Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
3.9 (U) Troubleshooting
(S//NF) BothanSpy couldn't find any versions to attack (as printed to the screen via
Shellterm ): Then BothanSpy could not find any Xshellcore.exe or Xshell.exe processes
to inject into. Perform a process listing on the target to see if those process exist. If those
processes do not exist, are you sure that Xshell is running? And are you sure that Xshell,
if it is running, has any active sessions? If the target has renamed the Xshell executables,
you'll have to edit the BothanSpy.py Shellterm script accordingly. Feel free to ask the
developer of BothanSpy what to do in this instance.
(S//NF) BothanSpy found Xshell processes to steal from, but no credentials were
recovered: Are you sure that the target has active sessions in Xshell? If you know for
sure that the target's Xshell process is managing active sessions, the version of Xshell in
use may be unsupported by BothanSpy. Check the registry key
HKLM\Software\NetSarang\Xshell for a list of major versions installed. If versions 4
and 5 are installed, you should see the subkeys '4' and '5' under the Xshell key. Under
those subkeys will be the build number. This information is useful to the developer to
add support for a new version of Xshell.
(S//NF) Shellterm says something about an unsupported request when running
BothanSpy.py, or some other error when running BothanSpy.py: Shellterm 3.0+ is
required to run BothanSpy against x64 target machines, as it is the latest Shellterm
version known to support Wow64 injection. The error message you are getting likely
means you are running a version of Shellterm that does not do Wow64 injection. If
Shellterm does not recognize the command “BothanSpy” then you may have put the
BothanSpy.py file in the wrong scripts folder for your Shellterm installation.
(S//NF) I went to destroy the Death Star with the information obtained by
BothanSpy, but The Empire's entire Star Ship fleet warped in, and the shield
generators are not down on the Death Star, what gives?: I told you it would be a trap
(Section 3.7), that's on you.
SECRET//NOFORN
1

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh