Vault 7: Projects
This publication series is about specific projects related to the Vault 7 main publication.
SECRET//20341105
Issue Cause Remediation
If a driver start type of boot start (-
b) is specified, the driver will be
started at the same time as the
system start drivers (-s).
This is a limitation of the covert
file system.
This will be fixed in a future
version.
If –c is used on a running system
and then a reboot occurs, wolfcreek
will exit during startup.
This behavior is expected. If
there is no covert storage area,
wolfcreek cannot function.
Re add the covert storage area
by using one of the following
BadMFS commands: –l, -f
If an existing file (not badmfs) is
specified in the zf, it will be used
and modified by badmfs.
BadMFS does not check to see
if the file specified is a valid
badmfs archive.
In the future, BadMFS can check
to see if the file is actually a
valid BadMFS archive. Until
then, care must be taken when
specifying the file name.
If an application that is started by
Angelfire crashes, it is possible that
a dialog box will pop up on the
target machine stating that
svchost.exe has crashed.
All user implants look like
svchost.exe.
Fix the bug in the crashing
implant.
If a reinstallation is being done (i.e.
a –r followed by a –ipl) it is likely
an error will be returned by stp (603
or 607).
This is due to remnants of
Angelfire remaining in memory
for a short period of time
following the –r command.
Run –ipl again and it should
succeed.
An application that uses networking
is failing when started on reboot.
Angelfire starts executables
very early and sometimes the
network stack might not be fully
up and available.
Use the –p switch to delay the
application executing for x
number of seconds. This should
allow the network stack time to
become available.
When using the –i (interval) option,
if an interval of less than 2 minutes
is used, there could be network
anomalies. This is similar to the
previous issue.
Cause is unknown. The problem has only been
observed with an interval of less
than 2 minutes.
When executing GUI programs with
Angelfire, the process might start,
but the GUI will not be visible.
This is due to the manner in
which MagicWand starts
processes.
This might be fixed in a future
version.
Angelfire does not allow execution
of 32 bit implants on a 64 bit
machine.
This is a limitation of
MagicWand as it doesn’t handle
WOW 64 execution.
Ensure you are running a 64 bit
version of the implant on 64 bit
machines.
af+mainrepo+wolfcreek+Docs+Angelfire_UserGuide
17 of 21
SECRET//20341105
Wolfcreek-Docs-Angelfire_UserGuide.pdf