Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
UNCLASSIFIED//LES
UNCLASSIFIED//LES Page19
7.1.13 SHUTTINGDOWNFULCRUMWITHFULCRUMSHUTDOWNASANEXE
1. CopytheFULCRUMSHUTDOWNexecutablebinary(fs32.exeorfs64.exe)tothedesiredlocation.
2. DoubleclicktheFULCRUMbinaryShuttingDownFulcrumwithFulcrumShutdownasaDLLwith
rundll32.exe
ShuttingDownFulcrumwithFulcrumShutdownasaDLLwithLoadLibrary
7.1.14 SHUTTINGDOWNFULCRUMWITHFULCRUMSHUTDOWNASADLLUSING
RUNDLL32.EXE
1. CopytheFULCRUMSHUTDOWNDLLbinary(fs32.dllorfs64.dll)tothedesiredlocation.
2. Openacommandprompt
3. ChangedirectoriestothelocationoftheFU LCRUMSHUTDOWNbinary.
4. Executethebinarybytypingthefollowingcommandintothecommandprompt:
rundll32.exefs32.dll,rundll_entry
7.1.15 SHUTTINGDOWNFULCRUMWITHFULCRUMSHUTDOWNASADLLUSINGLOADLIBRARY
1. CopytheFULCRUMSHUTDOWNDLLbinary(f32.dllorf64.dll)todesiredlocation.
2. Fromtheparentprocess,loadthebinaryusingLoadLibrary
3. Fromtheparentprocess,gettheparameterlessexportusingGetProcAddress(“func”).This
function’ssignatureis:voidfunc(void)
4. Fromtheparentprocess,callfunc
7.1.16 REMOVINGFULCRUM
1. ShutdownFULCRUMusingoneofthemethodsdescribedinSections7.1.13,7.1.14,or7.1.15
2. Deleteallofthefollowingfiles(notallwillbepresent):
a. f32.exe
b. f32.dll
c. fs32.exe
d. fs32.dll
e. f.cfg
f. f.log