Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

(running ES Server(64).exe), it will not trigger on that secondary host a second
time. Once the selected whitelisted thumb drive comes back to the Primary Host,
if checked, ES Server(64).exe will change the GUID located in
DllPayload(64).dll. This will allow DllPayload(64).dll to re-infect secondary
hosts.
4. Percentage for Covert Partition: This is how much covert storage to allocate on
the selected whitelisted thumb drive. ES Server(64).exe will attempt to provide
what was requested, but if it is not possible then ES Server(64).exe will provide
the maximum it can without going over the percentage specified. Taking more
than 10% of the drive could be noticeable by the user. (Default is 5%). 0% will
configure ES server to not put a covert storage on the drive. 0% does not support
collecting surveys or files, but will run payloads.
5. ES_Dll Black List: This is a list of executables where the presence of one will
cause DllPayload(64).dll to immediately exit. Note Black List is an ‘or condition.
6. Files to Delete: The last thing DllPayload(64).dll does (post survey, file
collection, and/or dropping of the payloads) is the file deletion. These files have
to be absolute paths. If the file is in use, then the file will not be deleted.
7. Persist Completed Reg Key: If this box is not checked, the reg key that indicates
the dll has fired will be deleted on reboot. If this box is checked, the reg key will
persist on reboot. The presence of the reg key prevents the secondary host from
being infected a second time.
8. Overwrite Existing Files: If this box is checked, and the Dll or lnk files exist on
the selected whitelisted thumb drive, they will be overwritten. However, if the
files are deleted then they will not be replaced. So, if the Target/Owner of the
thumb drive deletes the files, the files will not show up again unless a new
configuration file in installed.
12
SECRET//X1
CL BY: 2397517
REASON: 1.4(c)
DECL: 20361019
DRV: COL S-06

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh