Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

OFFLINE INSTALLER:
???? METHOD FOR Win7+ ?????? – console or windows view???
Find all volume hard drives
Find windows directories – assume windows\system32\kernel32.dll is off the root
Determine x86/x64 – \windows\system32\kernel32.dll (32bit or 64bit) from PE
Searching C:
Searching D:
Update options:
1) C:\windows\system32 (x64)
2) C:\win\system32 (x86)
3) D:\windows\system32 (x86)
4) Quit
Select instance to update: 1
Update completed successfully
Update failed: (0x12345678)
------------------------------------
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache]
"ImagePath"="%SystemRoot%\\system32\\svchost.exe -k netsvcs"
"Start"=dword:00000002
"Type"=dword:00000020
"ObjectName"="LocalSystem"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters]
????? set this to the correct path ?????
"extension"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,\
00,6e,00,73,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost]
????? add dnscache to the following: (this one is the tough one) ????
"netsvcs" = ... dnscache\0 ...
copy target_x??.dat -> data file
copy target_x??.dll -> target file

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh