Files
Angerona/README.md
T
2025-04-02 16:45:10 +02:00

5.2 KiB

Cazalla - Basic Mythic Implant in C

Cazalla is a basic Windows implant written in C, designed to interface with the Mythic C2 framework.

This project was developed based on the article How to build your own Mythic agent in C and serves as an initial version of an implant with room for future improvements.

Cazalla is developed by the OFSTeam at Kaseya. Currently, it only supports the exit and shell commands, but additional functionality is planned for future updates.

Install Cazalla

Once Mythic is installed and running, use the following command to install Cazalla:

./mythic-cli install github <repository-url>

Detection

A YARA rule can be provided for detection purposes.

Communication Protocol

HEADER - Implant to C2

Key Key Len (bytes) Type
UUID 36 Str (char*)
Action 1 UInt32

HEADER - C2 to Implant

Key Key Len (bytes) Type
Action 1 Int32

UUID | BODY

Checkin - Implant to C2

Expected:

{
    "action": "checkin",
    "uuid": "a21bab2e-462e-49ab-9800-fbedaf53ad15",
    "ip": "127.0.0.1",
    "os": "win",
    "arch": "x64",
    "hostname": "PC",
    "user": "bob",
    "domain": "domain.com",
    "pid": 123,
    "processname": "malware.exe"
}
Key Key Len (bytes) Type
UUID 36 Str (char*)
Size IP 4 Uint32
IP Size IP Str (char*)
Size OS 4 Uint32
OS Size OS Str (char*)
Architecture 1 Int
Size Hostname 4 Uint32
HostName Size Hostname Str (char*)
Size Username 4 Uint32
Username Size Username Str (char*)
Size Domain 4 Uint32
Domain Size Domain Str (char*)
PID 4 Uint32
Size Process 4 Uint32
Process Name Size Process Name Str (char*)
Size ExternIP 4 Uint32
Extern IP Size Extern IP Str (char*)

Checkin - C2 to Implant

Key Key Len (bytes) Type
New UUID 36 Str (char*)
Status 1 Byte

GetTasking - Implant to C2

Expected:

{
    "action": "get_tasking",
    "tasking_size": 1
}
Key Key Len (bytes) Type
Number tasks 4 Uint32

GetTasking - C2 to Implant

Expected:

{
    "action": "get_tasking",
    "tasks": [
        {
            "command": "command name",
            "parameters": "command param string",
            "timestamp": 1578706611.324671,
            "id": "task uuid"
        }
    ]
}
Key Key Len (bytes) Type
NumberOfTasks 4 Uint32
Size Of Task1 4 Uint32
Task1 CMD 1 Int
Task1 UUID 36 Str (char*)
Task1 LenPara1 4 Uint32
Task1 Param1 LenParam1 Task1 Str(char*)

Post Response Header - Implant to C2

Key Key Len (bytes) Type
Number Resp 4 Uint32

Post Response Header - C2 to Implant

Key Key Len (bytes) Type
Number Resp 4 Uint32

Post Response Classic Output Return - Implant to C2

Expected:

{
    "action": "post_response",
    "responses": [
        {
            "task_id": "uuid of task",
            ... response message
        }
    ]
}
Key Key Len (bytes) Type
UUID Resp 1 36 Str (char*)
Size Output R1 4 Uint32
Output R1 Size Output Bytes
Status R1 1 Int

Post Response Classic Output Return - C2 to Implant

Expected:

{
    "action": "post_response",
    "responses": [
        {
            "task_id": UUID,
            "status": "success" or "error",
            "error": "error message if it exists"
        }
    ]
}
Key Key Len (bytes) Type
Status Resp1 1 Int

Future Development

This is an initial version of Cazalla with limited functionality. Currently, it only supports the exit and shell commands. Future updates will introduce additional commands and improvements to enhance its capabilities.