Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
SECRET//NOFORN
________________________________________________________________________
Batch ID = 0x44444444
Command ID = 0x00000001
Command Type = execute
Command Status = 0x00000000
Error Code = 0x00000000
Persist = False
Stop On Error = False
Parent ID = test
Target ID = ABCD0086
Time = Mon Dec 21 22:09:02 2015 GMT
Filename = %systemroot%\system32\net.exe
Process Return Code = 0x00000000
<<STDIN/OUT/ERROR>>
New connections will be remembered.
Status Local Remote Network
-------------------------------------------------------------------------------
Unavailable Z: \\10.3.2.91\Athena Microsoft Windows Network
The command completed successfully.
9.4.8 (U) Uninstall
(S//NF) An example of the Parser output from a successful Uninstall command is shown below:
Batch ID = 0x99999999
Command ID = 0x00000000
Command Type = uninstall
Command Status = 0x00000000
Error Code = 0x00000000
Persist = False
Stop On Error = False
Parent ID = test
Target ID = ABCD0086
Time = Mon Dec 21 23:50:00 2015 GMT
9.5 (S//NF) Error Codes
(S//NF) The implant contains some defined error codes. It is possible to receive
standard windows error codes but most errors are defined at -1(0xFFFFFFFF). The
following table has the defined error codes that can be returned from the implant.
Table 10 - (U) Error Codes
Error Description
0
Success
0xA0000001
Invalid PE Header
0xA0000002
Initialization Failure – target DLL
0xA0000003
Teardown Failure – target DLL
0xA0000004
Relocation Failure – target DLL
0xA0000005
DLL Name Allocation Failure
0xA0000006
Forwarder Entry Allocation Failure
0xA0000007
Forwarder Buffer Overflow
0xA0000008
Duplicate Entry
0xA0000101
Timeout
SECRET//NOFORN 41