Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
________________________________________________________________________
Action / Help Text Notes
28
Uninstall - Kill File Path - full file path
on target (string)
default:[]
new value:
The default kill file name that is used to force a
self-delete when the file is present on the target
system.
File Name
29
Install - Target File Name (string)
default:[%SystemRoot%\System32\
Microsoft\Crypto\RAS\
iprcache.dll]
new value:
The default file path used for the host target file.
File Name
30
Install - Data File Name (string)
default:[%SystemRoot%\System32\
CodeIntegrity\ras.cache]
new value:
The default file path used for the data file on the
target system.
File Name
31
Install - Restart service with Service
Control Manager (SCM) (no,yes)
default:[yes]
new value:
The option to restart the service after install.
Otherwise, the tool will be installed and will not
start until next reboot or restart of the host service.
Yes/No
6.5 (U) Output
(U) The Builder produces multiple output components. All receipts will be placed in the receipts
folder. Each build will be in its own directory and contain all target specific files.
6.5.1 (U) Output Receipt File
(S//NF) The Builder outputs an XML receipt file containing all the configuration settings for a
target. The receipt file is required when tasking implants and parsing output from a target. The
receipt file name will include the parent id as well as the child id if one exists (e.g.
test_ABCD0064_receipt.xml). Figure 12 shows an example of the receipt file format.
<?xml version="1.0" encoding="UTF-8"?>
<ATHENA>
<CLIENT_KEY>
<PUBLIC_KEY>-----BEGIN PUBLIC KEY-----
MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAwJjJBMrqVw3insRnvkGp
b1ySeVzBU2SK38g8i1JpZXELqzNzmrXKjg23A9H24hojPHnANzruDe13qJY+0vpe
wO7wbFWOCr5aJ2ETcDK+N601URMTsjy8k7uNasPtI+ffzuiCHvDYvoLtDORjAy45
zrwoPozzVlX01YEfc3nQMZ7YRmUZxNlkAq5nXoZuUeBzNpzYAEA8h84t2/HpFb+H
+1RYWIf7ZvJTadLHcw+8PsCX06Gr+HZRpi/c9CEakzhVfIwQg4rPuXsMDbP0D38k
IH09oP/yd73EJT4wO6jddtFWvXdOI/HWOcb8GXkpoPmcVP0jeaVOwE1l+nYddAou
DKMzaYivpeHsdsA2RjnwlcIFJKEHmug7ga0+4Xr7PGv/B8tWmCyLJOFnTB3xTiJ6
AQ5+Fgej6I/zg1o9XVs37kNHBdxzkia6XmMapfezKFhL06IQtTzV383IU28bouaC
QamGy009wFs0ZmjKVCxwsJoMNDWx/6iSg4diLu6Ju4jgsolG9SaOXur4pbOg8hFl
z1lvSC5FBD3OekpQNIsfPWslHfNa0Mvw1g+CftEKV1EIwv+KCm0aNzVi3vf+LpHu
jKN9go9oqyHK0UY2G1otCh+UlyLJJ71vHnJZ7jaMQLG3iYKmWN/PYz0svD50cEW9
wK31H27uRLVBZYGQ5815M5cCAwEAAQ==
-----END PUBLIC KEY-----
</PUBLIC_KEY>
<PRIVATE_KEY>-----BEGIN RSA PRIVATE KEY-----
MIIJKAIBAAKCAgEAwJjJBMrqVw3insRnvkGpb1ySeVzBU2SK38g8i1JpZXELqzNz
mrXKjg23A9H24hojPHnANzruDe13qJY+0vpewO7wbFWOCr5aJ2ETcDK+N601URMT
sjy8k7uNasPtI+ffzuiCHvDYvoLtDORjAy45zrwoPozzVlX01YEfc3nQMZ7YRmUZ
xNlkAq5nXoZuUeBzNpzYAEA8h84t2/HpFb+H+1RYWIf7ZvJTadLHcw+8PsCX06Gr
+HZRpi/c9CEakzhVfIwQg4rPuXsMDbP0D38kIH09oP/yd73EJT4wO6jddtFWvXdO
I/HWOcb8GXkpoPmcVP0jeaVOwE1l+nYddAouDKMzaYivpeHsdsA2RjnwlcIFJKEH
mug7ga0+4Xr7PGv/B8tWmCyLJOFnTB3xTiJ6AQ5+Fgej6I/zg1o9XVs37kNHBdxz
kia6XmMapfezKFhL06IQtTzV383IU28bouaCQamGy009wFs0ZmjKVCxwsJoMNDWx
/6iSg4diLu6Ju4jgsolG9SaOXur4pbOg8hFlz1lvSC5FBD3OekpQNIsfPWslHfNa
0Mvw1g+CftEKV1EIwv+KCm0aNzVi3vf+LpHujKN9go9oqyHK0UY2G1otCh+UlyLJ
SECRET//NOFORN 19

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh