Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
4.6 (U) Installation Confirmation
(S//NF) To confirm an installation of SG2 which persisted a DLL payload, simply check
that the stub DLL was laid down on disk at the target location.
(S//NF) To confirm that a driver-only payload installation of SG2 worked, you'll have to
rely on the return codes of the installers. Driver-only installs write nothing to the file
system on disk, and verification of installation would require inspection of the disk using
something like WinHex. You could try to re-install again and see if you get a previous
install return code (900 for the shellcode installer).
(S//NF) Starting in SG 2.1, the Uninstall DLL (Named Control32 or Control64) will have
the ability to verify installation without uninstalling. Using the -c argument, the DLL
will verify installation after a reboot.
5. (U) Uninstall
(S//NF) If a GH1 payload is being persisted, the GH1 payload can trigger an uninstall.
Otherwise, two DLLs have been provided to trigger an uninstall event. The DLLs
Control32 and Control64 are simple Fire and Forget DLLs which tell SG2 to uninstall.
To instruct the Control DLL to uninstall, provide the -u argument. A non-zero return
value indicates failure. Otherwise, zero is returned.
(S//NF) If a payload DLL was used, the stub DLL on disk will be queued for deletion
after the next reboot. All other artifacts (stub driver, payload driver, payload DLL) are
wiped from disk during the uninstall process (3x overwrite with zeros).
(S//NF) Note: GH1 uninstalls can take some time. During testing, it was possible to
trigger the GH1 uninstall through something like IcePick, and restart the system before
IcePick had a chance to notify the SG2 stub to uninstall. Typically, the GH1 uninstall
will take 30-60 seconds to complete.
SECRET//NOFORN
- xii -

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh