Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

Elsa User Manual.doc
7
SECRET//NOFORN
4) The desired maximum log file size
5) Whether or not to resolve ap lists into geos from the target
4.1 (U) PATCHER Configuration Tool
(S) The PATCHER tool generates a deployable Elsa implant (dll) based upon the
configuration options specified by the user. These configuration options can be specified
in a file or interactively in wizard mode. The general PATCHER command line syntax is
as follows:
> patcher.exe –p [x86|x64] –o OUTPUT_FILE [–c CONFIG_FILE] [-W]
(S) The specific syntax for wizard mode and config file mode are as follows:
> patcher.exe -p [x64|x86] –o new_tool.dll –W
- or –
> patcher.exe –p [x64|x86] –o new_tool.dll –c new_tool.config
Figure 4 - (S) Command line syntax for the PATCHER tool
4.1.1 (U) PATCHER option Processor Architecture
(S) The processor architecture parameters specifies the creation of either the x86 or x64
version of the dll. For system services such as SvcHost, DllHost, and RunDll32 the
processor architecture must match. The switch for this parameter is ‘-p’.
4.1.2 (U) PATCHER option Output File
(S) The output file option specifies the output file name for the ELSA implant. The
switch for this option is ‘-o’.
4.1.3 (U) PATCHER option Config File
(S) The config file option specifies the ELSA configuration file to use when creating an
implant. This option does not need to be specified, if the operator is using the Wizard
mode to generate a configured implant. The switch for this option is ‘-c’.
Mode = RunDll32
TargetProcess = rundll32.exe
DataFileName = %SystemRoot%\TEMP\elsag.data
DataFileMaximumSizeKB = 202
DataFileArchiveSeconds = 62
DataFileKey = F4CD1BC482E98849027CACB150FB96247E60A2CCA329114167DB0710FA679823
Guid = {59553112-3228-49ce-8044-4AB3C63BD46C}
WifiSurveyIntervalSeconds = 32
WifiSurveyInstallDelaySeconds = 32
WifiSurveyStartupDelaySeconds = 32
WifiSurveyFailureBackoffMultiple = 13
WifiRssiThreshold = 303
WifiSaveAllSurveys = false
GeoProvider = google
ClientID = 2234

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh