Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
(S//NF) If the target file server is running in a VM, the host attempts to drag and
drop a folder into the file server VM, and the folder being copied into the file
server VM has the targeted path, then VMWare will throw an error. This is likely
due to how Windows is classifying VM drag and drop operations on the guest,
and Pandemic can't tell if it's a normal SMB operation or a weird VMWare
operation.
(S//NF) If a target user is running the replaced PE on their system through SMB
(direct execution without copying it down to their machine), and Pandemic is
uninstalled, this can cause process instability for the replacement PE. The
instability may not appear if the entire replacement PE is cached on the target
user's machine. Instability may not happen immediately if it does occur.
(S//NF) If the replacement PE file has a different icon than the target PE file, the
remote users may not see the correct icon all the time. The local Windows
machine tends to cache icons, and this icon caching can persist for some time (or
until reboot). The best work around is to ensure that if the target PE file has icon
information, the replacement PE file should then share that same icon
information.
(S//NF) There will be some memory leakage as a result of making 'safe' choices
vs. potentially destabilizing choices. Typical memory leakage size will be around
1 KB per run of Pandemic (of NonPagedPool). According to various sources,
Vista+ 64-bit systems cap NonPagedPool to 75% of RAM. So on a server with
64 GB of RAM, NonPagedPool is limited to 48 GB.
To limit leakage, run Pandemic with long death-timers. Avoid running
Pandemic many times using short death-timers. If this becomes an issue
(target server doesn't reboot often, operation requires many runs of Pandemic
on a short leash) then the developer can investigate ways of reducing the
memory impact
SECRET//NOFORN
7
Illustration 1: (S//NF) The same file is copied twice from the remote file
share to the user's local disk. As you can see, the file size Windows reports
is vastl
y d
ifferent
,
even if the user onl
y ge
ts the smaller re
p
lacement file

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh