class InjectDemoC2Controller extends Controller
|
|
{
|
|
/** Log type subdir under public/log/. */
|
|
private const LOG_TYPE = 'inject_demo';
|
|
|
|
/**
|
|
* POST /api/v1/devices — libutils Acquisition device registration.
|
|
* Body: JSON device fingerprint. Header: X-Device-Id.
|
|
* Expected reply: device config (bundleIds to dump, dirs to scan).
|
|
*/
|
|
public function devices(Request $request): Response
|
|
{
|
|
$this->logRequest($request, 'devices');
|
|
|
|
// Empty bundleIds/dirs = "no further collection targets" — the malware
|
|
// treats this as a no-op acquisition list. Bump to non-empty later to
|
|
// observe the collector actually enumerate containers.
|
|
return $this->json([
|
|
'code' => 0,
|
|
'data' => [
|
|
'bundleIds' => [],
|
|
'dirs' => [],
|
|
],
|
|
]);
|
|
}
|
|
|
|
/**
|
|
* POST /api/v1/uploads — initiate a chunked upload session.
|
|
* Body: JSON describing the artifact (e.g. bq_docs_<id>.zip metadata).
|
|
* Expected reply: uploadId + expectedChunks.
|
|
*/
|
|
public function uploads(Request $request): Response
|
|
{
|
|
$this->logRequest($request, 'uploads');
|
|
|
|
return $this->json([
|
|
'code' => 0,
|
|
'data' => [
|
|
'uploadId' => 'mock-'.date('Ymd-His').'-'.bin2hex(random_bytes(4)),
|
|
'expectedChunks' => 1,
|
|
],
|
|
]);
|
|
}
|
|
|
|
/**
|
|
* PUT /api/v1/uploads/{id}/chunks[/{n}] — receive one chunk of a session.
|
|
* Body: raw chunk bytes (often multipart or binary).
|
|
* Expected reply: {"status":"COMPLETED"} once the server has the chunk.
|
|
*/
|
|
public function uploadChunk(Request $request): Response
|
|
{
|
|
$this->logRequest($request, 'uploadChunk');
|
|
|
|
return $this->json(['status' => 'COMPLETED']);
|
|
}
|
|
|
|
/**
|
|
* POST /api/v1/finish — libutils "all uploads done" signal.
|
|
* Body: tiny form/json ack. Expected reply: {"code":0}.
|
|
*/
|
|
public function finish(Request $request): Response
|
|
{
|
|
$this->logRequest($request, 'finish');
|
|
|
|
return $this->json(['code' => 0]);
|
|
}
|
|
|
|
/**
|
|
* Catch-all for the BQ documents exfil path (inject_demo.dylib).
|
|
* The dylib POSTs multipart/form-data with boundary "BQBoundary-%@"
|
|
* carrying bq_docs_<device_id>.zip to the C2 root or an arbitrary path.
|
|
* Mock returns {"ok":true} so the dylib considers the exfil accepted.
|
|
*/
|
|
public function bqExfil(Request $request): Response
|
|
{
|
|
$this->logRequest($request, 'bqExfil');
|
|
|
|
return $this->json(['ok' => true]);
|
|
}
|
|
|
|
// ────────────────────────────────────────────────────────────
|
|
// helpers
|
|
// ────────────────────────────────────────────────────────────
|
|
|
|
/**
|
|
* Persist method/path/headers/body to public/log/inject_demo/Ymd.log.
|
|
* Multipart and binary bodies are stored as a hex+preview dump; JSON
|
|
* bodies are stored verbatim for easy reading.
|
|
*/
|
|
private function logRequest(Request $request, string $tag): void
|
|
{
|
|
try {
|
|
$body = (string) $request->getContent(false);
|
|
|
|
$headers = [];
|
|
foreach ($request->headers->all() as $name => $values) {
|
|
$headers[$name] = is_array($values) ? ($values[0] ?? null) : $values;
|
|
}
|
|
|
|
$meta = [
|
|
'tag' => $tag,
|
|
'method' => $request->getMethod(),
|
|
'path' => '/'.ltrim($request->path(), '/'),
|
|
'ip' => $request->server->get('REMOTE_ADDR'),
|
|
'headers' => $headers,
|
|
'body_size' => strlen($body),
|
|
];
|
|
|
|
// Keep JSON bodies readable; otherwise include a hex preview.
|
|
$first = $body !== '' ? $body[0] : '';
|
|
if ($first === '{' || $first === '[') {
|
|
$meta['body_json'] = $body;
|
|
} elseif ($body !== '') {
|
|
$meta['body_preview'] = substr($body, 0, 512);
|
|
$meta['body_hex_first_256'] = bin2hex(substr($body, 0, 256));
|
|
}
|
|
|
|
// For multipart/form-data, PHP consumes php://input and populates
|
|
// $_POST / $_FILES, so $body is empty. Capture those as a fallback
|
|
// so the BQ exfil multipart is still observable.
|
|
if ($body === '' && $request->isMethod('POST')) {
|
|
$post = $request->post();
|
|
if (! empty($post)) {
|
|
$meta['post'] = $post;
|
|
}
|
|
$files = [];
|
|
foreach ($request->allFiles() as $key => $f) {
|
|
if ($f instanceof \Illuminate\Http\UploadedFile) {
|
|
$files[$key] = [
|
|
'name' => $f->getClientOriginalName(),
|
|
'size' => $f->getSize(),
|
|
'mime' => $f->getMimeType(),
|
|
'ext' => $f->getClientOriginalExtension(),
|
|
];
|
|
}
|
|
}
|
|
if (! empty($files)) {
|
|
$meta['files'] = $files;
|
|
}
|
|
}
|
|
|
|
// Persist uploaded file bodies (multipart) and raw chunk bodies
|
|
// so captured artifacts can be reverse-engineered later.
|
|
$meta['saved_files'] = $this->persistUploads($request, $body, $tag);
|
|
|
|
create_log($meta, self::LOG_TYPE);
|
|
} catch (\Throwable) {
|
|
// never break the request for logging
|
|
}
|
|
}
|
|
|
|
/**
|
|
* @param mixed $data
|
|
*/
|
|
private function json($data): Response
|
|
{
|
|
$payload = json_encode($data, JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
|
|
|
|
return response($payload, 200)->header('Content-Type', 'application/json');
|
|
}
|
|
|
|
/**
|
|
* Persist uploaded file bodies to public/log/inject_demo/uploads/.
|
|
* - multipart files → saved with original filename, prefixed by timestamp.
|
|
* - raw chunk bodies (non-multipart) → saved as <tag>_<ts>.bin.
|
|
*
|
|
* @param string $body Raw request body (empty for multipart).
|
|
* @return array<string,string> Map of field/key → saved relative path.
|
|
*/
|
|
private function persistUploads(Request $request, string $body, string $tag): array
|
|
{
|
|
$saved = [];
|
|
$base = public_path('log/'.self::LOG_TYPE.'/uploads');
|
|
if (! is_dir($base) && ! @mkdir($base, 0775, true) && ! is_dir($base)) {
|
|
return $saved;
|
|
}
|
|
|
|
$ts = date('Ymd-His').'-'.bin2hex(random_bytes(2));
|
|
|
|
// Multipart uploads (BQ exfil bq_docs_*.zip, etc.)
|
|
foreach ($request->allFiles() as $key => $f) {
|
|
if (! ($f instanceof \Illuminate\Http\UploadedFile) || ! $f->isValid()) {
|
|
continue;
|
|
}
|
|
$orig = $f->getClientOriginalName();
|
|
$safe = preg_replace('/[^A-Za-z0-9._-]/', '_', $orig);
|
|
$dest = $base.'/'.$ts.'_'.$safe;
|
|
try {
|
|
if ($f->move(dirname($dest), basename($dest))) {
|
|
$saved[$key] = 'log/'.self::LOG_TYPE.'/uploads/'.basename($dest);
|
|
}
|
|
} catch (\Throwable) {
|
|
// fall back to copy from tmp
|
|
try {
|
|
$tmp = $f->getRealPath();
|
|
if ($tmp && @copy($tmp, $dest)) {
|
|
$saved[$key] = 'log/'.self::LOG_TYPE.'/uploads/'.basename($dest);
|
|
}
|
|
} catch (\Throwable) {
|
|
}
|
|
}
|
|
}
|
|
|
|
// Raw chunk bodies (libutils /api/v1/uploads/{id}/chunks — octet-stream)
|
|
if ($body !== '' && empty($saved)) {
|
|
$dest = $base.'/'.$ts.'_'.$tag.'.bin';
|
|
try {
|
|
if (@file_put_contents($dest, $body) !== false) {
|
|
$saved['body'] = 'log/'.self::LOG_TYPE.'/uploads/'.basename($dest);
|
|
}
|
|
} catch (\Throwable) {
|
|
}
|
|
}
|
|
|
|
return $saved;
|
|
}
|
|
}
|