Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
________________________________________________________________________
BIN
├───offline - linux offline files
functions.sh
linux.sh
reged.static
target_x64.ini
target_x86.ini
├───x64 - 64 bit implant components
command.axe
engine.axe
host.dll
install.dll
offline.exe
ram_only.dll
uninstall.axe
└───x86 - 32 bit implant components
command.axe
engine.axe
host.dll
install.dll
offline.exe
ram_only.dll
uninstall.axe
Figure 10 - (S//NF) System Binary Path
6.2.2 (U) System Import XML
(S//NF) This argument provides the location of the existing receipt file to be used for
configuration information. This option is used to input specific information into this build (e.g.
use this option to create an exact copy of an existing build).
6.2.3 (U) System Export Path
(S//NF) This argument provides the output directory path to store the target files. By default, the
.\builder_output path is the location for the output. A sub-directory called RECEIPTS is
created in this directory to contain all receipts created by this installation. This simplifies parsing
by having all receipts in a single location. When creating implants for a group of targets, the
parent name will be in the output directory (e.g. .\builder_output\test). If a build is generated for
a specific child, the child name will be incorporated into the name of the output directory (e.g.
.\builder_output\test_ABCD0086).
6.2.4 (U) Debug
(S//NF) This argument allows debugging information to be included in the output directory.
When this option is selected, an additional debug directory is included in the output. This
contains all intermediary files required by the Builder and can be used to support debugging.
6.3 (U) Wizard
(S//NF) The following (Figure 11) shows an example of using the wizard option of the Builder in
order to configure and build an implant. Select the default value by using ENTER key.
$ python.exe builder.py
Builder
Generating client RSA key pair
Generating server RSA key pair
Athena Wizard:
This wizard will guide you through the input options for the Athena tool.
Press enter to accept default value.
SECRET//NOFORN 13

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh