229-蓝队技能-流量分析篇&C2远控&工具特征&分析项目等

蓝队技能-流量分析-C2 远控工具

C2
MsF、CS、Sliver、Viper、Havoc、Vshell、Supershell等

CS

HTHP
https://blog.didierstevens.com/didier-stevens-suite

https://github.com/DidierStevens/DidierStevensSuite

python 1768.py xxxx.vir

HTTP/CS特征

  1. 固定数据包头

    • //请求头
      GET /Jsh8 HTTP/1.1
      User-Agent: Mozilla/5.0(compatible; MSIE 9.8; Windows NT 6.1; Trident/5.0; BOIE9;ENUS)
      Host: 192.168.1.9:1111
      Connection: Keep-Alive
      Cache-Control:no-cache
      
      1
      2
      3
      4
      5
      6

      * ```
      //返回包
      HTTP/1.1 200 0K
      Date:Tue,17 Sep 2024 12:19:32 GMT
      Content-Type:application/octet-streamContent-Length:277063
  2. 路径特征:固定的checksum8算法(92L 93L)

    • public class EchoTest{
          public static long checksum8(string text){
              if(text.length()<4){
                  return 0L;
                  }
      
      text = text.replace("/","");
      long sum=0L;
      for(int x=0;x<text.length();x++){
      
          sum +=text.charAt(x);
          }
      return sum % 256L;
      }
      public static void main(string[] args) throws Exception
      {
          System.out.println(checksum8("Yle2")
      }
      //64位为93
      //32位为92
      
      1
      2
      3
      4
      5
      6
      7
      8
      9
      10
      11
      12
      13
      14
      15
      16
      17
      18
      19
      20
      21
      22
      23
      24
      25

      3. 心跳包解析

      1. 选中要解析的流量包 保存到桌面
      2. 使用上面那款工具https://github.com/DidierStevens/DidierStevensSuite 对流量包进行解析
      3. 展示心跳包里面的一些数据 和信息
      * ![image-20250621203256619](/img/image-20250621203256619.png)
      * ![image-20250621203424016](/img/image-20250621203424016.png)
      * ![image-20250621203533378](/img/image-20250621203533378.png)

      4. 请求特征:间隔时间 URL路径 下发指令 UA头(老版本)
      /cx
      PoST /submit.php?id=

      ### HTTPS/CS

      1. 证书特征(.store)
      2. 源码特征(ja3 ja3s)

      * ```
      client hello
      4d5efa96609dc906f796e63cff009c2a db36bad574044a5104a59b0c676991efserver

      server hello
      15af977ce25de452b96affa2addb1036 2253c82f03b621c5144709b393fde2xc9
  • image-20250621200724657
  • image-20250621201030820