Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
replacement binaries were used. It should still say that the output file was written and
everything worked OK. The receipt file will list all 20 binaries.
(S//NF) The following are known/potential issues that may arise while using Pandemic:
(S//NF) Target paths with folder names will not match correctly (replacement will
not occur). This is a known issue that has been difficult to fix because certain
systems/network configurations will not have issues with folder names, but other
systems/networks will. If it makes sense for a particular CONOP, only use the
file name in the -t option. Otherwise, use as few folders in the path as possible
when targeting a file for replacement.
(S//NF) If the remote user goes to copy the targeted PE on the file server to their
local machine, and the remote user has a file with the same name as the targeted
PE in the destination folder, Windows will ask the user if they wish to replace the
file or cancel the copy operation. The issue is the Windows alert box will report
that the new file's size being the size of the targeted PE, not the replacement PE.
For example: The targeted file is Pexplorer.exe, size 4.5 MB. The
replacement file is NOTEPAD.exe, size 67 KB. If the remote user copies
down pexplorer.exe to a local folder with that same file name, Windows will
ask the user if they wish to overwrite/cancel the copy. When it does this, it
will say that the size of the remote copy is 4.5 MB. However, after the
operation is complete, the user will have only downloaded the replacement PE
file of size 500 KB.
(S//NF) If the target file server is running in a VM, the host attempts to drag and
drop a folder into the file server VM, and the folder being copied into the file
server VM has the targeted path, then VMWare will throw an error. This is likely
due to how Windows is classifying VM drag and drop operations on the guest,
SECRET//NOFORN
7
Illustration 1: (S//NF) The same file is copied twice from the remote file
share to the user's local disk. As you can see, the file size Windows reports
is vastl
y d
ifferent, even if the user onl
y ge
ts the smaller re
p
lacement file

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh