Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

(Oilrig) SideTwist agent doesn't react to 103 (upload) commands #159

Open
arty-hlr opened this issue Mar 19, 2024 · 0 comments
Open

(Oilrig) SideTwist agent doesn't react to 103 (upload) commands #159

arty-hlr opened this issue Mar 19, 2024 · 0 comments

Comments

@arty-hlr
Copy link

Hi,

When going through the Oilrig scenario, in step 3 the fsociety.dat is not uploaded to the control server after submitting the 102 command, here reproduced with a test file, the agent doesn't respond after the 102 command:
Pasted image 20240318165617

We tried with several different files, and do not see any POST request from the agent, unless the file doesn't exist, in which case it responds correctly with an error message. From the SideTwist agent or control server code, it is unclear why this should be happening for uploads.

Steps to reproduce:

  • run controlServer on the Kali VM
  • add scheduled task with SideTwist agent on the workstation
  • create a file on the workstation to be uploaded, or use the output file of Valuevault, fsociety.dat in %APPDATA%
  • run ./evalsC2client.py --set-task toMM '103 FILE_TO_DOWNLOAD'
  • check content of files folder and output of controlServer
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant