Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

Pg. 07
Boot PersistenceBoot PersistenceBoot
Persistence
<PORT>443</PORT>
</BEACON>
<INSTALL>
<ORIGINAL_FILE_NAME>%SystemRoot
%\System32\dnsext.dll</ORIGINAL_FILE_NAME>
<DATA_FILE_NAME>%SystemRoot
%\system32\codeintegrity\dns.cache</DATA_FILE_NAME>
<RESTART_SERVICE>1</RESTART_SERVICE>
<TARGET_FILE_NAME>%SystemRoot
%\System32\Microsoft\Crypto\DNS\dnsclext.dll</TARGET_FILE_NAME>
</INSTALL>
</ATHENA>
18. Wizard Output
Builder Tool
Generating client RSA key pair
Generating server RSA key pair
Athena Wizard:
This wizard will guide you through the input options for the Athena tool.
Press enter to accept default value.
Source - Name (string)
default:[20150921_07_35_14_5700]
new value:
Target - Parent ID (hex)
default:[7D98CC58]
new value:
Target - Child ID (optional hex) - 0=auto generate
default:[0]
new value:
Target - dynamic data config type (none,file,registry)
default:[none]
new value:
Beacon - Interval in seconds (number)
default:[86400]
new value:

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh