5.4 KiB
Cazalla - Basic Mythic Implant in C
Cazalla is a basic Windows implant written in C, designed to interface with the Mythic C2 framework.
This project was developed based on the article How to build your own Mythic agent in C and serves as an initial version of an implant with room for future improvements.
Cazalla is developed by the OFSTeam at Kaseya. Currently, it only supports the exit and shell commands, but additional functionality is planned for future updates.
Install Cazalla
Once Mythic is installed and running, use the following command to install Cazalla:
./mythic-cli install github <repository-url>
Detection
A YARA rule can be provided for detection purposes.
Communication Protocol
HEADER - Implant to C2
| Key | Key Len (bytes) | Type |
|---|---|---|
| UUID | 36 | Str (char*) |
| Action | 1 | UInt32 |
HEADER - C2 to Implant
| Key | Key Len (bytes) | Type |
|---|---|---|
| Action | 1 | Int32 |
UUID | BODY
Checkin - Implant to C2
Expected:
{
"action": "checkin",
"uuid": "a21bab2e-462e-49ab-9800-fbedaf53ad15",
"ip": "127.0.0.1",
"os": "win",
"arch": "x64",
"hostname": "PC",
"user": "bob",
"domain": "domain.com",
"pid": 123,
"processname": "malware.exe"
}
| Key | Key Len (bytes) | Type |
|---|---|---|
| UUID | 36 | Str (char*) |
| Size IP | 4 | Uint32 |
| IP | Size IP | Str (char*) |
| Size OS | 4 | Uint32 |
| OS | Size OS | Str (char*) |
| Architecture | 1 | Int |
| Size Hostname | 4 | Uint32 |
| HostName | Size Hostname | Str (char*) |
| Size Username | 4 | Uint32 |
| Username | Size Username | Str (char*) |
| Size Domain | 4 | Uint32 |
| Domain | Size Domain | Str (char*) |
| PID | 4 | Uint32 |
| Size Process | 4 | Uint32 |
| Process Name | Size Process Name | Str (char*) |
| Size ExternIP | 4 | Uint32 |
| Extern IP | Size Extern IP | Str (char*) |
Checkin - C2 to Implant
| Key | Key Len (bytes) | Type |
|---|---|---|
| New UUID | 36 | Str (char*) |
| Status | 1 | Byte |
GetTasking - Implant to C2
Expected:
{
"action": "get_tasking",
"tasking_size": 1
}
| Key | Key Len (bytes) | Type |
|---|---|---|
| Number tasks | 4 | Uint32 |
GetTasking - C2 to Implant
Expected:
{
"action": "get_tasking",
"tasks": [
{
"command": "command name",
"parameters": "command param string",
"timestamp": 1578706611.324671,
"id": "task uuid"
}
]
}
| Key | Key Len (bytes) | Type |
|---|---|---|
| NumberOfTasks | 4 | Uint32 |
| Size Of Task1 | 4 | Uint32 |
| Task1 CMD | 1 | Int |
| Task1 UUID | 36 | Str (char*) |
| Task1 LenPara1 | 4 | Uint32 |
| Task1 Param1 | LenParam1 Task1 | Str(char*) |
Post Response Header - Implant to C2
| Key | Key Len (bytes) | Type |
|---|---|---|
| Number Resp | 4 | Uint32 |
Post Response Header - C2 to Implant
| Key | Key Len (bytes) | Type |
|---|---|---|
| Number Resp | 4 | Uint32 |
Post Response Classic Output Return - Implant to C2
Expected:
{
"action": "post_response",
"responses": [
{
"task_id": "uuid of task",
... response message
}
]
}
| Key | Key Len (bytes) | Type |
|---|---|---|
| UUID Resp 1 | 36 | Str (char*) |
| Size Output R1 | 4 | Uint32 |
| Output R1 | Size Output | Bytes |
| Status R1 | 1 | Int |
Post Response Classic Output Return - C2 to Implant
Expected:
{
"action": "post_response",
"responses": [
{
"task_id": UUID,
"status": "success" or "error",
"error": "error message if it exists"
}
]
}
| Key | Key Len (bytes) | Type |
|---|---|---|
| Status Resp1 | 1 | Int |
Future Development
This is an initial version of Cazalla with limited functionality. Currently, it only supports the exit and shell commands. Future updates will introduce additional commands and improvements to enhance its capabilities.