Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
If Dumbo is unable to create a blue screen crash scenario, a warning will be displayed to the
operator that the attempt failed.
Link to view a screenshot of the Exit Options tab
3.3 (U) Logging Details
(U) Dumbo maintains a verbose log of all actions taken either automatically or manually by
the operator. The log is stored in a file called “log.txt” and is located in the same directory as
the tool’s execution. For the log to be maintained, the thumb drive Dumbo is executed from
must remain plugged into the system throughout the duration of the operation. Dumbo will
not report failed logging attempts if the drive is removed.
All logging entries are preceded by an ISO 8601 UTC timestamp, ex.:
[Year-Month-Day Hour:Minutes:Seconds UTC]
Logging entries are also preceded by a header labeling if the entry is good, bad, or simply
informative. The following shows an example log excerpt:
[2015-06-24 20:10:17 UTC] ==================== Started ====================
[2015-06-24 20:10:17 UTC] (INFO) Operating System: Windows 7 Professional Service Pack 1
[2015-06-24 20:10:17 UTC] (INFO) Computer Name: Example-PC
[2015-06-24 20:10:17 UTC] (INFO) Computer Architecture: x64
[2015-06-24 20:10:17 UTC] (GOOD) Disabled adapter: Local Area Connection
[2015-06-24 20:10:17 UTC] (GOOD) Muted all microphones
[2015-06-24 20:10:17 UTC] (INFO) Found a camera device, Friendly Name: Microsoft® LifeCam Cinema(TM)
[2015-06-24 20:10:18 UTC] (BAD) Found a process using a camera! PID: 6020, Filename: C:\iSpy\iSpy.exe
[2015-06-24 20:10:18 UTC] (GOOD) Suspended PID: 6020, Filename: C:\iSpy\iSpy.exe
[2015-06-24 20:10:18 UTC] (INFO) Found a file with write-permission, Filename: C:\Recordings\video.mp4
[2015-06-24 20:10:23 UTC] (GOOD) Corrupted file: C:\Recordings\video.mp4
[2015-06-24 20:10:23 UTC] (GOOD) Deleted file: C:\Recordings\video.mp4
[2015-06-24 20:10:29 UTC] (INFO) Began exit timer for 3 minutes
Dumbo’s log is constantly appended to at the end of the file. If the tool is run on the same
thumb drive, across multiple uses, without cleaning the log file, the log will maintain the
entries from all uses.
3.4 (U) Additional Notes
Recording Software Crashes
(S) If Dumbo corrupts or deletes a file, the recording software using that file may crash upon
being resumed. This is dependent on how the recording software handles the resulting error,
and is impossible to detect beforehand.
Windows XP
(S) In order to function properly, Dumbo must install a device driver when running on
Windows XP. Dumbo will handle this automatically, but the initialization process may take
considerably longer to load in comparison to a user’s experience with the tool on other
operating systems.
SECRET//NOFORN
7

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh