Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
________________________________________________________________________
8.5 (U) Output
(S//NF) The Tasker produces a binary file (no extension) and a text file (.txt). The binary file
will be copied to the Listening Post for downloading to the target. The text file is an
unencrypted textual reference of the commands within the specific batch file which can be used
as an historical reference or as an input to the Tasker to generate a duplicate batch.
8.5.1 (U) Binary-Based Output File
(S//NF) Sample output: __128_test_ABCD0064_12345678
(S//NF) The binary file is an encrypted block that can only be decrypted by the target. The
Listening Post cannot decode the content of this file. To allow the Listening Post some
knowledge about the file’s content and priority, the filename is encoded as described below:
Table 9 – (U) Command File Encoding
Filename
Component
Value Description
Position 0 _
+
The underbar shows that this is a standard batch file (e.g. __128).
The plus sign tells the server that this file is persistent and the server will not delete it after
processing (e.g. +_128).
Priority number This number represents the priority. 0-highest and 255-lowest (NOTE: 128-default)
Parent string This string represents the target parent ID. This name must match the parent ID reference
in the directory.
Child hex This string representation of hex is the target child ID. This name must match the child
ID reference in the directory.
Batch hex This string representation of hex is the batch ID. This is a random number which prevents
duplicate batches.
8.5.2 (U) Text-Based Output File
(S//NF) Sample output: __128_test_ABCD0064_12345678_script.txt
(S//NF) The text file contains the textual representation of the command. This content is stored
in the text file as UTF-8. The file name is the same as the corresponding binary file with the
_script.txt extension.
# ATHENA SCRIPT
execute pre=0 post=0 task=0 filename="ipconfig"
arguments="/all"
9. (U) Parser
(S//NF) Some general usage comments are presented below:
Any default value (e.g., [bracketed text]) is either randomly generated or a suggestion, and
their use on multiple operations without modification may present a signature that could
identify the presence of Athena in a network.
SECRET//NOFORN 36

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh