Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//ORCON//NOFORN
If I put an upload_all at the end of a batch, why don't I get all my results
right away?
All results of a batch are placed in a single result file. When the upload_all portion of
the batch runs, the file is still open and unfinished, therefore it is not uploaded.
Only results in the upload queue that existed prior to the batch execution are
uploaded.
In order to immediately receive the results of a batch, run the generate_batch
command with the push run mode flag.
If I set bothanuninstall_timer and an uninstall_date, when will the implant
actually uninstall?
Whichever happens first, the uninstall timer counts down to zero or the uninstall
date arrives.
I ran a command that says it succeeded in the results, but it has a
Windows Error Code; did the command actually succeed?
Yes. The Windows error code is the result of Windows GetLastError function and
does not necessarily mean something unexpected happened. If the implant reports
success, either the GetLastError result was expected or not critical.
The Windows error code is most useful for determining the cause of a reported
failure from the implant.
I have a large file in the implant output directory that is not being
uploaded; why?
Assassin will not store more than 16,384 files in its staging directory. The
combination of a very large file and/or very small chunk size may overflow this
directory limit. Assassin will leave the file in the output directory, but it will not
process or upload it.
In order to retrieve the file, you can:
Increase the chunk size such that the file will not overflow the staging
directory.
Manually break up the file such that it will be chunked piecewise.
Use the get command in push mode to manually upload the file to the
listening post directly.
Can I run multiple Assassin Implants on a target at the same time?
Only one Assassin Implant can run on a target per unique parent ID. If you must run
multiple Implants on a single target, make sure they each have different four-byte
parent IDs.
What if an Assassin Implant is started multiple times?
Assassin is able to detect concurrent instances with the same parent ID. If an
Assassin Implant starts and detects that another implant with the same parent ID is
running, it will exit.
How can I export a commonly used task for later use?
In the Tasker, run generate_batch to create your task. Before generating the task,
use the export command as follows: x <xml_filename><task_filename> to export the
task to xml.
51
SECRET//ORCON//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh