Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

UNCLASSIFIED//FOUO
Dyn_config can only be written
Athena_Package_Close(); - called by uninstaller
Offline
* Option 1: update actual registry / files (problem is ACLs not updated and uninstall
may fail)
Option 2: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\!Installer.exe
(requires registry change)
Option 3: overload a service dll that is always running?
* Option 4: set a schedule –
c:\windows\system32\tasks\microsoft\windows\xxx\xmlfile
(no registry change maybe)
Option 5: boot exec – write native api exe – this may actually need to be signed
(requires registry change)
Option 6: app init?
(requires registry change)
Virtual Disk Development Kit (VDDK) from VMWare
vmware-mount Z: a.vmdk /v:1 (mount volume to drive K:)
vmware-mount Z: /d /f (dismount volume)
Live Server CD Ubuntu – autorun our command line tool – no desktop / no login
MENU:
1 \dev\sda1 – Hard Disk 1 (use hex 1..F – to get 15 max
partitions)
2 \dev\sda2 – Rescue Disk
X Exit to Shell
S Shutdown
Enter selection: 1
Processing \dev\sda1 – Hard Disk 1
Completed Successfully
{rerun menu}
Documentation must contain Instructions for building USB image (perhaps python
script)
Offline Update:
1) Mount volume
2) File System: copy {drive}\windows\system32\dnsclnt.dll
a. {Windows} – duplicate security from dnsrslvr
b. Update create\modify\last update dates
3) Registry: replace “dnsrslvr.dll” -> “dnsclnt.dll” - is this enough
a. (maybe) ensure the service is autorun / no triggers?
4) Dismount volume
Use Bart PE with Windows Server 2003 for Windows offline
UNCLASSIFIED//FOUO

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh