Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//ORCON//NOFORN
ASSASSIN v1.3 USER GUIDE
June 2013
1OVERVIEW............................................................................................3
1.1CONCEPT OF OPERATIONS........................................................................................4
1.2SYSTEM COMPONENTS............................................................................................ 5
1.2.1IMPLANT EXECUTABLES.................................................................................................6
1.2.2DEPLOYMENT EXECUTABLES...........................................................................................7
1.2.3BUILDER.................................................................................................................... 8
1.2.4TASKER..................................................................................................................... 9
1.2.5POST PROCESSOR.....................................................................................................10
1.2.6COLLIDE HANDLERS...................................................................................................11
1.3SYSTEM REQUIREMENTS........................................................................................ 12
1.3.1PYTHON.................................................................................................................. 13
1.3.2COLLIDE.................................................................................................................. 14
2ASSASSIN IMPLANT.............................................................................15
2.1IMPLANT EXECUTABLE USAGE.................................................................................16
2.1.1IMPLANT DLL...........................................................................................................17
3RUNNING VIA DLLMAIN.......................................................................18
4RUNNING VIA GH1...............................................................................19
5RUNNING VIA RUNDLL32.....................................................................20
5.1.1IMPLANT SERVICE DLL...............................................................................................21
6RUNNING VIA RUNDLL32.....................................................................22
7RUNNING VIA SERVICEMAIN.................................................................23
7.1.1IMPLANT EXE...........................................................................................................24
7.1.2IMPLANT ICE DLL.....................................................................................................25
7.1.3IMPLANT PERNICIOUS ICE DLL.....................................................................................26
7.2IMPLANT IDENTIFICATION........................................................................................ 27
7.3BEACON............................................................................................................. 28
7.3.1BEACON TRANSACTION...............................................................................................29
7.3.2BEACON TIMING........................................................................................................30
7.3.3PROCESS CHECK.......................................................................................................31
7.4TASKING............................................................................................................. 32
7.4.1TASK INPUT.............................................................................................................33
7.4.2TASK EXECUTION......................................................................................................34
7.4.3TASK OUTPUT..........................................................................................................35
7.5COMMUNICATION..................................................................................................36
7.5.1TRANSPORTS............................................................................................................37
7.5.2PUSH DIRECTORIES................................................................................................... 38
7.5.3UPLOAD QUEUE........................................................................................................39
CL BY: 2355679
CL REASON: Section
1.5(c),(e)
DECL ON: 20351003
DRV FRM: COL 6-03
SECRET//ORCON//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh