[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feDWEJVl5fnHmBpxvkR8k8lHuIissbBAtumv4mbcavB8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},967,"Why does executing `pc_prep` in DanderSpritz not return any echo, and how can it be fixed?","The missing echo when running `pc_prep` is typically due to downloading an incomplete version of the FuzzBunch framework from unverified sources like [x0rz\u002FEQGRP_Lost_in_Translation](https:\u002F\u002Fgithub.com\u002Fx0rz\u002FEQGRP_Lost_in_Translation). The correct repository is [fuzzbunch\u002Ffuzzbunch](https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch), but even that may require supplementing missing files. A tested fix is to use a forked version that completes these files, as described in the [NSA DanderSpiritz Testing Guide - Trojan Generation and Testing](\u002Fnews\u002Fnsa-danderspiritz-testing-guide-trojan-generation-and-testing). Alternatively, ensure the log directory follows the required format `c:\\logs\\xxx`.","\u003Cp>The missing echo when running `pc_prep` is typically due to downloading an incomplete version of the FuzzBunch framework from unverified sources like [x0rz\u002FEQGRP_Lost_in_Translation](https:\u002F\u002Fgithub.com\u002Fx0rz\u002FEQGRP_Lost_in_Translation). The correct repository is [fuzzbunch\u002Ffuzzbunch](https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch), but even that may require supplementing missing files. A tested fix is to use a forked version that completes these files, as described in the [NSA DanderSpiritz Testing Guide - Trojan Generation and Testing](\u002Fnews\u002Fnsa-danderspiritz-testing-guide-trojan-generation-and-testing). Alternatively, ensure the log directory follows the required format `c:\\logs\\xxx`.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fnsa-danderspiritz-testing-guide-trojan-generation-and-testing\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-does-executing-pc_prep-in-danderspritz-not-return-any-echo-and-how-can-it-be-1777480920090","pc_prep, DanderSpritz, trojan generation, echo missing, fuzzbunch",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},236,"NSA DanderSpiritz Testing Guide - Trojan Generation and Testing","nsa-danderspiritz-testing-guide-trojan-generation-and-testing","Step-by-step guide to NSA DanderSpiritz Trojan testing, covering generation, classification, and troubleshooting for security analysis.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DanderSpritz is a GUI-based remote control tool from the NSA, built on the FuzzBunch framework, and can be launched by executing Start.jar\u003C\u002Fp>\u003Cp>During actual testing, due to the lack of documentation, many issues were encountered, and some details are worth in-depth study\u003C\u002Fp>\u003Cp>Therefore, this article aims to help answer questions, share testing insights, and analyze defense strategies based on the characteristics of the trojan\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Reasons and solutions for not receiving echo when executing pc_prep\u003C\u002Fli>\u003Cli>Differences between Pc and Pc2.2\u003C\u002Fli>\u003Cli>The meaning and usage of level3 and level4 trojans\u003C\u002Fli>\u003Cli>Differences among various types of trojans\u003C\u002Fli>\u003Cli>Methods for exploiting DLL trojans\u003C\u002Fli>\u003Cli>Windows single log deletion feature\u003C\u002Fli>\u003Cli>Trojan removal methodology\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Practical testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test environment:\u003C\u002Fp>\u003Cul>\u003Cli>Win7 x86\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Install the following tools:\u003C\u002Fp>\u003Cul>\u003Cli>python2.6\u003C\u002Fli>\u003Cli>pywin32\u003C\u002Fli>\u003Cli>jdk\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Download fuzzbunch\u003C\u002Fh3>\u003Cp>\u003Cstrong>Reference link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>I forked the public fuzzbunch project (https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch) and added some content, fixing a bug. Specific details will be introduced later\u003C\u002Fp>\u003Ch3>2. Run Start.jar directly\u003C\u002Fh3>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015593194_0_b26f72d23e.jpeg\">\u003C\u002Fp>\u003Cp>Set the startup parameters, the Log Directory must be set to a fixed format: c:\\logs\\xxx (xxx can be any name)\u003C\u002Fp>\u003Cp>Otherwise, an error will occur, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015597252_1_a5cd29bf69.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some online analysis articles suggest that you should first use fb.py to generate a log file, then point Start.jar to that directory. In fact, this is not necessary; as long as the path format is correct, it will work.\u003C\u002Fp>\u003Ch3>3. Execute pc_prep to configure the Trojan\u003C\u002Fh3>\u003Cp>Enter pc_prep to get the echo, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015599669_2_a834459fdb.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Many people find during testing that entering pc_prep does not produce an echo, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015603221_3_25d773cf2f.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The fuzzbunch project was downloaded from the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fx0rz\u002FEQGRP_Lost_in_Translation\u003C\u002Fp>\u003Cp>Missing files cause this error\u003C\u002Fp>\u003Cp>\u003Cstrong>Correct download location:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch\u003C\u002Fp>\u003Cp>However, after downloading, missing files still need to be supplemented for full normal use\u003C\u002Fp>\u003Cp>I forked the above project and completed the missing files; downloading from my GitHub will resolve the aforementioned issues, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>During previous testing, a buggy version was used; although pc_prep could not obtain echo, using pc2.2_prep could generate a Trojan\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015605706_4_8e528f00ab.jpeg\">\u003C\u002Fp>\u003Cp>But the Trojan cannot connect back\u003C\u002Fp>\u003Cp>\u003Cstrong>Possible reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>pc is a higher version compared to Pc2.2, and the lower version is no longer in use\u003C\u002Fp>\u003Cp>Check \\Resources\\Pc2.2\\Version.xml, which shows: PeddleCheap 2.2.0.2\u003C\u002Fp>\u003Cp>Indicates that the PeddleCheap version corresponding to Pc2.2 is 2.2.0.2\u003C\u002Fp>\u003Cp>Check \\Resources\\Pc\\Version.xml, which shows: PeddleCheap 2.3.0\u003C\u002Fp>\u003Cp>Indicates that the PeddleCheap version corresponding to Pc is 2.3.0\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PeddleCheap is used to operate communication with the Trojan and is displayed on the DanderSpritz main panel\u003C\u002Fp>\u003Ch3>4. Trojan Classification\u003C\u002Fh3>\u003Cp>The selectable Trojan types are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>1) - Standard TCP (i386-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>2) - HTTP Proxy (i386-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>3) - Standard TCP (i386-winnt Level3 exe)\u003C\u002Fli>\u003Cli>4) - HTTP Proxy (i386-winnt Level3 exe)\u003C\u002Fli>\u003Cli>5) - Standard TCP (x64-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>6) - HTTP Proxy (x64-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>7) - Standard TCP (x64-winnt Level3 exe)\u003C\u002Fli>\u003Cli>8) - HTTP Proxy (x64-winnt Level3 exe)\u003C\u002Fli>\u003Cli>9) - Standard TCP Generic (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>10) - HTTP Proxy Generic (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>11) - Standard TCP AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>12) - HTTP Proxy AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>13) - Standard TCP UtilityBurst-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>14) - HTTP Proxy UtilityBurst-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>15) - Standard TCP WinsockHelperApi-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>16) - HTTP Proxy WinsockHelperApi-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>17) - Standard TCP (i386-winnt Level4 exe)\u003C\u002Fli>\u003Cli>18) - HTTP Proxy (i386-winnt Level4 exe)\u003C\u002Fli>\u003Cli>19) - Standard TCP (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>20) - HTTP Proxy (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>21) - Standard TCP AppCompat-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>22) - HTTP Proxy AppCompat-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>23) - Standard TCP WinsockHelperApi-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>24) - HTTP Proxy WinsockHelperApi-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>25) - Standard TCP (x64-winnt Level4 exe)\u003C\u002Fli>\u003Cli>26) - HTTP Proxy (x64-winnt Level4 exe)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by platform:\u003C\u002Fp>\u003Cul>\u003Cli>x86\u003C\u002Fli>\u003Cli>x64\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by file format:\u003C\u002Fp>\u003Cul>\u003Cli>exe\u003C\u002Fli>\u003Cli>dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by communication protocol:\u003C\u002Fp>\u003Cul>\u003Cli>Standard TCP\u003C\u002Fli>\u003Cli>HTTP Proxy\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by function:\u003C\u002Fp>\u003Cul>\u003Cli>Standard\u003C\u002Fli>\u003Cli>AppCompat-enabled\u003C\u002Fli>\u003Cli>UtilityBurst-enabled\u003C\u002Fli>\u003Cli>WinsockHelperApi-enabled\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by Level:\u003C\u002Fp>\u003Cul>\u003Cli>Level3\u003C\u002Fli>\u003Cli>Level4\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Based on actual testing, Level represents the connection method\u003C\u002Fp>\u003Cp>Level3 indicates reverse connection, where the controller listens on a port and waits for the connection\u003C\u002Fp>\u003Cp>Level4 indicates forward connection, where the target host listens on a port and waits for the controller to actively connect\u003C\u002Fp>\u003Ch3>5. Trojan Testing\u003C\u002Fh3>\u003Cp>Select representative ones for testing\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong> Level3, select 3) - Standard TCP (i386-winnt Level3 exe)\u003C\u002Fp>\u003Cul>\u003Cli>Generate exe according to configuration (not detailed here, refer to other articles)\u003C\u002Fli>\u003Cli>DanderSpiritz controller selects PeddleCheap-Listen-Start Listening\u003C\u002Fli>\u003Cli>Execute exe directly on the target host\u003C\u002Fli>\u003Cli>Wait for callback connection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Operates similarly to a normal reverse shell Trojan\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Two files are generated under the log directory: PC_Level3_exe.base and PC_Level3_exe.configured\u003C\u002Fp>\u003Cp>PC_Level3_exe.base is the template file, sourced from \\\\Resources\\\\Pc\\\\Level3\\\\i386-winnt\\\\release\u003C\u002Fp>\u003Cp>PC_Level3_exe.configured is the file with configuration parameters added\u003C\u002Fp>\u003Cp>Both files have the same size but contain differences at specific locations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015607700_5_56cbd7ac1a.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong>Level3, select 6) - HTTP Proxy (x64-winnt Level3 sharedlib)\u003C\u002Fp>\u003Cp>Generate PC_Level3_http_dll.configured according to configuration (not detailed here, refer to other articles)\u003C\u002Fp>\u003Cp>Loading method:\u003C\u002Fp>\u003Cp>1. Load the DLL using DoublePulsar\u003C\u002Fp>\u003Cp>(Not detailed here, refer to other articles)\u003C\u002Fp>\u003Cp>2. Manually load DLL\u003C\u002Fp>\u003Cp>Use dumpbin to view the exported functions of the DLL, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015610145_6_4f147c72b7.jpeg\">\u003C\u002Fp>\u003Cp>The DLL export function name corresponding to ordinal 1 is rst32\u003C\u002Fp>\u003Cp>That is to say, we can try to load this DLL directly via rundll32\u003C\u002Fp>\u003Cp>The command line code is as follows:\u003C\u002Fp>\u003Cp>rundll32 PC_Level3_http_dll.configured,rst32\u003C\u002Fp>\u003Cp>The Trojan successfully connects back\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For HTTP protocol Trojans, remember to select HTTP when setting the listen protocol\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong>Level4, select 17) - Standard TCP (i386-winnt Level4 exe)\u003C\u002Fp>\u003Cp>Generate PC_Level4_exe.configured according to configuration (can use advanced mode to specify a fixed listening port)\u003C\u002Fp>\u003Cp>After starting the exe, execute netstat -ano to see that a fixed port is opened\u003C\u002Fp>\u003Cp>DanderSpiritz controller selects PeddleCheap-Connect, selects IP, and fills in the port corresponding to Level 4\u003C\u002Fp>\u003Cp>Forward Connection\u003C\u002Fp>\u003Cp>\u003Cstrong>(4)\u003C\u002Fstrong>Level4, select 9) - Standard TCP Generic (i386-winnt Level4 sharedlib)\u003C\u002Fp>\u003Cp>Generate PC_Level4_dll.configured as configured (can use advanced mode to specify a fixed listening port)\u003C\u002Fp>\u003Cp>View its exported functions, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015612566_7_1c39125d0e.jpeg\">\u003C\u002Fp>\u003Cp>That is to say, it does not support direct loading via rundll32\u003C\u002Fp>\u003Cp>\u003Cstrong>Guess:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Level4 Trojan needs to run continuously in the background; considering stealth, this feature is not supported\u003C\u002Fp>\u003Cp>Provide a test method for DLL loading: via APC injection\u003C\u002Fp>\u003Cp>As shown in the figure below, successfully loaded, listening port opened\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015614090_8_db559aae4a.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The injected program requires administrator privileges; otherwise, it will fail to open a listening port due to permission issues.\u003C\u002Fp>\u003Cp>Provide another DLL loading test method: via Application Compatibility Shims.\u003C\u002Fp>\u003Cp>Refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002F%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95%E4%B8%AD%E7%9A%84Application-Compatibility-Shims\u003C\u002Fp>\u003Cp>As shown below, successfully loaded, opening a listening port.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015615261_9_9547f64940.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(5)\u003C\u002Fstrong>Level4, select 11) - Standard TCP AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fp>\u003Cp>Based on the literal meaning, it is guessed to support Application Compatibility Shims.\u003C\u002Fp>\u003Cp>Compare the differences between Generic and AppCompat-enabled:\u003C\u002Fp>\u003Cp>Both are the same size; AppCompat-enabled just has an additional exported function GetHookAPIs.\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015616364_10_aa4a4cdf22.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Trojan Functionality\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After the Trojan connection is successful, information gathering automatically begins, returning various detailed information.\u003C\u002Fp>\u003Cp>A more user-friendly design is that it automatically asks the user whether to escalate privileges.\u003C\u002Fp>\u003Cp>After detecting a safe environment, it will ask the user whether to export hashes.\u003C\u002Fp>\u003Cp>Once information gathering is complete, entering 'help' will display supported operations.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The content obtained from 'help' is incomplete; entering 'aliases' will provide more operation command introductions.\u003C\u002Fp>\u003Cp>'help' + command provides a detailed introduction to the specific command's operation.\u003C\u002Fp>\u003Cp>For example, entering 'help eventlogedit' returns the display as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770015617129_11_b1a4b1368a.jpeg\">\u003C\u002Fp>\u003Ch3>1. Log operation functions\u003C\u002Fh3>\u003Cp>The commands related to log operations are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>eventlogclear\u003C\u002Fli>\u003Cli>eventlogedit\u003C\u002Fli>\u003Cli>eventlogfilter\u003C\u002Fli>\u003Cli>eventlogquery\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>The specific functions are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogquery:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Statistics log list, query all log information, including time and count\u003C\u002Fp>\u003Cp>Can query log information of specified categories, including time and count, command as follows:\u003C\u002Fp>\u003Cp>eventlogquery -log Setup\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil.exe gli setup\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wevtutil.exe is included by default in the operating system\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogfilter:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>View log content of specified categories\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Cp>eventlogfilter -log Setup -num 19\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil qe \u002Ff:text setup\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogedit：\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete a single log entry\u003C\u002Fp>\u003Cp>You can delete the content of a single log entry with the following command:\u003C\u002Fp>\u003Cp>eventlogedit -log Setup -record 1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The record number can be obtained via eventlogfilter\u003C\u002Fp>\u003Cp>This command currently has no publicly available tool support\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogclear：\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete all content of this log type\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>eventlogclear -log Microsoft-Windows-Dhcpv6-Client\u002FAdmin\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil cl Microsoft-Windows-Dhcpv6-Client\u002FAdmin\u003C\u002Fp>\u003Ch2>0x04 Trojan Detection Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Trojan generation method of DanderSpritz is as follows:\u003C\u002Fp>\u003Cp>Template files are stored in folders \\Resources\\Pc\\Level3 and \\Resources\\Pc\\Level4, with fixed positions reserved for parameter configuration information; during actual generation, configuration information is written into the template files\u003C\u002Fp>\u003Cp>Currently, antivirus software has successfully identified and eliminated these template files. Additionally, the code for these template files is not open source, which also raises the barrier for malicious exploitation\u003C\u002Fp>\u003Cp>Recommendations for ordinary users:\u003C\u002Fp>\u003Cul>\u003Cli>Update system patches\u003C\u002Fli>\u003Cli>Update antivirus software virus databases\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This can prevent attacks from this tool\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article shares testing insights on DanderSpiritz, hoping to help everyone gain a better understanding of it in technical research. Some specific exploitation details and sections have been omitted to prevent misuse of the tool\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>DanderSpritz is a GUI-based remote control tool from the NSA, built on the FuzzBunch framework, and can be launched by executing Start.jar\u003C\u002Fp>\u003Cp>During actual testing, due to the lack of documentation, many issues were encountered, and some details are worth in-depth study\u003C\u002Fp>\u003Cp>Therefore, this article aims to help answer questions, share testing insights, and analyze defense strategies based on the characteristics of the trojan\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Reasons and solutions for not receiving echo when executing pc_prep\u003C\u002Fli>\u003Cli>Differences between Pc and Pc2.2\u003C\u002Fli>\u003Cli>The meaning and usage of level3 and level4 trojans\u003C\u002Fli>\u003Cli>Differences among various types of trojans\u003C\u002Fli>\u003Cli>Methods for exploiting DLL trojans\u003C\u002Fli>\u003Cli>Windows single log deletion feature\u003C\u002Fli>\u003Cli>Trojan removal methodology\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Practical testing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Test environment:\u003C\u002Fp>\u003Cul>\u003Cli>Win7 x86\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Install the following tools:\u003C\u002Fp>\u003Cul>\u003Cli>python2.6\u003C\u002Fli>\u003Cli>pywin32\u003C\u002Fli>\u003Cli>jdk\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Download fuzzbunch\u003C\u002Fh3>\u003Cp>\u003Cstrong>Reference link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>I forked the public fuzzbunch project (https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch) and added some content, fixing a bug. Specific details will be introduced later\u003C\u002Fp>\u003Ch3>2. Run Start.jar directly\u003C\u002Fh3>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015593194_0_b26f72d23e-1.jpeg\">\u003C\u002Fp>\u003Cp>Set the startup parameters, the Log Directory must be set to a fixed format: c:\\logs\\xxx (xxx can be any name)\u003C\u002Fp>\u003Cp>Otherwise, an error will occur, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015597252_1_a5cd29bf69-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some online analysis articles suggest that you should first use fb.py to generate a log file, then point Start.jar to that directory. In fact, this is not necessary; as long as the path format is correct, it will work.\u003C\u002Fp>\u003Ch3>3. Execute pc_prep to configure the Trojan\u003C\u002Fh3>\u003Cp>Enter pc_prep to get the echo, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015599669_2_a834459fdb-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Many people find during testing that entering pc_prep does not produce an echo, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015603221_3_25d773cf2f-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The fuzzbunch project was downloaded from the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fx0rz\u002FEQGRP_Lost_in_Translation\u003C\u002Fp>\u003Cp>Missing files cause this error\u003C\u002Fp>\u003Cp>\u003Cstrong>Correct download location:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ffuzzbunch\u002Ffuzzbunch\u003C\u002Fp>\u003Cp>However, after downloading, missing files still need to be supplemented for full normal use\u003C\u002Fp>\u003Cp>I forked the above project and completed the missing files; downloading from my GitHub will resolve the aforementioned issues, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>During previous testing, a buggy version was used; although pc_prep could not obtain echo, using pc2.2_prep could generate a Trojan\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015605706_4_8e528f00ab-1.jpeg\">\u003C\u002Fp>\u003Cp>But the Trojan cannot connect back\u003C\u002Fp>\u003Cp>\u003Cstrong>Possible reason:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>pc is a higher version compared to Pc2.2, and the lower version is no longer in use\u003C\u002Fp>\u003Cp>Check \\Resources\\Pc2.2\\Version.xml, which shows: PeddleCheap 2.2.0.2\u003C\u002Fp>\u003Cp>Indicates that the PeddleCheap version corresponding to Pc2.2 is 2.2.0.2\u003C\u002Fp>\u003Cp>Check \\Resources\\Pc\\Version.xml, which shows: PeddleCheap 2.3.0\u003C\u002Fp>\u003Cp>Indicates that the PeddleCheap version corresponding to Pc is 2.3.0\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PeddleCheap is used to operate communication with the Trojan and is displayed on the DanderSpritz main panel\u003C\u002Fp>\u003Ch3>4. Trojan Classification\u003C\u002Fh3>\u003Cp>The selectable Trojan types are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>1) - Standard TCP (i386-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>2) - HTTP Proxy (i386-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>3) - Standard TCP (i386-winnt Level3 exe)\u003C\u002Fli>\u003Cli>4) - HTTP Proxy (i386-winnt Level3 exe)\u003C\u002Fli>\u003Cli>5) - Standard TCP (x64-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>6) - HTTP Proxy (x64-winnt Level3 sharedlib)\u003C\u002Fli>\u003Cli>7) - Standard TCP (x64-winnt Level3 exe)\u003C\u002Fli>\u003Cli>8) - HTTP Proxy (x64-winnt Level3 exe)\u003C\u002Fli>\u003Cli>9) - Standard TCP Generic (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>10) - HTTP Proxy Generic (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>11) - Standard TCP AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>12) - HTTP Proxy AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>13) - Standard TCP UtilityBurst-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>14) - HTTP Proxy UtilityBurst-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>15) - Standard TCP WinsockHelperApi-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>16) - HTTP Proxy WinsockHelperApi-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>17) - Standard TCP (i386-winnt Level4 exe)\u003C\u002Fli>\u003Cli>18) - HTTP Proxy (i386-winnt Level4 exe)\u003C\u002Fli>\u003Cli>19) - Standard TCP (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>20) - HTTP Proxy (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>21) - Standard TCP AppCompat-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>22) - HTTP Proxy AppCompat-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>23) - Standard TCP WinsockHelperApi-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>24) - HTTP Proxy WinsockHelperApi-enabled (x64-winnt Level4 sharedlib)\u003C\u002Fli>\u003Cli>25) - Standard TCP (x64-winnt Level4 exe)\u003C\u002Fli>\u003Cli>26) - HTTP Proxy (x64-winnt Level4 exe)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by platform:\u003C\u002Fp>\u003Cul>\u003Cli>x86\u003C\u002Fli>\u003Cli>x64\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by file format:\u003C\u002Fp>\u003Cul>\u003Cli>exe\u003C\u002Fli>\u003Cli>dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by communication protocol:\u003C\u002Fp>\u003Cul>\u003Cli>Standard TCP\u003C\u002Fli>\u003Cli>HTTP Proxy\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by function:\u003C\u002Fp>\u003Cul>\u003Cli>Standard\u003C\u002Fli>\u003Cli>AppCompat-enabled\u003C\u002Fli>\u003Cli>UtilityBurst-enabled\u003C\u002Fli>\u003Cli>WinsockHelperApi-enabled\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Distinguished by Level:\u003C\u002Fp>\u003Cul>\u003Cli>Level3\u003C\u002Fli>\u003Cli>Level4\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Based on actual testing, Level represents the connection method\u003C\u002Fp>\u003Cp>Level3 indicates reverse connection, where the controller listens on a port and waits for the connection\u003C\u002Fp>\u003Cp>Level4 indicates forward connection, where the target host listens on a port and waits for the controller to actively connect\u003C\u002Fp>\u003Ch3>5. Trojan Testing\u003C\u002Fh3>\u003Cp>Select representative ones for testing\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong> Level3, select 3) - Standard TCP (i386-winnt Level3 exe)\u003C\u002Fp>\u003Cul>\u003Cli>Generate exe according to configuration (not detailed here, refer to other articles)\u003C\u002Fli>\u003Cli>DanderSpiritz controller selects PeddleCheap-Listen-Start Listening\u003C\u002Fli>\u003Cli>Execute exe directly on the target host\u003C\u002Fli>\u003Cli>Wait for callback connection\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Operates similarly to a normal reverse shell Trojan\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Two files are generated under the log directory: PC_Level3_exe.base and PC_Level3_exe.configured\u003C\u002Fp>\u003Cp>PC_Level3_exe.base is the template file, sourced from \\\\Resources\\\\Pc\\\\Level3\\\\i386-winnt\\\\release\u003C\u002Fp>\u003Cp>PC_Level3_exe.configured is the file with configuration parameters added\u003C\u002Fp>\u003Cp>Both files have the same size but contain differences at specific locations, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015607700_5_56cbd7ac1a-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong>Level3, select 6) - HTTP Proxy (x64-winnt Level3 sharedlib)\u003C\u002Fp>\u003Cp>Generate PC_Level3_http_dll.configured according to configuration (not detailed here, refer to other articles)\u003C\u002Fp>\u003Cp>Loading method:\u003C\u002Fp>\u003Cp>1. Load the DLL using DoublePulsar\u003C\u002Fp>\u003Cp>(Not detailed here, refer to other articles)\u003C\u002Fp>\u003Cp>2. Manually load DLL\u003C\u002Fp>\u003Cp>Use dumpbin to view the exported functions of the DLL, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015610145_6_4f147c72b7-1.jpeg\">\u003C\u002Fp>\u003Cp>The DLL export function name corresponding to ordinal 1 is rst32\u003C\u002Fp>\u003Cp>That is to say, we can try to load this DLL directly via rundll32\u003C\u002Fp>\u003Cp>The command line code is as follows:\u003C\u002Fp>\u003Cp>rundll32 PC_Level3_http_dll.configured,rst32\u003C\u002Fp>\u003Cp>The Trojan successfully connects back\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For HTTP protocol Trojans, remember to select HTTP when setting the listen protocol\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong>Level4, select 17) - Standard TCP (i386-winnt Level4 exe)\u003C\u002Fp>\u003Cp>Generate PC_Level4_exe.configured according to configuration (can use advanced mode to specify a fixed listening port)\u003C\u002Fp>\u003Cp>After starting the exe, execute netstat -ano to see that a fixed port is opened\u003C\u002Fp>\u003Cp>DanderSpiritz controller selects PeddleCheap-Connect, selects IP, and fills in the port corresponding to Level 4\u003C\u002Fp>\u003Cp>Forward Connection\u003C\u002Fp>\u003Cp>\u003Cstrong>(4)\u003C\u002Fstrong>Level4, select 9) - Standard TCP Generic (i386-winnt Level4 sharedlib)\u003C\u002Fp>\u003Cp>Generate PC_Level4_dll.configured as configured (can use advanced mode to specify a fixed listening port)\u003C\u002Fp>\u003Cp>View its exported functions, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015612566_7_1c39125d0e-1.jpeg\">\u003C\u002Fp>\u003Cp>That is to say, it does not support direct loading via rundll32\u003C\u002Fp>\u003Cp>\u003Cstrong>Guess:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Level4 Trojan needs to run continuously in the background; considering stealth, this feature is not supported\u003C\u002Fp>\u003Cp>Provide a test method for DLL loading: via APC injection\u003C\u002Fp>\u003Cp>As shown in the figure below, successfully loaded, listening port opened\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015614090_8_db559aae4a-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Reference code:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The injected program requires administrator privileges; otherwise, it will fail to open a listening port due to permission issues.\u003C\u002Fp>\u003Cp>Provide another DLL loading test method: via Application Compatibility Shims.\u003C\u002Fp>\u003Cp>Refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002F%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95%E4%B8%AD%E7%9A%84Application-Compatibility-Shims\u003C\u002Fp>\u003Cp>As shown below, successfully loaded, opening a listening port.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015615261_9_9547f64940-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(5)\u003C\u002Fstrong>Level4, select 11) - Standard TCP AppCompat-enabled (i386-winnt Level4 sharedlib)\u003C\u002Fp>\u003Cp>Based on the literal meaning, it is guessed to support Application Compatibility Shims.\u003C\u002Fp>\u003Cp>Compare the differences between Generic and AppCompat-enabled:\u003C\u002Fp>\u003Cp>Both are the same size; AppCompat-enabled just has an additional exported function GetHookAPIs.\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015616364_10_aa4a4cdf22-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Trojan Functionality\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After the Trojan connection is successful, information gathering automatically begins, returning various detailed information.\u003C\u002Fp>\u003Cp>A more user-friendly design is that it automatically asks the user whether to escalate privileges.\u003C\u002Fp>\u003Cp>After detecting a safe environment, it will ask the user whether to export hashes.\u003C\u002Fp>\u003Cp>Once information gathering is complete, entering 'help' will display supported operations.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The content obtained from 'help' is incomplete; entering 'aliases' will provide more operation command introductions.\u003C\u002Fp>\u003Cp>'help' + command provides a detailed introduction to the specific command's operation.\u003C\u002Fp>\u003Cp>For example, entering 'help eventlogedit' returns the display as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770015617129_11_b1a4b1368a-1.jpeg\">\u003C\u002Fp>\u003Ch3>1. Log operation functions\u003C\u002Fh3>\u003Cp>The commands related to log operations are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>eventlogclear\u003C\u002Fli>\u003Cli>eventlogedit\u003C\u002Fli>\u003Cli>eventlogfilter\u003C\u002Fli>\u003Cli>eventlogquery\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>The specific functions are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogquery:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Statistics log list, query all log information, including time and count\u003C\u002Fp>\u003Cp>Can query log information of specified categories, including time and count, command as follows:\u003C\u002Fp>\u003Cp>eventlogquery -log Setup\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil.exe gli setup\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wevtutil.exe is included by default in the operating system\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogfilter:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>View log content of specified categories\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Cp>eventlogfilter -log Setup -num 19\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil qe \u002Ff:text setup\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogedit：\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete a single log entry\u003C\u002Fp>\u003Cp>You can delete the content of a single log entry with the following command:\u003C\u002Fp>\u003Cp>eventlogedit -log Setup -record 1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The record number can be obtained via eventlogfilter\u003C\u002Fp>\u003Cp>This command currently has no publicly available tool support\u003C\u002Fp>\u003Cp>\u003Cstrong>eventlogclear：\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete all content of this log type\u003C\u002Fp>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>eventlogclear -log Microsoft-Windows-Dhcpv6-Client\u002FAdmin\u003C\u002Fp>\u003Cp>This operation is equivalent to\u003C\u002Fp>\u003Cp>wevtutil cl Microsoft-Windows-Dhcpv6-Client\u002FAdmin\u003C\u002Fp>\u003Ch2>0x04 Trojan Detection Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Trojan generation method of DanderSpritz is as follows:\u003C\u002Fp>\u003Cp>Template files are stored in folders \\Resources\\Pc\\Level3 and \\Resources\\Pc\\Level4, with fixed positions reserved for parameter configuration information; during actual generation, configuration information is written into the template files\u003C\u002Fp>\u003Cp>Currently, antivirus software has successfully identified and eliminated these template files. Additionally, the code for these template files is not open source, which also raises the barrier for malicious exploitation\u003C\u002Fp>\u003Cp>Recommendations for ordinary users:\u003C\u002Fp>\u003Cul>\u003Cli>Update system patches\u003C\u002Fli>\u003Cli>Update antivirus software virus databases\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This can prevent attacks from this tool\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article shares testing insights on DanderSpiritz, hoping to help everyone gain a better understanding of it in technical research. Some specific exploitation details and sections have been omitted to prevent misuse of the tool\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",504,"Onedaysec",7,"published","2026-02-02T07:25:19.986Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"NSA DanderSpiritz Trojan Testing Guide: Generation & Analysis","NSA DanderSpiritz, Trojan generation, FuzzBunch testing, pc_prep, Level3 Level4, Windows exploit",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],970,969,968,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.507Z","2026-07-23T16:02:20.859Z","draft","2026-07-23T16:15:49.221Z"]