cobaltstrike4.5版本破/解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等
Crack cobaltstrike4.5, remove checksum8 feature, bypass BeaconEye, fix stage leakage via wrong path, add TOTP two-factor authentication, add encrypted username display, fix foreign spawn bug in 4.5, rename client configuration file, etc.
cobalt strike4.5 crack
cobaltstrike4.5 crack
[TOC]
This tool and article content are for security research only. Users assume all legal and related responsibilities arising from the use of this tool and article content! The author assumes no legal responsibility! If you engage in any illegal activities while using this tool or article content, you shall bear the corresponding consequences yourself. We will not assume any legal or joint liability. Otherwise, please do not install or use this tool. Your use of this tool or any other express or implied acceptance of this agreement shall be deemed as your having read and agreed to be bound by this agreement. When using this tool for security research, you should ensure that the behavior complies with laws and regulations and that sufficient authorization has been obtained. Do not use it against unauthorized targets.
Yes, I'm back, continuing the original cobaltstrike4.4_cdf: https://github.com/lovechoudoufu/about_cobaltstrike4.4_cdf This time it's version 4.5. The previous 4.4 was deleted by GitHub, and it's estimated that this project will also be deleted soon.
It is recommended to join the Telegram group. Subsequent updates and deleted projects can be downloaded from the group:

Before use, please carefully verify the corresponding version's jar file hash.
Certificate authentication process (using 4.3 as an example): slightly modified in version 4.5.
Official decryption keys for each version:
4.0 1be5be52c6255c33558e8a1cb667cb06
4.1 80e32a742060b884419ba0c171c9aa76
4.2 b20d487addd4713418f2d5a3ae02a7a0
4.3 3a4425490f389aeec312bdd758ad2b99
4.4 5e98194a01c6b48fa582a6a9fcbb92d6
cobaltstrike.auth authentication key file, RSA encrypted. Decrypted content:
4.3
-54, -2, -64, -45, // file header
0, 77, // subsequent length
1, -55, -61, 127, // certificate time limit 29999999 (perpetual)
0, 0, 0, 1, // watermark
43, // version
16, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20,
16, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20,
16, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20,
16, 58, 68, 37, 73, 15, 56, -102, -18, -61, 18, -67, -41, 88, -83, 43, -103
With each version update, the corresponding length increases by 17, and the key increases by 17 bytes.
In aggressor/Aggressor.class, License.checkLicenseGUI(new Authorization()); starts the license authentication:

License.checkLicenseGUI uses isValid, isPerpetual, isExpired, isAlmostExpired to determine if the license is valid or expired:

The Authorization class handles the cobaltstrike.auth file, reads the file content, and calls AuthCrypto().decrypt to process it:

In the AuthCrypto() constructor, load() is called, which performs an MD5 check on resources/authkey.pub and then retrieves the RSA public key:

In decrypt(), _decrypt is called to RSA-decrypt the content of the cobaltstrike.auth file using the public key, assigns the result to array var2, then converts it using DataParser to var3. readInt() retrieves the first four bytes of var3 for file header verification (-889274181 for 3.x; -889274157 for 4.x). Then readShort() gets two bytes as the length, assigned to var5, and var6 = var3.readBytes(var5) retrieves that length of content and returns it:

In the Authorization class, the obtained arrayOfByte2 is the content after removing the first six bytes. It continues processing arrayOfByte2: first retrieves four bytes assigned to i, then four bytes assigned to watermark, then one byte assigned to b1. It checks if b1 < 43, if i == 29999999. In common/ListenerConfig, when watermark is 0, an antivirus detection watermark is added:


After removing the first six bytes, then removing the nine bytes for i, watermark, b1, the remaining content is the keys from 4.0 to 4.3, structured as: 16, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20, 20:
byte b2 = dataParser.readByte(); // get 1 byte, i.e., 16
byte[] arrayOfByte3 = dataParser.readBytes(b2); // get 16 bytes, which is the key for 4.0
byte b3 = dataParser.readByte(); // get 1 byte, i.e., 16
byte[] arrayOfByte4 = dataParser.readBytes(b3); // get 16 bytes, which is the key for 4.1
byte b4 = dataParser.readByte(); // get 1 byte, i.e., 16
byte[] arrayOfByte5 = dataParser.readBytes(b4); // get 16 bytes, which is the key for 4.2
byte b5 = dataParser.readByte(); // get 1 byte, i.e., 16
byte[] arrayOfByte6 = dataParser.readBytes(b5); // get 16 bytes, which is the key for 4.3, assigned to arrayOfByte6
In the Authorization class, SleevedResource.Setup is called to process arrayOfByte6. In SleevedResource, the key is set as the decryption key for AES and HmacSHA256. In _readResource, this.data.decrypt(arrayOfByte1); is called for decryption, and the decrypted content is the dll files in /sleeve/:

In SleeveSecurity, the key for AES and HmacSHA256 decryption is set. It uses the passed value to compute a 256-bit digest, then takes bytes 0-16 as the AES key and bytes 16-32 as the HmacSHA256 key:

If the corresponding key is not obtained, the dll in the sleeve folder cannot be decrypted, and when connecting to the server, the error message "[Sleeve] Bad HMAC" will appear:

For the HMAC decryption part, refer to: Cobaltstrike 4 crack: I issue a license to myself
Therefore, the key to a successful crack is the corresponding CS version key.
According to the official description, version 4.5 adds license security, which is indeed the case:
