Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//ORCON//NOFORN
18.6.7 FAF Load
The load FAF command tells the target Implant to load the provided FAF DLL into
memory and execute it using the Fire and Forget V2 specification.
XML Example
<ICELoad>
<FeatureSet>faf</FeatureSet>
<Ordinal>1</Ordinal>
<CmdLine>append</CmdLine>
<FileSize>1m</FileSize>
<FAFDLLPath>c:\test\faf-test.dll</FAFDLLPath>
</ICELoad>
Field Definitions
Feature Set
The feature set field describes the feature set to use when loading and executing
the DLL. For Fire and Forget V2 DLLs this value will always be “faf”.
Ordinal
The ordinal field describes the ordinal function that will be executed once the
DLL has been loaded into memory. For Fire and Forget V2 DLLs this value will
always be 1.
Command Line
The command line field describes the command line arguments to pass to the
ordinal call on execution.
In the example above, the command line value “append” will be passed to the
ordinal.
File Size
The file size field describes the size of the DLL file that is going to be uploaded to
the target.
In the example above, the DLL file is one megabyte.
DLL Path
The DLL path field describes the local full path to the DLL file that is going to be
uploaded to the target.
In the example above, the local file “c:\test\faf-test.dll” will be uploaded to the
target.
183
SECRET//ORCON//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh