Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
________________________________________________________________________
9KQOrFATxmyIt0kXbWXQ1yNmRKnybXAWHleAzCj0qrKf7CtdRSPOB7WetwTH5ork
7FYwjPTWEr+hsDZmKXOuU3XvlCByNbKe7M2CilseCcqpzhmQDghH3lIAp+BTkwYL
zD5Z5IakrmXE+NmRafPUUZnEhmi1yNuinPeTlrULBbh3X6W9mvJQcOSFZ4HkaE5W
nFVG1GYYAISzBqgk4aALrupQGzshdQgvEcfOeEZuYUxRaqeQGvZS7z/cDQ/10Z7J
3NN4NMOj7VGMNj/tcW5ScEba5ZbZwnPZWiDChHTblOpkbnLKhb/o1898RFaEryg=
-----END RSA PRIVATE KEY-----
</PRIVATE_KEY>
</SERVER_KEY>
<SOURCE>
<MASK>4D324A24C2EB88548A760390ED9DEAB6</MASK>
</SOURCE>
<TARGET>
<CHILD_ID>0xABCD0064</CHILD_ID>
<DYN_CONFIG_TYPE>0</DYN_CONFIG_TYPE>
<PARENT_ID>test</PARENT_ID>
</TARGET>
</ATHENA>
Figure 12 - (S//NF) Example Receipt File - XML
6.5.1 (U) Output Target Files
(S//NF) The Builder outputs files that are used to manage the target implant. Figure 13 shows
the listing of the files included in a standard target configuration.
<SYSTEM_EXPORT_PATH>
builder.log - output log from the Builder
test_ABCD0064_receipt.xml - target receipt file
├───installer - NOD spec installation files
installer_x64.dll - 64 bit installation dll
installer_x86.dll - 32 bit installation dll
├───offline
├───linux - linux offline installation files
functions.sh
linux.sh
reged.static - registry editor
target_x64.dat
target_x64.dll
target_x64.ini
target_x86.dat
target_x86.dll
target_x86.ini
└───windows - windows offline installation files
offline_x64.exe - installer for 64 bit recovery OS
offline_x86.exe - installer for 32 bit recovery OS
target.ini - configuration for specific implant
target_x64.dat
target_x64.dll
target_x86.dat
target_x86.dll
└───ram_only - NOD spec ram-only version of Athena
ram_only_x64.dll - 64 bit run dll
ram_only_x86.dll - 32 bit run dll
Figure 13 - (S//NF) Builder Output Files
Note
(S//NF) Athena's Builder has a --debug option that will build
all the intermediate files and place them in a debug directory
in the Builder output directory.
SECRET//NOFORN 22

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh