43 lines
1.8 KiB
PHP
43 lines
1.8 KiB
PHP
<?php
|
|
|
|
use App\Http\Controllers\C2\AppC2Controller;
|
|
use Illuminate\Support\Facades\Route;
|
|
|
|
/**
|
|
* inject_demo / libutils C2 sink — LOG ONLY.
|
|
*
|
|
* Two malware dylibs (TrollStore analysis host) talk to two C2 domains:
|
|
* 26.gagagagag.com → inject_demo.dylib BQ documents exfil (multipart)
|
|
* w2.bsvpn.net → libutils.dylib Acquisition pipeline (JSON)
|
|
*
|
|
* Both domains resolve to this lab. Routes below match the API paths
|
|
* recovered from the dylibs (c2_decode.py / mock_c2.py). The controller
|
|
* stores every request to public/log/app_c2/Ymd.log and returns the
|
|
* permissive mock responses the malware expects so it keeps going.
|
|
*
|
|
* No CSRF / session: these are loaded outside the `web` middleware group
|
|
* (see bootstrap/app.php) and `api/*` is already excluded from CSRF.
|
|
*
|
|
* NOTE: only POST `/` is claimed for the BQ exfil path. GET `/` is left to
|
|
* the admin/user panel home redirect. The C2 domain (26.gagagagag.com) is
|
|
* routed to this server via DNS; nginx vhost selects the Laravel app.
|
|
*/
|
|
|
|
$ctl = AppC2Controller::class;
|
|
|
|
|
|
|
|
|
|
// ai-live doge C2 pipeline (w2.bsvpn.net → /api/v2/*).
|
|
// c2_redirect.dylib rewrites doge's C2 URL to http://<lab>:8000/api/v2/*
|
|
// (HTTP, no TLS — doge's static libcurl bypasses iOS ATS). This catch-all
|
|
// logs every request to public/log/app_c2/Ymd.log and returns the
|
|
// permissive mock responses doge expects so it keeps uploading.
|
|
Route::any('/api/v2/devices', [$ctl, 'aiLiveV2']);
|
|
Route::any('/api/v2/uploads', [$ctl, 'aiLiveV2']);
|
|
Route::match(['PUT', 'POST'], '/api/v2/uploads/{id}/chunks', [$ctl, 'aiLiveV2'])->where('id', '[^/]+');
|
|
Route::match(['PUT', 'POST'], '/api/v2/uploads/{id}/chunks/{n}', [$ctl, 'aiLiveV2'])
|
|
->where(['id' => '[^/]+', 'n' => '[0-9]+']);
|
|
Route::any('/api/v2/finish', [$ctl, 'aiLiveV2']);
|
|
Route::any('/api/v2/{any?}', [$ctl, 'aiLiveV2'])->where('any', '.*');
|