[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgOcHBX9fw7MSA8bJRtnJ1NB2Ejzgp16bKbXRKNcFkvE":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},969,"How do Pc and Pc2.2 differ in the context of DanderSpritz trojan generation?","Pc and Pc2.2 correspond to different versions of the PeddleCheap communication module. According to their `Version.xml` files, Pc2.2 is PeddleCheap 2.2.0.2 while Pc is PeddleCheap 2.3.0, a higher version. Using the older Pc2.2 may generate trojans that fail to connect back, as observed during testing. For reliable callback, it is recommended to use the Pc module, as detailed in the [NSA DanderSpiritz Testing Guide](\u002Fnews\u002Fnsa-danderspiritz-testing-guide-trojan-generation-and-testing).","\u003Cp>Pc and Pc2.2 correspond to different versions of the PeddleCheap communication module. According to their `Version.xml` files, Pc2.2 is PeddleCheap 2.2.0.2 while Pc is PeddleCheap 2.3.0, a higher version. Using the older Pc2.2 may generate trojans that fail to connect back, as observed during testing. For reliable callback, it is recommended to use the Pc module, as detailed in the [NSA DanderSpiritz Testing Guide](\u002Fnews\u002Fnsa-danderspiritz-testing-guide-trojan-generation-and-testing).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fnsa-danderspiritz-testing-guide-trojan-generation-and-testing\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-pc-and-pc22-differ-in-the-context-of-danderspritz-trojan-generation-1777480920221","Pc, Pc2.2, PeddleCheap version, NSA DanderSpiritz",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},236,"NSA DanderSpiritz Testing Guide - Trojan Generation and Testing","nsa-danderspiritz-testing-guide-trojan-generation-and-testing","Step-by-step guide to NSA DanderSpiritz Trojan testing, covering generation, classification, and troubleshooting for security analysis.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DanderSpritz is a GUI-based remote control tool from the NSA, built on the FuzzBunch framework, and can be launched by executing Start.jar\u003C\u002Fp>\u003Cp>During actual testing, due to the lack of documentation, many issues were encountered, and some details are worth in-depth study\u003C\u002Fp>\u003Cp>Therefore, this article aims to help answer questions, share testing insights, and analyze defense strategies based on the characteristics of the trojan\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Reasons and solutions for not receiving echo when executing pc_prep\u003C\u002Fli>\u003Cli>Differences between Pc and Pc2.2\u003C\u002Fli>\u003Cli>The meaning and usage of level3 and level4 trojans\u003C\u002Fli>\u003Cli>Differences among various types of trojans\u003C\u002Fli>\u003Cli>Methods for exploiting DLL trojans\u003C\u002Fli>\u003Cli>Windows single log deletion feature\u003C\u002Fli>\u003Cli>Trojan removal methodology\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Practical testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test environment:\u003C\u002Fp>\u003Cul>\u003Cli>Win7 x86\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Install the following tools:\u003C\u002Fp>\u003Cul>\u003Cli>python2.6\u003C\u002Fli>\u003Cli>pywin32\u003C\u002Fli>\u003Cli>jdk\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Download fuzzbunch\u003C\u002Fh3>\u003Cp>\u003Cstrong>Reference link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>I forked the public fuzzbunch project (https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch) and added some content, fixing a bug. Specific details will be introduced later\u003C\u002Fp>\u003Ch3>2. Run Start.jar directly\u003C\u002Fh3>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015593194_0_b26f72d23e.jpeg\">\u003C\u002Fp>\u003Cp>Set the startup parameters, the Log Directory must be set to a fixed format: c:\\logs\\xxx (xxx can be any name)\u003C\u002Fp>\u003Cp>Otherwise, an error will occur, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015597252_1_a5cd29bf69.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some online analysis articles suggest that you should first use fb.py to generate a log file, then point Start.jar to that directory. In fact, this is not necessary; as long as the path format is correct, it will work.\u003C\u002Fp>\u003Ch3>3. Execute pc_prep to configure the Trojan\u003C\u002Fh3>\u003Cp>Enter pc_prep to get the echo, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015599669_2_a834459fdb.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Many people find during testing that entering pc_prep does not produce an echo, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015603221_3_25d773cf2f.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The fuzzbunch project was downloaded from the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fx0rz\u002FEQGRP_Lost_in_Translation\u003C\u002Fp>\u003Cp>Missing files cause this error\u003C\u002Fp>\u003Cp>\u003Cstrong>Correct download location:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch\u003C\u002Fp>\u003Cp>However, after downloading, missing files still need to be supplemented for full normal use\u003C\u002Fp>\u003Cp>I forked the above project and completed the missing files; downloading from my GitHub will resolve the aforementioned issues, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>During previous testing, a buggy version was used; although pc_prep could not obtain echo, using pc2.2_prep could generate a Trojan\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015605706_4_8e528f00ab.jpeg\">\u003C\u002Fp>\u003Cp>But the Trojan cannot connect back\u003C\u002Fp>\u003Cp>\u003Cstrong>Possible reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>pc is a higher version compared to Pc2.2, and the lower version is no longer in use\u003C\u002Fp>\u003Cp>Check \\Resources\\Pc2.2\\Version.xml, which shows: PeddleCheap 2.2.0.2\u003C\u002Fp>\u003Cp>Indicates that the PeddleCheap version corresponding to Pc2.2 is 2.2.0.2\u003C\u002Fp>\u003Cp>Check \\Resources\\Pc\\Version.xml, which shows: PeddleCheap 2.3.0\u003C\u002Fp>\u003Cp>Indicates that the PeddleCheap version corresponding to Pc is 2.3.0\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PeddleCheap is used to operate communication with the Trojan and is displayed on the DanderSpritz main panel\u003C\u002Fp>\u003Ch3>4. Trojan Classification\u003C\u002Fh3>\u003Cp>The selectable Trojan types are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>1) - Standard TCP (i386-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>2) - HTTP Proxy (i386-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>3) - Standard TCP (i386-winnt Level3 exe)\u003C\u002Fli>\u003Cli>4) - HTTP Proxy (i386-winnt Level3 exe)\u003C\u002Fli>\u003Cli>5) - Standard TCP (x64-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>6) - HTTP Proxy (x64-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>7) - Standard TCP (x64-winnt Level3 exe)\u003C\u002Fli>\u003Cli>8) - HTTP Proxy (x64-winnt Level3 exe)\u003C\u002Fli>\u003Cli>9) - Standard TCP Generic (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>10) - HTTP Proxy Generic (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>11) - Standard TCP AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>12) - HTTP Proxy AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>13) - Standard TCP UtilityBurst-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>14) - HTTP Proxy UtilityBurst-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>15) - Standard TCP WinsockHelperApi-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>16) - HTTP Proxy WinsockHelperApi-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>17) - Standard TCP (i386-winnt Level4 exe)\u003C\u002Fli>\u003Cli>18) - HTTP Proxy (i386-winnt Level4 exe)\u003C\u002Fli>\u003Cli>19) - Standard TCP (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>20) - HTTP Proxy (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>21) - Standard TCP AppCompat-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>22) - HTTP Proxy AppCompat-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>23) - Standard TCP WinsockHelperApi-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>24) - HTTP Proxy WinsockHelperApi-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>25) - Standard TCP (x64-winnt Level4 exe)\u003C\u002Fli>\u003Cli>26) - HTTP Proxy (x64-winnt Level4 exe)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by platform:\u003C\u002Fp>\u003Cul>\u003Cli>x86\u003C\u002Fli>\u003Cli>x64\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by file format:\u003C\u002Fp>\u003Cul>\u003Cli>exe\u003C\u002Fli>\u003Cli>dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by communication protocol:\u003C\u002Fp>\u003Cul>\u003Cli>Standard TCP\u003C\u002Fli>\u003Cli>HTTP Proxy\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by function:\u003C\u002Fp>\u003Cul>\u003Cli>Standard\u003C\u002Fli>\u003Cli>AppCompat-enabled\u003C\u002Fli>\u003Cli>UtilityBurst-enabled\u003C\u002Fli>\u003Cli>WinsockHelperApi-enabled\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by Level:\u003C\u002Fp>\u003Cul>\u003Cli>Level3\u003C\u002Fli>\u003Cli>Level4\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Based on actual testing, Level represents the connection method\u003C\u002Fp>\u003Cp>Level3 indicates reverse connection, where the controller listens on a port and waits for the connection\u003C\u002Fp>\u003Cp>Level4 indicates forward connection, where the target host listens on a port and waits for the controller to actively connect\u003C\u002Fp>\u003Ch3>5. Trojan Testing\u003C\u002Fh3>\u003Cp>Select representative ones for testing\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong> Level3, select 3) - Standard TCP (i386-winnt Level3 exe)\u003C\u002Fp>\u003Cul>\u003Cli>Generate exe according to configuration (not detailed here, refer to other articles)\u003C\u002Fli>\u003Cli>DanderSpiritz controller selects PeddleCheap-Listen-Start Listening\u003C\u002Fli>\u003Cli>Execute exe directly on the target host\u003C\u002Fli>\u003Cli>Wait for callback connection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Operates similarly to a normal reverse shell Trojan\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Two files are generated under the log directory: PC_Level3_exe.base and PC_Level3_exe.configured\u003C\u002Fp>\u003Cp>PC_Level3_exe.base is the template file, sourced from \\\\Resources\\\\Pc\\\\Level3\\\\i386-winnt\\\\release\u003C\u002Fp>\u003Cp>PC_Level3_exe.configured is the file with configuration parameters added\u003C\u002Fp>\u003Cp>Both files have the same size but contain differences at specific locations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015607700_5_56cbd7ac1a.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong>Level3, select 6) - HTTP Proxy (x64-winnt Level3 sharedlib)\u003C\u002Fp>\u003Cp>Generate PC_Level3_http_dll.configured according to configuration (not detailed here, refer to other articles)\u003C\u002Fp>\u003Cp>Loading method:\u003C\u002Fp>\u003Cp>1. Load the DLL using DoublePulsar\u003C\u002Fp>\u003Cp>(Not detailed here, refer to other articles)\u003C\u002Fp>\u003Cp>2. Manually load DLL\u003C\u002Fp>\u003Cp>Use dumpbin to view the exported functions of the DLL, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015610145_6_4f147c72b7.jpeg\">\u003C\u002Fp>\u003Cp>The DLL export function name corresponding to ordinal 1 is rst32\u003C\u002Fp>\u003Cp>That is to say, we can try to load this DLL directly via rundll32\u003C\u002Fp>\u003Cp>The command line code is as follows:\u003C\u002Fp>\u003Cp>rundll32 PC_Level3_http_dll.configured,rst32\u003C\u002Fp>\u003Cp>The Trojan successfully connects back\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For HTTP protocol Trojans, remember to select HTTP when setting the listen protocol\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong>Level4, select 17) - Standard TCP (i386-winnt Level4 exe)\u003C\u002Fp>\u003Cp>Generate PC_Level4_exe.configured according to configuration (can use advanced mode to specify a fixed listening port)\u003C\u002Fp>\u003Cp>After starting the exe, execute netstat -ano to see that a fixed port is opened\u003C\u002Fp>\u003Cp>DanderSpiritz controller selects PeddleCheap-Connect, selects IP, and fills in the port corresponding to Level 4\u003C\u002Fp>\u003Cp>Forward Connection\u003C\u002Fp>\u003Cp>\u003Cstrong>(4)\u003C\u002Fstrong>Level4, select 9) - Standard TCP Generic (i386-winnt Level4 sharedlib)\u003C\u002Fp>\u003Cp>Generate PC_Level4_dll.configured as configured (can use advanced mode to specify a fixed listening port)\u003C\u002Fp>\u003Cp>View its exported functions, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015612566_7_1c39125d0e.jpeg\">\u003C\u002Fp>\u003Cp>That is to say, it does not support direct loading via rundll32\u003C\u002Fp>\u003Cp>\u003Cstrong>Guess:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Level4 Trojan needs to run continuously in the background; considering stealth, this feature is not supported\u003C\u002Fp>\u003Cp>Provide a test method for DLL loading: via APC injection\u003C\u002Fp>\u003Cp>As shown in the figure below, successfully loaded, listening port opened\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015614090_8_db559aae4a.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The injected program requires administrator privileges; otherwise, it will fail to open a listening port due to permission issues.\u003C\u002Fp>\u003Cp>Provide another DLL loading test method: via Application Compatibility Shims.\u003C\u002Fp>\u003Cp>Refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002F%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95%E4%B8%AD%E7%9A%84Application-Compatibility-Shims\u003C\u002Fp>\u003Cp>As shown below, successfully loaded, opening a listening port.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015615261_9_9547f64940.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(5)\u003C\u002Fstrong>Level4, select 11) - Standard TCP AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fp>\u003Cp>Based on the literal meaning, it is guessed to support Application Compatibility Shims.\u003C\u002Fp>\u003Cp>Compare the differences between Generic and AppCompat-enabled:\u003C\u002Fp>\u003Cp>Both are the same size; AppCompat-enabled just has an additional exported function GetHookAPIs.\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015616364_10_aa4a4cdf22.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Trojan Functionality\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After the Trojan connection is successful, information gathering automatically begins, returning various detailed information.\u003C\u002Fp>\u003Cp>A more user-friendly design is that it automatically asks the user whether to escalate privileges.\u003C\u002Fp>\u003Cp>After detecting a safe environment, it will ask the user whether to export hashes.\u003C\u002Fp>\u003Cp>Once information gathering is complete, entering 'help' will display supported operations.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The content obtained from 'help' is incomplete; entering 'aliases' will provide more operation command introductions.\u003C\u002Fp>\u003Cp>'help' + command provides a detailed introduction to the specific command's operation.\u003C\u002Fp>\u003Cp>For example, entering 'help eventlogedit' returns the display as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015617129_11_b1a4b1368a.jpeg\">\u003C\u002Fp>\u003Ch3>1. Log operation functions\u003C\u002Fh3>\u003Cp>The commands related to log operations are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>eventlogclear\u003C\u002Fli>\u003Cli>eventlogedit\u003C\u002Fli>\u003Cli>eventlogfilter\u003C\u002Fli>\u003Cli>eventlogquery\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>The specific functions are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogquery:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Statistics log list, query all log information, including time and count\u003C\u002Fp>\u003Cp>Can query log information of specified categories, including time and count, command as follows:\u003C\u002Fp>\u003Cp>eventlogquery -log Setup\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil.exe gli setup\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wevtutil.exe is included by default in the operating system\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogfilter:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>View log content of specified categories\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Cp>eventlogfilter -log Setup -num 19\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil qe \u002Ff:text setup\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogedit：\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete a single log entry\u003C\u002Fp>\u003Cp>You can delete the content of a single log entry with the following command:\u003C\u002Fp>\u003Cp>eventlogedit -log Setup -record 1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The record number can be obtained via eventlogfilter\u003C\u002Fp>\u003Cp>This command currently has no publicly available tool support\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogclear：\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete all content of this log type\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>eventlogclear -log Microsoft-Windows-Dhcpv6-Client\u002FAdmin\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil cl Microsoft-Windows-Dhcpv6-Client\u002FAdmin\u003C\u002Fp>\u003Ch2>0x04 Trojan Detection Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Trojan generation method of DanderSpritz is as follows:\u003C\u002Fp>\u003Cp>Template files are stored in folders \\Resources\\Pc\\Level3 and \\Resources\\Pc\\Level4, with fixed positions reserved for parameter configuration information; during actual generation, configuration information is written into the template files\u003C\u002Fp>\u003Cp>Currently, antivirus software has successfully identified and eliminated these template files. Additionally, the code for these template files is not open source, which also raises the barrier for malicious exploitation\u003C\u002Fp>\u003Cp>Recommendations for ordinary users:\u003C\u002Fp>\u003Cul>\u003Cli>Update system patches\u003C\u002Fli>\u003Cli>Update antivirus software virus databases\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This can prevent attacks from this tool\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article shares testing insights on DanderSpiritz, hoping to help everyone gain a better understanding of it in technical research. Some specific exploitation details and sections have been omitted to prevent misuse of the tool\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DanderSpritz is a GUI-based remote control tool from the NSA, built on the FuzzBunch framework, and can be launched by executing Start.jar\u003C\u002Fp>\u003Cp>During actual testing, due to the lack of documentation, many issues were encountered, and some details are worth in-depth study\u003C\u002Fp>\u003Cp>Therefore, this article aims to help answer questions, share testing insights, and analyze defense strategies based on the characteristics of the trojan\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Reasons and solutions for not receiving echo when executing pc_prep\u003C\u002Fli>\u003Cli>Differences between Pc and Pc2.2\u003C\u002Fli>\u003Cli>The meaning and usage of level3 and level4 trojans\u003C\u002Fli>\u003Cli>Differences among various types of trojans\u003C\u002Fli>\u003Cli>Methods for exploiting DLL trojans\u003C\u002Fli>\u003Cli>Windows single log deletion feature\u003C\u002Fli>\u003Cli>Trojan removal methodology\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Practical testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test environment:\u003C\u002Fp>\u003Cul>\u003Cli>Win7 x86\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Install the following tools:\u003C\u002Fp>\u003Cul>\u003Cli>python2.6\u003C\u002Fli>\u003Cli>pywin32\u003C\u002Fli>\u003Cli>jdk\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Download fuzzbunch\u003C\u002Fh3>\u003Cp>\u003Cstrong>Reference link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>I forked the public fuzzbunch project (https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch) and added some content, fixing a bug. Specific details will be introduced later\u003C\u002Fp>\u003Ch3>2. Run Start.jar directly\u003C\u002Fh3>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015593194_0_b26f72d23e-1.jpeg\">\u003C\u002Fp>\u003Cp>Set the startup parameters, the Log Directory must be set to a fixed format: c:\\logs\\xxx (xxx can be any name)\u003C\u002Fp>\u003Cp>Otherwise, an error will occur, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015597252_1_a5cd29bf69-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some online analysis articles suggest that you should first use fb.py to generate a log file, then point Start.jar to that directory. In fact, this is not necessary; as long as the path format is correct, it will work.\u003C\u002Fp>\u003Ch3>3. Execute pc_prep to configure the Trojan\u003C\u002Fh3>\u003Cp>Enter pc_prep to get the echo, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015599669_2_a834459fdb-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Many people find during testing that entering pc_prep does not produce an echo, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015603221_3_25d773cf2f-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The fuzzbunch project was downloaded from the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fx0rz\u002FEQGRP_Lost_in_Translation\u003C\u002Fp>\u003Cp>Missing files cause this error\u003C\u002Fp>\u003Cp>\u003Cstrong>Correct download location:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch\u003C\u002Fp>\u003Cp>However, after downloading, missing files still need to be supplemented for full normal use\u003C\u002Fp>\u003Cp>I forked the above project and completed the missing files; downloading from my GitHub will resolve the aforementioned issues, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>During previous testing, a buggy version was used; although pc_prep could not obtain echo, using pc2.2_prep could generate a Trojan\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015605706_4_8e528f00ab-1.jpeg\">\u003C\u002Fp>\u003Cp>But the Trojan cannot connect back\u003C\u002Fp>\u003Cp>\u003Cstrong>Possible reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>pc is a higher version compared to Pc2.2, and the lower version is no longer in use\u003C\u002Fp>\u003Cp>Check \\Resources\\Pc2.2\\Version.xml, which shows: PeddleCheap 2.2.0.2\u003C\u002Fp>\u003Cp>Indicates that the PeddleCheap version corresponding to Pc2.2 is 2.2.0.2\u003C\u002Fp>\u003Cp>Check \\Resources\\Pc\\Version.xml, which shows: PeddleCheap 2.3.0\u003C\u002Fp>\u003Cp>Indicates that the PeddleCheap version corresponding to Pc is 2.3.0\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PeddleCheap is used to operate communication with the Trojan and is displayed on the DanderSpritz main panel\u003C\u002Fp>\u003Ch3>4. Trojan Classification\u003C\u002Fh3>\u003Cp>The selectable Trojan types are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>1) - Standard TCP (i386-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>2) - HTTP Proxy (i386-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>3) - Standard TCP (i386-winnt Level3 exe)\u003C\u002Fli>\u003Cli>4) - HTTP Proxy (i386-winnt Level3 exe)\u003C\u002Fli>\u003Cli>5) - Standard TCP (x64-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>6) - HTTP Proxy (x64-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>7) - Standard TCP (x64-winnt Level3 exe)\u003C\u002Fli>\u003Cli>8) - HTTP Proxy (x64-winnt Level3 exe)\u003C\u002Fli>\u003Cli>9) - Standard TCP Generic (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>10) - HTTP Proxy Generic (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>11) - Standard TCP AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>12) - HTTP Proxy AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>13) - Standard TCP UtilityBurst-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>14) - HTTP Proxy UtilityBurst-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>15) - Standard TCP WinsockHelperApi-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>16) - HTTP Proxy WinsockHelperApi-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>17) - Standard TCP (i386-winnt Level4 exe)\u003C\u002Fli>\u003Cli>18) - HTTP Proxy (i386-winnt Level4 exe)\u003C\u002Fli>\u003Cli>19) - Standard TCP (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>20) - HTTP Proxy (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>21) - Standard TCP AppCompat-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>22) - HTTP Proxy AppCompat-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>23) - Standard TCP WinsockHelperApi-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>24) - HTTP Proxy WinsockHelperApi-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>25) - Standard TCP (x64-winnt Level4 exe)\u003C\u002Fli>\u003Cli>26) - HTTP Proxy (x64-winnt Level4 exe)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by platform:\u003C\u002Fp>\u003Cul>\u003Cli>x86\u003C\u002Fli>\u003Cli>x64\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by file format:\u003C\u002Fp>\u003Cul>\u003Cli>exe\u003C\u002Fli>\u003Cli>dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by communication protocol:\u003C\u002Fp>\u003Cul>\u003Cli>Standard TCP\u003C\u002Fli>\u003Cli>HTTP Proxy\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by function:\u003C\u002Fp>\u003Cul>\u003Cli>Standard\u003C\u002Fli>\u003Cli>AppCompat-enabled\u003C\u002Fli>\u003Cli>UtilityBurst-enabled\u003C\u002Fli>\u003Cli>WinsockHelperApi-enabled\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by Level:\u003C\u002Fp>\u003Cul>\u003Cli>Level3\u003C\u002Fli>\u003Cli>Level4\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Based on actual testing, Level represents the connection method\u003C\u002Fp>\u003Cp>Level3 indicates reverse connection, where the controller listens on a port and waits for the connection\u003C\u002Fp>\u003Cp>Level4 indicates forward connection, where the target host listens on a port and waits for the controller to actively connect\u003C\u002Fp>\u003Ch3>5. Trojan Testing\u003C\u002Fh3>\u003Cp>Select representative ones for testing\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong> Level3, select 3) - Standard TCP (i386-winnt Level3 exe)\u003C\u002Fp>\u003Cul>\u003Cli>Generate exe according to configuration (not detailed here, refer to other articles)\u003C\u002Fli>\u003Cli>DanderSpiritz controller selects PeddleCheap-Listen-Start Listening\u003C\u002Fli>\u003Cli>Execute exe directly on the target host\u003C\u002Fli>\u003Cli>Wait for callback connection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Operates similarly to a normal reverse shell Trojan\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Two files are generated under the log directory: PC_Level3_exe.base and PC_Level3_exe.configured\u003C\u002Fp>\u003Cp>PC_Level3_exe.base is the template file, sourced from \\\\Resources\\\\Pc\\\\Level3\\\\i386-winnt\\\\release\u003C\u002Fp>\u003Cp>PC_Level3_exe.configured is the file with configuration parameters added\u003C\u002Fp>\u003Cp>Both files have the same size but contain differences at specific locations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015607700_5_56cbd7ac1a-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong>Level3, select 6) - HTTP Proxy (x64-winnt Level3 sharedlib)\u003C\u002Fp>\u003Cp>Generate PC_Level3_http_dll.configured according to configuration (not detailed here, refer to other articles)\u003C\u002Fp>\u003Cp>Loading method:\u003C\u002Fp>\u003Cp>1. Load the DLL using DoublePulsar\u003C\u002Fp>\u003Cp>(Not detailed here, refer to other articles)\u003C\u002Fp>\u003Cp>2. Manually load DLL\u003C\u002Fp>\u003Cp>Use dumpbin to view the exported functions of the DLL, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015610145_6_4f147c72b7-1.jpeg\">\u003C\u002Fp>\u003Cp>The DLL export function name corresponding to ordinal 1 is rst32\u003C\u002Fp>\u003Cp>That is to say, we can try to load this DLL directly via rundll32\u003C\u002Fp>\u003Cp>The command line code is as follows:\u003C\u002Fp>\u003Cp>rundll32 PC_Level3_http_dll.configured,rst32\u003C\u002Fp>\u003Cp>The Trojan successfully connects back\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For HTTP protocol Trojans, remember to select HTTP when setting the listen protocol\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong>Level4, select 17) - Standard TCP (i386-winnt Level4 exe)\u003C\u002Fp>\u003Cp>Generate PC_Level4_exe.configured according to configuration (can use advanced mode to specify a fixed listening port)\u003C\u002Fp>\u003Cp>After starting the exe, execute netstat -ano to see that a fixed port is opened\u003C\u002Fp>\u003Cp>DanderSpiritz controller selects PeddleCheap-Connect, selects IP, and fills in the port corresponding to Level 4\u003C\u002Fp>\u003Cp>Forward Connection\u003C\u002Fp>\u003Cp>\u003Cstrong>(4)\u003C\u002Fstrong>Level4, select 9) - Standard TCP Generic (i386-winnt Level4 sharedlib)\u003C\u002Fp>\u003Cp>Generate PC_Level4_dll.configured as configured (can use advanced mode to specify a fixed listening port)\u003C\u002Fp>\u003Cp>View its exported functions, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015612566_7_1c39125d0e-1.jpeg\">\u003C\u002Fp>\u003Cp>That is to say, it does not support direct loading via rundll32\u003C\u002Fp>\u003Cp>\u003Cstrong>Guess:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Level4 Trojan needs to run continuously in the background; considering stealth, this feature is not supported\u003C\u002Fp>\u003Cp>Provide a test method for DLL loading: via APC injection\u003C\u002Fp>\u003Cp>As shown in the figure below, successfully loaded, listening port opened\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015614090_8_db559aae4a-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The injected program requires administrator privileges; otherwise, it will fail to open a listening port due to permission issues.\u003C\u002Fp>\u003Cp>Provide another DLL loading test method: via Application Compatibility Shims.\u003C\u002Fp>\u003Cp>Refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002F%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95%E4%B8%AD%E7%9A%84Application-Compatibility-Shims\u003C\u002Fp>\u003Cp>As shown below, successfully loaded, opening a listening port.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015615261_9_9547f64940-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(5)\u003C\u002Fstrong>Level4, select 11) - Standard TCP AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fp>\u003Cp>Based on the literal meaning, it is guessed to support Application Compatibility Shims.\u003C\u002Fp>\u003Cp>Compare the differences between Generic and AppCompat-enabled:\u003C\u002Fp>\u003Cp>Both are the same size; AppCompat-enabled just has an additional exported function GetHookAPIs.\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015616364_10_aa4a4cdf22-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Trojan Functionality\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After the Trojan connection is successful, information gathering automatically begins, returning various detailed information.\u003C\u002Fp>\u003Cp>A more user-friendly design is that it automatically asks the user whether to escalate privileges.\u003C\u002Fp>\u003Cp>After detecting a safe environment, it will ask the user whether to export hashes.\u003C\u002Fp>\u003Cp>Once information gathering is complete, entering 'help' will display supported operations.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The content obtained from 'help' is incomplete; entering 'aliases' will provide more operation command introductions.\u003C\u002Fp>\u003Cp>'help' + command provides a detailed introduction to the specific command's operation.\u003C\u002Fp>\u003Cp>For example, entering 'help eventlogedit' returns the display as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015617129_11_b1a4b1368a-1.jpeg\">\u003C\u002Fp>\u003Ch3>1. Log operation functions\u003C\u002Fh3>\u003Cp>The commands related to log operations are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>eventlogclear\u003C\u002Fli>\u003Cli>eventlogedit\u003C\u002Fli>\u003Cli>eventlogfilter\u003C\u002Fli>\u003Cli>eventlogquery\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>The specific functions are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogquery:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Statistics log list, query all log information, including time and count\u003C\u002Fp>\u003Cp>Can query log information of specified categories, including time and count, command as follows:\u003C\u002Fp>\u003Cp>eventlogquery -log Setup\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil.exe gli setup\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wevtutil.exe is included by default in the operating system\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogfilter:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>View log content of specified categories\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Cp>eventlogfilter -log Setup -num 19\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil qe \u002Ff:text setup\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogedit：\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete a single log entry\u003C\u002Fp>\u003Cp>You can delete the content of a single log entry with the following command:\u003C\u002Fp>\u003Cp>eventlogedit -log Setup -record 1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The record number can be obtained via eventlogfilter\u003C\u002Fp>\u003Cp>This command currently has no publicly available tool support\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogclear：\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete all content of this log type\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>eventlogclear -log Microsoft-Windows-Dhcpv6-Client\u002FAdmin\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil cl Microsoft-Windows-Dhcpv6-Client\u002FAdmin\u003C\u002Fp>\u003Ch2>0x04 Trojan Detection Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Trojan generation method of DanderSpritz is as follows:\u003C\u002Fp>\u003Cp>Template files are stored in folders \\Resources\\Pc\\Level3 and \\Resources\\Pc\\Level4, with fixed positions reserved for parameter configuration information; during actual generation, configuration information is written into the template files\u003C\u002Fp>\u003Cp>Currently, antivirus software has successfully identified and eliminated these template files. Additionally, the code for these template files is not open source, which also raises the barrier for malicious exploitation\u003C\u002Fp>\u003Cp>Recommendations for ordinary users:\u003C\u002Fp>\u003Cul>\u003Cli>Update system patches\u003C\u002Fli>\u003Cli>Update antivirus software virus databases\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This can prevent attacks from this tool\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article shares testing insights on DanderSpiritz, hoping to help everyone gain a better understanding of it in technical research. Some specific exploitation details and sections have been omitted to prevent misuse of the tool\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",504,"Onedaysec",7,"published","2026-02-02T07:25:19.986Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"NSA DanderSpiritz Trojan Testing Guide: Generation & Analysis","NSA DanderSpiritz, Trojan generation, FuzzBunch testing, pc_prep, Level3 Level4, Windows exploit",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],970,968,967,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.507Z","2026-07-23T16:02:20.859Z","draft","2026-07-23T16:15:49.830Z"]