Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

computer. Once the thumb drive comes back to the Primary Host, if checked, ES
Server(64).exe will change the GUID located in DllPayload(64).dll. This will
allow DllPayload(64).dll to rewhacked downstream targets.
4. Percentage for Covert Partition: This is how much covert storage you want to
allocate on this thumb drive. Warnings: You are not guaranteed the amount you
request. ES Server(64).exe will attempt to give you as much as you asked for, but
if it is not possible ES Server(64).exe will give you the maximum it can without
going over the percentage you specify. Taking more than 10% of the drive could
be noticeable by the user. (Default is 5%). 0% will enable ES server to not put a
covert storage on the drive, however with 0% you will not be able to collect a
survey or files, but it will allow you run payloads.
5. Black List: This is a list of executables that signal a no go for
DllPayload(64).exe. Note Black List is an ‘or’ condition. Meaning if any of the
conditions set forth are met it will not deploy the payload.
6. Files to Delete: After everything has been accomplished (survey, file collection,
and\or dropping of the payloads) DllPayload(64).dll will attempt to delete these
files. These files have to be absolute paths. If the file is in use, then the file will
not be deleted.
7. Persist Completed Reg Key: If this box is not checked, the reg key that indicates
the dll has fired will be deleted on reboot. Checked, this reg key will persist a
reboot. You would use this if you needed to run a payload once per reboot.
8. Overwrite Existing Files: If this box is checked, and the Dll or lnk files exist,
they will be overwritten. However, once the thumbdrive has been whacked, the
files will not be replaced regardless. So, if Target/Owner of the thumbdrive
deletes the files, the files will not show up again unless you lay down a new
configuration file.
12
SECRET//X1
CL BY: 2397517
REASON: 1.4(c)
DECL: 20361019
DRV: COL S-06

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh