
Python implementation of the CaRT library for (un)inerting files.
The CaRT file format is used to store/transfer malware and its associated metadata. It neuters the malware so it cannot be executed and encrypts it so anti-virus software cannot flag the CaRT file as malware.
Now that STIX v2 uses JSON as encoding, you can now bundle your STIX report directly in the CaRT format.
When CaRT encodes files, it adds metadata from *.cartmeta file with the same prefix of your file.
Therefore, if you save your STIX report to a .cartmeta file, the resulting CaRT file will have the
full STIX report embedded within it.
Example:
$ ls
file.exe - File I want to encode
file.exe.cartmeta - Stix report of file.exe
$ cart file.exe
$ ls
file.exe - File I want to encode
file.exe.cartmeta - Stix report of file.exe
file.exe.cart - CaRT file containing both the file.exe and its STIX report
CaRT has a mandatory header that looks like this
4s h Q 16s Q
CART<VERSION><RESERVED><ARC4KEY><OPT_HEADER_LEN>
Where VERSION is 1 and RESERVED is 0. In most cases the RC4 key used to decrypt the file is stored in the mandatory header and is always the same thing (first 8 digit of pi twice). However, CaRT provides an option to override the key which then stores null bytes in the mandatory header. You'll then need to know the key to unCaRT the file...
CaRT's optional header is an OPT_HEADER_LEN bytes RC4 blob of a JSON serialized header
RC4(<JSON_SERIALIZED_OPTIONAL_HEADER>)
CaRT's data block is a zlib then RC4 block
RC4(ZLIB(block encoded stream))
Like the optional header, CaRT's optional footer is aN OPT_FOOTER_LEN bytes RC4 blob of a JSON serialized footer
RC4(<JSON_SERIALIZED_OPTIONAL_FOOTER>)
CaRT ends its file with a mandatory footer which allow the format to read the footer and return the hashes without reading the whole file
4s QQ Q
TRAC<RESERVED><OPT_FOOTER_LEN>
By installing the pip package, you get access to the CaRT library and also access to the CaRT CLI.
The CaRT CLI has the following priority for its options:
~/.cart/cart.cfgThese are the options available in the CaRT CLI:
usage: cart [options] file1 file2 ... fileN
The CaRT file format is used to store/transfer malware and its associated metadata.
It neuters the malware so it cannot be executed and encrypts it so anti-virus software
cannot flag the CaRT file as malware.
positional arguments:
file
options:
-h, --help show this help message and exit
-v, --version show program's version number and exit
-d, --delete Delete original after operation succeeded
-f, --force Replace output file if it already exists
-i, --ignore Ignore RC4 key from conf file
-j JSONMETA, --jsonmeta JSONMETA
Provide header metadata as JSON blob
-k KEY, --key KEY Use private RC4 key (base64 encoded). Same key must be provided to unCaRT.
-m, --meta Keep metadata around when extracting CaRTs
-n FILENAME, --name FILENAME
Use this value as metadata filename
-o OUTFILE, --outfile OUTFILE
Set output file
-s, --showmeta Only show the file metadata
CaRT is smart enough to determine if a file needs to be CaRTed or unCaRTed.
To CaRT an unCaRTed file: cart file1
To unCaRT a CaRTed file: cart file1
It is the same command!
The CaRT configuration file looks like this:
[global]
# rc4_key is a base64 representation of your key
rc4_key: AvUzYXNkZg==
# keep_meta is an equivalent to -m in the CLI
keep_meta: True
# force is an equivalent to -f in the CLI
force: True
# default_header is a key/value pair of data to be added to the CaRT in the optional header
[default_header]
poc: Your Name
poc_email: [email protected]
There are also implementations of CaRT in Rust and Java. Check them out below:
Le format de fichier CaRT permet de stocker et de transférer les maliciels et les métadonnées connexes. Il neutralise les maliciels de manière à ce qu’ils puissent être exécutés et chiffrés pour que le logiciel antivirus ne signale pas le fichier CaRT comme étant un maliciel.
Maintenant que la version 2 de STIX utilise JSON aux fins de codage, vous pouvez grouper vos rapports STIX directement
dans le format CaRT. Lorsque CaRT code les fichiers, il ajoute les métadonnées depuis le fichier *.cartmeta avec le même
préfixe que celui utilisé par votre fichier. Par conséquent, si vous enregistrez votre rapport STIX dans un fichier
.cartmeta, le rapport complet sera intégré dans le fichier CaRT résultant.
Par exemple :
$ ls
file.exe - Fichier à coder
file.exe.cartmeta - Rapport STIX du fichier file.exe
$ cart file.exe
$ ls
file.exe - Fichier à coder
file.exe.cartmeta - Rapport STIX du fichier file.exe
file.exe.cart - Fichier CaRT contenant à la fois le fichier file.exe et son rapport STIX