Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
MD5 Values:
Emotional_Simian_Config.exe 199CE7F487C43B3562041BC1D94EDDBF
Emotional_Simian_Config.exe.config
D0089718B62F6E9D91154ACAE007699C
Emotional_Simian_Config.vshost.exe
B4D5137244BB4259A208B815E7C9F7B9
Emotional_Simian_Config.Vshost.exe.config
D0089718B62F6E9D91154ACAE007699C
ES Server.exe FDB376AAC8F1D3B3891ED49C90CF9770
ES Server64.exe 1CDA0D262661F8561ACD292565DE5AE2
ES Setup. exe F8A27982E0D8B315CFCEE0F1EF831884
Extract WM Files. exe 1E2092CF75760F96DC5543D233FD7072
Get SN. exe 851AFAFB0EEA7C30F80B20D676BEF84E
Keygen. exe 4305E6275B98A6C22BCA762350615461
Post Processor. exe D3F1C6CCA9F7CDDFDCBF02F7EF3A0BCF
Whack_Thumbdrive. exe FF8CF6E59FFBB328C179492D0C391AD8
Dll_Payload.dll 3B90EF9C6BA44B8EE0F0313CA6990614
Dll_Payload64.dll 04F94FE005613B5C0CE13DAFB640D645
3.2 System Concepts and Capabilities
• Emotional_Simian_Config.exe – This is the setup GUI used by the user to create
the .cfg file to be laid down on the primary host.
• ./Internal/ES Setup.exe – This tool is called by Emotional_Simian_Config.exe
and is used to package the .cfg file.
• ./Internal/KeyGen.exe – This tool is called by Emotional_Simian_Config.exe to
create a public-private key pair.
• ./Internal/Post Processor.exe – This tool is used to decompress, decrypt, and
piece together any collected files.
• ./Internal/ES Server.exe – Executable to be laid down on a 32-bit primary host.
This tool runs in the background and watches for the insertion of a whitelisted
thumb drive. Upon insertion of a whitelisted thumb drive, ES Server will infect
the drive with the required files.
• ./Internal/ES Server64.exe – Executable to be laid down on a 64-bit primary
host.
• ./Internal/Extract WM Files.exe – This tool extracts files stored on the covert
storage of the thumb drive.
• ./Internal/Get SN.exe – This tool can be put on a target to find the serial number
of targeted thumb drives (This can also be done by looking at the registry files).
• ./Internal/Dlls/DllPayload64.dll - The 64-bit version of the Emotional Simian dll
payload.
5
SECRET//X1
CL BY: 2397517
REASON: 1.4(c)
DECL: 20361019
DRV: COL S-06