Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
________________________________________________________________________
Modify Time: Mon Dec 21 22:08:02 2015 GMT
Create Time: Mon Dec 21 22:08:02 2015 GMT
File Size: 18 bytes
Output Filename:
d:\Development\Athena\Tests\TestCommandEngine\parser_output\test\ABCD0086\responses\20
151221_17_10_01_0375_get.bin
9.4.2 (U) Put
(S//NF) An example of the Parser output from a successful Put command is shown below:
Batch ID = 0x22222222
Command ID = 0x00000000
Command Type = put
Command Status = 0x00000000
Error Code = 0x00000000
Persist = False
Stop On Error = False
Parent ID = test
Target ID = ABCD0086
Time = Mon Dec 21 22:08:52 2015 GMT
Filename = d:\Development\Athena\Tests\TestCommandEngine\win32\debug\put.txt
9.4.3 (U) Set
(S//NF) The SET command can return an error for the following reasons. The return code will
be ARESULT_DISK_ERROR(0xA0000104). The parser.py code has been changed to detect
this error code and change the output to “DATA NOT PERSISTED”. The dynamic data storage
will update the data in memory but will not be available at next reboot.
1) If the implant is running in ram-only mode, the attempt to write to disk will return an
error.
2) If the implant is configured with an invalid dyn_config file, the attempt to write to the
file will return an error.
Output: Error Code = DATA NOT PERSISTED
(S//NF) An example of the Parser output from a successful Set command is shown below:
Batch ID = 0x33333333
Command ID = 0x00000000
Command Type = set
Command Status = 0x00000000
Error Code = 0x00000000
Persist = False
Stop On Error = False
Parent ID = test
Target ID = ABCD0086
Time = Mon Dec 21 22:08:58 2015 GMT
Set Type = killfilepath
Argument = c:\temp\kill
SECRET//NOFORN 39

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh