Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

3. System Description
3.1 Technical References
MD5 Values:
ES Setup.exe
Extract WM Files.exe
Get SN.exe
KeyGen.exe
Post Processor.exe
Whack_Thumbdrive.exe
ES Server.exe
ES Server64.exe
Dll_Payload.dll
Dll_Payload64.dll
Emotional_Simian_Config.exe
3.2 System Concepts and Capabilities
The following is a quick overview of the above mentioned pieces.
Emotional_Simian_Config.exe – This is setup GUI used by the user to create the
.cfg file to be laid down on the primary host.
./Internal/ES Setup.exe – This tool is called by Emotional_Simian_Config.exe
and is used package the .cfg file.
./Internal/KeyGen.exe – This tool creates a public private key. This program is
used by Emotional_Simian_Config.exe.
./Internal/Post Processor.exe – This is used to decompress, decrypt, and piece
together any collected files.
./Internal/ES Server.exe – To be laid down on a 32bit primary host. This tool
runs in the background and watches for the insertion of a white list drive. Upon
introduction ES Server will infect the drive with the required files.
./Internal/ES Server64.exe – To be laid down on a 64bit primary host. This tool
runs in the background and watches for the insertion of a white list drive. Upon
introduction ES Server will infect the drive with the required files.
./Internal/Extract WM Files.exe – This tool can extract files stored on the covert
storage of the thumb drive to a folder of your choosing.
./Internal/Get SN.exe – This tool can be put on a target to find the serial number
for the thumb drive you are targeting. (This can also be done by looking at the
registry files.
./Internal/Dlls/DllPayload64.dll - The 64bit version of the Emotional Simian dll
payload.
./Internal/Dlls/DllPayload.dll – The 32bit version of Emotional Simian dll
payload.
5
SECRET//X1
CL BY: 2397517
REASON: 1.4(c)
DECL: 20361019
DRV: COL S-06

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh