addtaskscheduler.c 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403
  1. #include <stdio.h>
  2. #include <windows.h>
  3. #include <taskschd.h>
  4. #include <combaseapi.h>
  5. #include "addtaskscheduler.h"
  6. #include "beacon.h"
  7. HRESULT SetOneTimeTask(HRESULT hr, ITriggerCollection* pTriggerCollection, wchar_t* startTime, wchar_t* repeatTask) {
  8. IID IIDITimeTrigger = {0xb45747e0, 0xeba7, 0x4276, {0x9f, 0x29, 0x85, 0xc5, 0xbb, 0x30, 0x00, 0x06}};
  9. ITrigger* pTrigger = NULL;
  10. hr = pTriggerCollection->lpVtbl->Create(pTriggerCollection, TASK_TRIGGER_TIME, &pTrigger);
  11. if (SUCCEEDED(hr)) {
  12. ITimeTrigger* pTimeTrigger = NULL;
  13. hr = pTrigger->lpVtbl->QueryInterface(pTrigger, &IIDITimeTrigger, (void**)&pTimeTrigger);
  14. if (SUCCEEDED(hr)) {
  15. BSTR startTimeBstr = OLEAUT32$SysAllocString(startTime);
  16. pTimeTrigger->lpVtbl->put_StartBoundary(pTimeTrigger, startTimeBstr);
  17. IRepetitionPattern* pRepetitionPattern = NULL;
  18. hr = pTimeTrigger->lpVtbl->get_Repetition(pTimeTrigger, &pRepetitionPattern);
  19. if (SUCCEEDED(hr)) {
  20. BSTR repeatTaskBstr = OLEAUT32$SysAllocString(repeatTask);
  21. BSTR durationBstr = OLEAUT32$SysAllocString(L""); // Indefinite duration
  22. pRepetitionPattern->lpVtbl->put_Interval(pRepetitionPattern, repeatTaskBstr);
  23. pRepetitionPattern->lpVtbl->put_Duration(pRepetitionPattern, durationBstr);
  24. pRepetitionPattern->lpVtbl->Release(pRepetitionPattern);
  25. OLEAUT32$SysFreeString(repeatTaskBstr);
  26. OLEAUT32$SysFreeString(durationBstr);
  27. }
  28. pTimeTrigger->lpVtbl->put_Repetition(pTimeTrigger, pRepetitionPattern);
  29. OLEAUT32$SysFreeString(startTimeBstr);
  30. pTimeTrigger->lpVtbl->Release(pTimeTrigger);
  31. }
  32. pTrigger->lpVtbl->Release(pTrigger);
  33. }
  34. pTriggerCollection->lpVtbl->Release(pTriggerCollection);
  35. return hr;
  36. }
  37. HRESULT SetDailyTask(HRESULT hr, ITriggerCollection* pTriggerCollection, wchar_t* startTime, wchar_t* expireTime, int daysInterval, wchar_t* delay) {
  38. IID IIDIDailyTrigger = {0x126c5cd8, 0xb288, 0x41d5, {0x8d, 0xbf, 0xe4, 0x91, 0x44, 0x6a, 0xdc, 0x5c}};
  39. ITrigger* pTrigger = NULL;
  40. hr = pTriggerCollection->lpVtbl->Create(pTriggerCollection, TASK_TRIGGER_DAILY, &pTrigger);
  41. if (SUCCEEDED(hr)) {
  42. IDailyTrigger* pDailyTrigger = NULL;
  43. hr = pTrigger->lpVtbl->QueryInterface(pTrigger, &IIDIDailyTrigger, (void**)&pDailyTrigger);
  44. if (SUCCEEDED(hr)) {
  45. BSTR startTimeBstr = OLEAUT32$SysAllocString(startTime);
  46. BSTR expireTimeBstr = OLEAUT32$SysAllocString(expireTime);
  47. BSTR delayBstr = OLEAUT32$SysAllocString(delay);
  48. pDailyTrigger->lpVtbl->put_StartBoundary(pDailyTrigger, startTimeBstr);
  49. pDailyTrigger->lpVtbl->put_EndBoundary(pDailyTrigger, expireTimeBstr);
  50. pDailyTrigger->lpVtbl->put_DaysInterval(pDailyTrigger, daysInterval);
  51. pDailyTrigger->lpVtbl->put_RandomDelay(pDailyTrigger, delayBstr);
  52. pDailyTrigger->lpVtbl->Release(pDailyTrigger);
  53. OLEAUT32$SysFreeString(startTimeBstr);
  54. OLEAUT32$SysFreeString(expireTimeBstr);
  55. OLEAUT32$SysFreeString(delayBstr);
  56. }
  57. pTrigger->lpVtbl->Release(pTrigger);
  58. }
  59. pTriggerCollection->lpVtbl->Release(pTriggerCollection);
  60. return hr;
  61. }
  62. HRESULT SetLogonTask(HRESULT hr, ITriggerCollection* pTriggerCollection, wchar_t* userID) {
  63. IID IIDILogonTrigger = {0x72dade38, 0xfae4, 0x4b3e, {0xba, 0xf4, 0x5d, 0x00, 0x9a, 0xf0, 0x2b, 0x1c}};
  64. ITrigger* pTrigger = NULL;
  65. hr = pTriggerCollection->lpVtbl->Create(pTriggerCollection, TASK_TRIGGER_LOGON, &pTrigger);
  66. if (SUCCEEDED(hr)) {
  67. ILogonTrigger* pLogonTrigger = NULL;
  68. hr = pTrigger->lpVtbl->QueryInterface(pTrigger, &IIDILogonTrigger, (void**)&pLogonTrigger);
  69. if (SUCCEEDED(hr)) {
  70. BSTR userIDBstr = OLEAUT32$SysAllocString(userID);
  71. pLogonTrigger->lpVtbl->put_UserId(pLogonTrigger, userIDBstr);
  72. pLogonTrigger->lpVtbl->Release(pLogonTrigger);
  73. OLEAUT32$SysFreeString(userIDBstr);
  74. }
  75. pTrigger->lpVtbl->Release(pTrigger);
  76. }
  77. pTriggerCollection->lpVtbl->Release(pTriggerCollection);
  78. return hr;
  79. }
  80. HRESULT SetStartUpTask(HRESULT hr, ITriggerCollection* pTriggerCollection, wchar_t* delay) {
  81. IID IIDIBootTrigger = {0x2a9c35da, 0xd357, 0x41f4, {0xbb, 0xc1, 0x20, 0x7a, 0xc1, 0xb1, 0xf3, 0xcb}};
  82. ITrigger* pTrigger = NULL;
  83. hr = pTriggerCollection->lpVtbl->Create(pTriggerCollection, TASK_TRIGGER_BOOT, &pTrigger);
  84. if (SUCCEEDED(hr)) {
  85. IBootTrigger* pBootTrigger = NULL;
  86. hr = pTrigger->lpVtbl->QueryInterface(pTrigger, &IIDIBootTrigger, (void**)&pBootTrigger);
  87. if (SUCCEEDED(hr)) {
  88. BSTR delayBstr = OLEAUT32$SysAllocString(delay);
  89. pBootTrigger->lpVtbl->put_Delay(pBootTrigger, delayBstr);
  90. pBootTrigger->lpVtbl->Release(pBootTrigger);
  91. OLEAUT32$SysFreeString(delayBstr);
  92. }
  93. pTrigger->lpVtbl->Release(pTrigger);
  94. }
  95. pTriggerCollection->lpVtbl->Release(pTriggerCollection);
  96. return hr;
  97. }
  98. HRESULT SetLockTask(HRESULT hr, ITriggerCollection* pTriggerCollection, wchar_t* userID, wchar_t* delay) {
  99. IID IIDISessionStateChangeTrigger = {0x754da71b, 0x4385, 0x4475, {0x9d, 0xd9, 0x59, 0x82, 0x94, 0xfa, 0x36, 0x41}};
  100. ITrigger* pTrigger = NULL;
  101. hr = pTriggerCollection->lpVtbl->Create(pTriggerCollection, TASK_TRIGGER_SESSION_STATE_CHANGE, &pTrigger);
  102. if (SUCCEEDED(hr)) {
  103. ISessionStateChangeTrigger* pSessionStateChangeTrigger = NULL;
  104. hr = pTrigger->lpVtbl->QueryInterface(pTrigger, &IIDISessionStateChangeTrigger, (void**)&pSessionStateChangeTrigger);
  105. if (SUCCEEDED(hr)) {
  106. BSTR userIDBstr = OLEAUT32$SysAllocString(userID);
  107. BSTR delayBstr = OLEAUT32$SysAllocString(delay);
  108. pSessionStateChangeTrigger->lpVtbl->put_StateChange(pSessionStateChangeTrigger, TASK_SESSION_LOCK);
  109. pSessionStateChangeTrigger->lpVtbl->put_UserId(pSessionStateChangeTrigger, userIDBstr);
  110. pSessionStateChangeTrigger->lpVtbl->put_Delay(pSessionStateChangeTrigger, delayBstr);
  111. OLEAUT32$SysFreeString(userIDBstr);
  112. OLEAUT32$SysFreeString(delayBstr);
  113. pSessionStateChangeTrigger->lpVtbl->Release(pSessionStateChangeTrigger);
  114. }
  115. pTrigger->lpVtbl->Release(pTrigger);
  116. }
  117. pTriggerCollection->lpVtbl->Release(pTriggerCollection);
  118. return hr;
  119. }
  120. HRESULT SetUnlockTask(HRESULT hr, ITriggerCollection* pTriggerCollection, wchar_t* userID, wchar_t* delay) {
  121. IID IIDISessionStateChangeTrigger = {0x754da71b, 0x4385, 0x4475, {0x9d, 0xd9, 0x59, 0x82, 0x94, 0xfa, 0x36, 0x41}};
  122. ITrigger* pTrigger = NULL;
  123. hr = pTriggerCollection->lpVtbl->Create(pTriggerCollection, TASK_TRIGGER_SESSION_STATE_CHANGE, &pTrigger);
  124. if (SUCCEEDED(hr)) {
  125. ISessionStateChangeTrigger* pSessionStateChangeTrigger = NULL;
  126. hr = pTrigger->lpVtbl->QueryInterface(pTrigger, &IIDISessionStateChangeTrigger, (void**)&pSessionStateChangeTrigger);
  127. if (SUCCEEDED(hr)) {
  128. BSTR userIDBstr = OLEAUT32$SysAllocString(userID);
  129. BSTR delayBstr = OLEAUT32$SysAllocString(delay);
  130. pSessionStateChangeTrigger->lpVtbl->put_StateChange(pSessionStateChangeTrigger, TASK_SESSION_UNLOCK);
  131. pSessionStateChangeTrigger->lpVtbl->put_UserId(pSessionStateChangeTrigger, userIDBstr);
  132. pSessionStateChangeTrigger->lpVtbl->put_Delay(pSessionStateChangeTrigger, delayBstr);
  133. OLEAUT32$SysFreeString(userIDBstr);
  134. OLEAUT32$SysFreeString(delayBstr);
  135. pSessionStateChangeTrigger->lpVtbl->Release(pSessionStateChangeTrigger);
  136. }
  137. pTrigger->lpVtbl->Release(pTrigger);
  138. }
  139. pTriggerCollection->lpVtbl->Release(pTriggerCollection);
  140. return hr;
  141. }
  142. BOOL CreateScheduledTask(char* triggerType, wchar_t* taskName, wchar_t * host, wchar_t* programPath, wchar_t* programArguments, wchar_t* startTime, wchar_t* expireTime, int daysInterval, wchar_t* delay, wchar_t* userID, wchar_t* repeatTask) {
  143. BOOL actionResult = FALSE;
  144. HRESULT hr = S_OK;
  145. hr = OLE32$CoInitializeEx(NULL, COINIT_MULTITHREADED);
  146. if (FAILED(hr)) return actionResult;
  147. IID CTaskScheduler = {0x0f87369f, 0xa4e5, 0x4cfc, {0xbd,0x3e,0x73,0xe6,0x15,0x45,0x72,0xdd}};
  148. IID IIDITaskService = {0x2faba4c7, 0x4da9, 0x4013, {0x96, 0x97, 0x20, 0xcc, 0x3f, 0xd4, 0x0f, 0x85}};
  149. ITaskService *pTaskService = NULL;
  150. hr = OLE32$CoCreateInstance(&CTaskScheduler, NULL, CLSCTX_INPROC_SERVER, &IIDITaskService, (void**)&pTaskService);
  151. if (FAILED(hr)) {
  152. //MSVCRT$printf("Failed to create ITaskService: %x\n", hr); //DEBUG
  153. return actionResult;
  154. }
  155. VARIANT Vhost;
  156. VARIANT VNull;
  157. OLEAUT32$VariantInit(&Vhost);
  158. OLEAUT32$VariantInit(&VNull);
  159. Vhost.vt = VT_BSTR;
  160. Vhost.bstrVal = OLEAUT32$SysAllocString(host);
  161. hr = pTaskService->lpVtbl->Connect(pTaskService, Vhost, VNull, VNull, VNull);
  162. if (FAILED(hr)) {
  163. //MSVCRT$printf("ITaskService::Connect failed: %x\n", hr); //DEBUG
  164. goto cleanup;
  165. }
  166. ITaskFolder* pTaskFolder = NULL;
  167. BSTR folderPathBstr = OLEAUT32$SysAllocString(L"\\");
  168. hr = pTaskService->lpVtbl->GetFolder(pTaskService, folderPathBstr, &pTaskFolder);
  169. if (FAILED(hr)) {
  170. //MSVCRT$printf("ITaskService::GetFolder failed: %x\n", hr); //DEBUG
  171. goto cleanup;
  172. }
  173. OLEAUT32$SysFreeString(folderPathBstr);
  174. ITaskDefinition* pTaskDefinition = NULL;
  175. hr = pTaskService->lpVtbl->NewTask(pTaskService, 0, &pTaskDefinition);
  176. if (FAILED(hr)) {
  177. goto cleanup;
  178. }
  179. IPrincipal* pPrincipal = NULL;
  180. hr = pTaskDefinition->lpVtbl->get_Principal(pTaskDefinition, &pPrincipal);
  181. if (SUCCEEDED(hr)) {
  182. pPrincipal->lpVtbl->put_LogonType(pPrincipal, TASK_LOGON_INTERACTIVE_TOKEN);
  183. pPrincipal->lpVtbl->Release(pPrincipal);
  184. }
  185. ITriggerCollection* pTriggerCollection = NULL;
  186. hr = pTaskDefinition->lpVtbl->get_Triggers(pTaskDefinition, &pTriggerCollection);
  187. if (FAILED(hr)) {
  188. //MSVCRT$printf("ITaskDefinition::get_Triggers failed: %x\n", hr); //DEBUG
  189. goto cleanup;
  190. }
  191. //trigger options
  192. if (MSVCRT$strcmp(triggerType, "onetime") == 0) {
  193. hr = SetOneTimeTask(hr, pTriggerCollection, startTime, repeatTask);
  194. } else if (MSVCRT$strcmp(triggerType, "daily") == 0) {
  195. hr = SetDailyTask(hr, pTriggerCollection, startTime, expireTime, daysInterval, delay);
  196. } else if (MSVCRT$strcmp(triggerType, "logon") == 0) {
  197. hr = SetLogonTask(hr, pTriggerCollection, userID);
  198. } else if (MSVCRT$strcmp(triggerType, "startup") == 0) {
  199. hr = SetStartUpTask(hr, pTriggerCollection, delay);
  200. } else if (MSVCRT$strcmp(triggerType, "lock") == 0) {
  201. hr = SetLockTask(hr, pTriggerCollection, userID, delay);
  202. } else if (MSVCRT$strcmp(triggerType, "unlock") == 0) {
  203. hr = SetUnlockTask(hr, pTriggerCollection, userID, delay);
  204. }
  205. else {
  206. //MSVCRT$printf("[-] [%ls] is not a supported trigger type\n", triggerType); //DEBUG
  207. goto cleanup;
  208. }
  209. IActionCollection* pActionCollection = NULL;
  210. hr = pTaskDefinition->lpVtbl->get_Actions(pTaskDefinition, &pActionCollection);
  211. if (FAILED(hr)) {
  212. goto cleanup;
  213. }
  214. IAction* pAction = NULL;
  215. hr = pActionCollection->lpVtbl->Create(pActionCollection, TASK_ACTION_EXEC, &pAction);
  216. if (FAILED(hr)) {
  217. goto cleanup;
  218. }
  219. IID IIDIExecAction = {0x4c3d624d, 0xfd6b, 0x49a3, {0xb9, 0xb7, 0x09, 0xcb, 0x3c, 0xd3, 0xf0, 0x47}};
  220. IExecAction* pExecAction = NULL;
  221. hr = pAction->lpVtbl->QueryInterface(pAction, &IIDIExecAction, (void**)&pExecAction);
  222. if (FAILED(hr)) {
  223. goto cleanup;
  224. }
  225. BSTR programPathBstr = OLEAUT32$SysAllocString(programPath);
  226. hr = pExecAction->lpVtbl->put_Path(pExecAction, programPathBstr);
  227. if (FAILED(hr)) {
  228. goto cleanup;
  229. }
  230. OLEAUT32$SysFreeString(programPathBstr);
  231. BSTR programArgumentsBstr = OLEAUT32$SysAllocString(programArguments);
  232. hr = pExecAction->lpVtbl->put_Arguments(pExecAction, programArgumentsBstr);
  233. if (FAILED(hr)) {
  234. goto cleanup;
  235. }
  236. OLEAUT32$SysFreeString(programArgumentsBstr);
  237. pExecAction->lpVtbl->Release(pExecAction);
  238. pAction->lpVtbl->Release(pAction);
  239. IRegisteredTask* pRegisteredTask = NULL;
  240. hr = pTaskFolder->lpVtbl->RegisterTaskDefinition(pTaskFolder, taskName, pTaskDefinition, TASK_CREATE_OR_UPDATE, VNull, VNull, TASK_LOGON_INTERACTIVE_TOKEN, VNull, &pRegisteredTask);
  241. if (FAILED(hr)) {
  242. BeaconPrintf(CALLBACK_ERROR, "Failed to register the scheduled task with error code: %x\n", hr);
  243. } else {
  244. BeaconPrintf(CALLBACK_OUTPUT, "[+] Scheduled task '%ls' created successfully!\n", taskName);
  245. actionResult = TRUE;
  246. }
  247. cleanup:
  248. if (pRegisteredTask) {
  249. pRegisteredTask->lpVtbl->Release(pRegisteredTask);
  250. }
  251. if (pActionCollection) {
  252. pActionCollection->lpVtbl->Release(pActionCollection);
  253. }
  254. if (pTaskDefinition) {
  255. pTaskDefinition->lpVtbl->Release(pTaskDefinition);
  256. }
  257. if (pTaskFolder) {
  258. pTaskFolder->lpVtbl->Release(pTaskFolder);
  259. }
  260. if (pTaskService) {
  261. pTaskService->lpVtbl->Release(pTaskService);
  262. }
  263. OLEAUT32$VariantClear(&Vhost);
  264. OLEAUT32$VariantClear(&VNull);
  265. OLE32$CoUninitialize();
  266. return actionResult;
  267. }
  268. int go(char *args, int len) {
  269. BOOL res = NULL;
  270. datap parser;
  271. WCHAR *taskName;
  272. WCHAR *hostName = L"";
  273. WCHAR *programPath;
  274. WCHAR *programArguments = L"";
  275. CHAR *triggerType; //onetime, daily, logon , startup, lock, unlock
  276. WCHAR *startTime;
  277. WCHAR *expireTime = L"";
  278. int daysInterval = 0;
  279. WCHAR *delay = L"";
  280. WCHAR *userID = L"";
  281. WCHAR *repeatTask = L"";
  282. BeaconDataParse(&parser, args, len);
  283. taskName = BeaconDataExtract(&parser, NULL);
  284. hostName = BeaconDataExtract(&parser, NULL);
  285. programPath = BeaconDataExtract(&parser, NULL);
  286. programArguments = BeaconDataExtract(&parser, NULL);
  287. triggerType = BeaconDataExtract(&parser, NULL);
  288. if (MSVCRT$strcmp(triggerType, "onetime") == 0) {
  289. startTime = BeaconDataExtract(&parser, NULL);
  290. repeatTask = BeaconDataExtract(&parser, NULL);
  291. res = CreateScheduledTask(triggerType, taskName, hostName, programPath, programArguments, startTime, expireTime, daysInterval, delay, userID, repeatTask);
  292. }
  293. else if (MSVCRT$strcmp(triggerType, "daily") == 0) {
  294. startTime = BeaconDataExtract(&parser, NULL);
  295. expireTime = BeaconDataExtract(&parser, NULL);
  296. daysInterval = BeaconDataInt(&parser);
  297. delay = BeaconDataExtract(&parser, NULL);
  298. res = CreateScheduledTask(triggerType, taskName, hostName, programPath, programArguments, startTime, expireTime, daysInterval, delay, userID, repeatTask);
  299. }
  300. else if (MSVCRT$strcmp(triggerType, "logon") == 0) {
  301. userID = BeaconDataExtract(&parser, NULL);
  302. res = CreateScheduledTask(triggerType, taskName, hostName, programPath, programArguments, startTime, expireTime, daysInterval, delay, userID, repeatTask);
  303. }
  304. else if (MSVCRT$strcmp(triggerType, "startup") == 0) {
  305. delay = BeaconDataExtract(&parser, NULL);
  306. res = CreateScheduledTask(triggerType, taskName, hostName, programPath, programArguments, startTime, expireTime, daysInterval, delay, userID, repeatTask);
  307. }
  308. else if (MSVCRT$strcmp(triggerType, "lock") == 0) {
  309. userID = BeaconDataExtract(&parser, NULL);
  310. delay = BeaconDataExtract(&parser, NULL);
  311. res = CreateScheduledTask(triggerType, taskName, hostName, programPath, programArguments, startTime, expireTime, daysInterval, delay, userID, repeatTask);
  312. }
  313. else if (MSVCRT$strcmp(triggerType, "unlock") == 0) {
  314. userID = BeaconDataExtract(&parser, NULL);
  315. delay = BeaconDataExtract(&parser, NULL);
  316. res = CreateScheduledTask(triggerType, taskName, hostName, programPath, programArguments, startTime, expireTime, daysInterval, delay, userID, repeatTask);
  317. }
  318. else {
  319. BeaconPrintf(CALLBACK_ERROR, "Specified triggerType is not supported.\n");
  320. }
  321. return 0;
  322. }