RE: SpyNote v6.5 Cracked 2020 - mothered - 10-04-2020
(10-04-2020, 01:45 PM)fritz Wrote: I don't mind taking some risks for the sake of curiosity.  Curiosity has Its consequences.
Be sure to keep your sensitive data Isolated.
RE: SpyNote v6.5 Cracked 2020 - amc83 - 10-04-2020
(10-04-2020, 03:42 PM)mothered Wrote: (10-04-2020, 01:45 PM)fritz Wrote: I don't mind taking some risks for the sake of curiosity.  Curiosity has Its consequences.
Be sure to keep your sensitive data Isolated. try kinnie
RE: SpyNote v6.5 Cracked 2020 - fritz - 10-04-2020
(10-04-2020, 03:42 PM)mothered Wrote: (10-04-2020, 01:45 PM)fritz Wrote: I don't mind taking some risks for the sake of curiosity.  Curiosity has Its consequences.
Be sure to keep your sensitive data Isolated.
Well I don't have any sensitive data on my VMs
RE: SpyNote v6.5 Cracked 2020 - fritz - 10-04-2020
So I tried building an apk, it seems to work except it got stuck on signing it. Probably a problem with certificates, probably easy fix.
Here is the new analysis :
Code: Detailed report of suspicious malware actions:
Checked for debuggers
Checked for Microsoft Management Console software presence
Code injection in process: C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp
Code injection in process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe
Code injection in process: C:\Windows\System32\icacls.exe
Code injection in process: C:\Windows\SysWOW64\chcp.com
Code injection in process: C:\Windows\SysWOW64\cmd.exe
Code injection in process: C:\Windows\SysWOW64\WerFault.exe
Created a mutex named: .NET CLR Data_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET CLR Networking 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET CLR Networking_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Data Provider for Oracle_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Data Provider for SqlServer_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Memory Cache 4.0_Perf_Library_Lock_PID_6b8
Created a mutex named: .NETFramework_Perf_Library_Lock_PID_6b8
Created a mutex named: BITS_Perf_Library_Lock_PID_6b8
Created a mutex named: ESENT_Perf_Library_Lock_PID_6b8
Created a mutex named: Global\CLR_PerfMon_WrapMutex
Created a mutex named: Lsa_Perf_Library_Lock_PID_6b8
Created a mutex named: LSM_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC Bridge 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC Bridge 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC_Perf_Library_Lock_PID_6b8
Created a mutex named: MSSCNTRS_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfDisk_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfNet_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfOS_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfProc_Perf_Library_Lock_PID_6b8
Created a mutex named: rdyboost_Perf_Library_Lock_PID_6b8
Created a mutex named: RemoteAccess_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelEndpoint 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelOperation 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelService 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: SMSvcHost 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: SMSvcHost 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: Spooler_Perf_Library_Lock_PID_6b8
Created a mutex named: TapiSrv_Perf_Library_Lock_PID_6b8
Created a mutex named: Tcpip_Perf_Library_Lock_PID_6b8
Created a mutex named: TermService_Perf_Library_Lock_PID_6b8
Created a mutex named: UGatherer_Perf_Library_Lock_PID_6b8
Created a mutex named: UGTHRSVC_Perf_Library_Lock_PID_6b8
Created a mutex named: usbhub_Perf_Library_Lock_PID_6b8
Created a mutex named: Windows Workflow Foundation 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: Windows Workflow Foundation 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: WmiApRpl_Perf_Library_Lock_PID_6b8
Created a mutex named: WSearchIdxPi_Perf_Library_Lock_PID_6b8
Created an event named: Global\CLR_PerfMon_DoneEnumEvent
Created an event named: Global\CLR_PerfMon_StartEnumEvent
Created an event named: Global\CPFATE_1720_v4.0.30319
Created an event named: Global\CPFATE_5900_v4.0.30319
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar" b -f -r app-release, C:\Building-6.4\apktool
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar" d app-release.apk, C:\Building-6.4\apktool
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -version, C:\Users\root\Downloads\AT
Created process: C:\Program Files\Java\jre1.8.0_261\bin\java.exe, java -jar C:\Building-6.4\apktool\SignApk.jar C:\Building-6.4\apktool\certificate.pem C:\Building-6.4\apktool\key.pk8 C:\Building-6.4\apktool\app-release\dist\app-release.apk C:\Building-6.4\apktool\out\client.apk, C:\Program Files\Java\jre1.8.0_261\bin
Created process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe, "C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe" n -160, C:\Users\root\Downloads\AT
Created process: C:\Windows\system32\chcp.com, chcp 65001 , C:\Building-6.4\apktool
Created process: null, "C:\Windows\explorer.exe" "C:\Building-6.4\apktool\out", null
Created process: null, "cmd.exe", C:\Users\root\Downloads\AT
Created process: null, C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp p --forced-package-id 127 --min-sdk-version 10 --target-sdk-version 22 --version-code 1 --version-name 6.4.4 --no-version-vectors -F C:\Users\root\AppData\Local\Temp\APKTOOL8645836706554158331.tmp -0 arsc -0 png -0 res/drawable-hdpi/abc_ab_share_pack_mtrl_alpha.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00001.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00012.9.png -0 res/drawable-hdpi/abc_cab_background_top_mtrl_alpha.9.png -, null
Created process: null, C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M, null
Defined file type created: C:\Building-6.4\apktool\apktool.bat
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Data\Linkage\Export = .NET CLR Data
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Networking\Linkage\Export = .NET CLR Networking
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for Oracle\Linkage\Export = .NET Data Provider for Oracle
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for SqlServer\Linkage\Export = .NET Data Provider for SqlServer
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Performance\1008 = A07730EF809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Start = 00000003
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DcomLaunch = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DPS = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\gpsvc = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\Lsa\Performance\1008 = C5AA7AEF809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\rdyboost\Performance\1023 = 2AD35EF0809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\RpcSs = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\SamSs = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrkWks = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrustedInstaller = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiServiceHost = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiSystemHost = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WmiApRpl\Performance\1008 = 2FB07BF0809AD601
Detected keylogger functionality
Detected privilege modification
Detected process privilege elevation
Enumerated running processes
Error reporting dialog change: machine\software\microsoft\windows\windows error reporting\dontshowui = 00000001
Got computer name
Got input locale identifiers
Got system default language ID
Got volume information
Locked screen
Queried DNS: eafddirect.msedge.net
Queried DNS: encrypted-tbn0.gstatic.com
Queried DNS: fonts.gstatic.com
Queried DNS: k-ring.msedge.net
Queried DNS: virustotal.lan
Queried DNS: wpad.lan
Queried DNS: www.google.com
Queried DNS: www.virustotal.com
Slept over 2 minutes
Terminated process: C:\Windows\SysWOW64\cmd.exe
This executable was detected by an antivirus software: 8 vendors from virustotal.com (2020-09-27)
Traces of Max++
Used a pipe for inter-process communication
It looks pretty clean. I wonder about those Queries though, maybe that's a problem with BSA itself (I don't see why would this app call virustotal).
I just noticed the code injections though, that might not be normal, not really sure as JRE could be responsible ? I'd guess it's normal for cmd.exe at least.
And here is the VT of the APK generated : https://www.virustotal.com/gui/file/c6c8e1e731c4d69c2ee7f8fdc7943ebd09b0cc096fb0d8a8c29f8986d11c3ff4/detection
Next plan is to try it (I need a safe Android environnement first) and look at the connexions.
RE: SpyNote v6.5 Cracked 2020 - mothered - 10-05-2020
(10-04-2020, 04:47 PM)fritz Wrote: Well I don't have any sensitive data on my VMs Malware and the like can circumvent VMs, and Infect the Host/physical machine.
It's good practice to have a dedicated Host system (with a VM as the Guest) solely used for testing purposes.
RE: SpyNote v6.5 Cracked 2020 - miso - 10-05-2020
(10-04-2020, 08:26 PM)fritz Wrote: So I tried building an apk, it seems to work except it got stuck on signing it. Probably a problem with certificates, probably easy fix.
Here is the new analysis :
Code: Detailed report of suspicious malware actions:
Checked for debuggers
Checked for Microsoft Management Console software presence
Code injection in process: C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp
Code injection in process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe
Code injection in process: C:\Windows\System32\icacls.exe
Code injection in process: C:\Windows\SysWOW64\chcp.com
Code injection in process: C:\Windows\SysWOW64\cmd.exe
Code injection in process: C:\Windows\SysWOW64\WerFault.exe
Created a mutex named: .NET CLR Data_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET CLR Networking 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET CLR Networking_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Data Provider for Oracle_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Data Provider for SqlServer_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Memory Cache 4.0_Perf_Library_Lock_PID_6b8
Created a mutex named: .NETFramework_Perf_Library_Lock_PID_6b8
Created a mutex named: BITS_Perf_Library_Lock_PID_6b8
Created a mutex named: ESENT_Perf_Library_Lock_PID_6b8
Created a mutex named: Global\CLR_PerfMon_WrapMutex
Created a mutex named: Lsa_Perf_Library_Lock_PID_6b8
Created a mutex named: LSM_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC Bridge 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC Bridge 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC_Perf_Library_Lock_PID_6b8
Created a mutex named: MSSCNTRS_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfDisk_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfNet_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfOS_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfProc_Perf_Library_Lock_PID_6b8
Created a mutex named: rdyboost_Perf_Library_Lock_PID_6b8
Created a mutex named: RemoteAccess_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelEndpoint 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelOperation 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelService 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: SMSvcHost 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: SMSvcHost 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: Spooler_Perf_Library_Lock_PID_6b8
Created a mutex named: TapiSrv_Perf_Library_Lock_PID_6b8
Created a mutex named: Tcpip_Perf_Library_Lock_PID_6b8
Created a mutex named: TermService_Perf_Library_Lock_PID_6b8
Created a mutex named: UGatherer_Perf_Library_Lock_PID_6b8
Created a mutex named: UGTHRSVC_Perf_Library_Lock_PID_6b8
Created a mutex named: usbhub_Perf_Library_Lock_PID_6b8
Created a mutex named: Windows Workflow Foundation 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: Windows Workflow Foundation 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: WmiApRpl_Perf_Library_Lock_PID_6b8
Created a mutex named: WSearchIdxPi_Perf_Library_Lock_PID_6b8
Created an event named: Global\CLR_PerfMon_DoneEnumEvent
Created an event named: Global\CLR_PerfMon_StartEnumEvent
Created an event named: Global\CPFATE_1720_v4.0.30319
Created an event named: Global\CPFATE_5900_v4.0.30319
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar" b -f -r app-release, C:\Building-6.4\apktool
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar" d app-release.apk, C:\Building-6.4\apktool
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -version, C:\Users\root\Downloads\AT
Created process: C:\Program Files\Java\jre1.8.0_261\bin\java.exe, java -jar C:\Building-6.4\apktool\SignApk.jar C:\Building-6.4\apktool\certificate.pem C:\Building-6.4\apktool\key.pk8 C:\Building-6.4\apktool\app-release\dist\app-release.apk C:\Building-6.4\apktool\out\client.apk, C:\Program Files\Java\jre1.8.0_261\bin
Created process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe, "C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe" n -160, C:\Users\root\Downloads\AT
Created process: C:\Windows\system32\chcp.com, chcp 65001 , C:\Building-6.4\apktool
Created process: null, "C:\Windows\explorer.exe" "C:\Building-6.4\apktool\out", null
Created process: null, "cmd.exe", C:\Users\root\Downloads\AT
Created process: null, C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp p --forced-package-id 127 --min-sdk-version 10 --target-sdk-version 22 --version-code 1 --version-name 6.4.4 --no-version-vectors -F C:\Users\root\AppData\Local\Temp\APKTOOL8645836706554158331.tmp -0 arsc -0 png -0 res/drawable-hdpi/abc_ab_share_pack_mtrl_alpha.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00001.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00012.9.png -0 res/drawable-hdpi/abc_cab_background_top_mtrl_alpha.9.png -, null
Created process: null, C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M, null
Defined file type created: C:\Building-6.4\apktool\apktool.bat
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Data\Linkage\Export = .NET CLR Data
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Networking\Linkage\Export = .NET CLR Networking
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for Oracle\Linkage\Export = .NET Data Provider for Oracle
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for SqlServer\Linkage\Export = .NET Data Provider for SqlServer
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Performance\1008 = A07730EF809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Start = 00000003
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DcomLaunch = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DPS = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\gpsvc = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\Lsa\Performance\1008 = C5AA7AEF809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\rdyboost\Performance\1023 = 2AD35EF0809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\RpcSs = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\SamSs = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrkWks = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrustedInstaller = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiServiceHost = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiSystemHost = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WmiApRpl\Performance\1008 = 2FB07BF0809AD601
Detected keylogger functionality
Detected privilege modification
Detected process privilege elevation
Enumerated running processes
Error reporting dialog change: machine\software\microsoft\windows\windows error reporting\dontshowui = 00000001
Got computer name
Got input locale identifiers
Got system default language ID
Got volume information
Locked screen
Queried DNS: eafddirect.msedge.net
Queried DNS: encrypted-tbn0.gstatic.com
Queried DNS: fonts.gstatic.com
Queried DNS: k-ring.msedge.net
Queried DNS: virustotal.lan
Queried DNS: wpad.lan
Queried DNS: www.google.com
Queried DNS: www.virustotal.com
Slept over 2 minutes
Terminated process: C:\Windows\SysWOW64\cmd.exe
This executable was detected by an antivirus software: 8 vendors from virustotal.com (2020-09-27)
Traces of Max++
Used a pipe for inter-process communication
It looks pretty clean. I wonder about those Queries though, maybe that's a problem with BSA itself (I don't see why would this app call virustotal).
I just noticed the code injections though, that might not be normal, not really sure as JRE could be responsible ? I'd guess it's normal for cmd.exe at least.
And here is the VT of the APK generated : https://www.virustotal.com/gui/file/c6c8e1e731c4d69c2ee7f8fdc7943ebd09b0cc096fb0d8a8c29f8986d11c3ff4/detection
Next plan is to try it (I need a safe Android environnement first) and look at the connexions. i also have problem with apk signing, if i knew how to do it i'd also propose cracks of android apps.
what is the app supposed to do?
RE: SpyNote v6.5 Cracked 2020 - fritz - 10-05-2020
(10-05-2020, 02:47 AM)mothered Wrote: (10-04-2020, 04:47 PM)fritz Wrote: Well I don't have any sensitive data on my VMs Malware and the like can circumvent VMs, and Infect the Host/physical machine.
It's good practice to have a dedicated Host system (with a VM as the Guest) solely used for testing purposes.
Do you have some sources about this ? I know there has been exploits in the past, but I believe it's much more secured now. But yeah of course there is never 0 risk...
(10-05-2020, 05:58 AM)miso Wrote: (10-04-2020, 08:26 PM)fritz Wrote: So I tried building an apk, it seems to work except it got stuck on signing it. Probably a problem with certificates, probably easy fix.
Here is the new analysis :
Code: Detailed report of suspicious malware actions:
Checked for debuggers
Checked for Microsoft Management Console software presence
Code injection in process: C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp
Code injection in process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe
Code injection in process: C:\Windows\System32\icacls.exe
Code injection in process: C:\Windows\SysWOW64\chcp.com
Code injection in process: C:\Windows\SysWOW64\cmd.exe
Code injection in process: C:\Windows\SysWOW64\WerFault.exe
Created a mutex named: .NET CLR Data_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET CLR Networking 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET CLR Networking_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Data Provider for Oracle_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Data Provider for SqlServer_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Memory Cache 4.0_Perf_Library_Lock_PID_6b8
Created a mutex named: .NETFramework_Perf_Library_Lock_PID_6b8
Created a mutex named: BITS_Perf_Library_Lock_PID_6b8
Created a mutex named: ESENT_Perf_Library_Lock_PID_6b8
Created a mutex named: Global\CLR_PerfMon_WrapMutex
Created a mutex named: Lsa_Perf_Library_Lock_PID_6b8
Created a mutex named: LSM_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC Bridge 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC Bridge 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC_Perf_Library_Lock_PID_6b8
Created a mutex named: MSSCNTRS_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfDisk_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfNet_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfOS_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfProc_Perf_Library_Lock_PID_6b8
Created a mutex named: rdyboost_Perf_Library_Lock_PID_6b8
Created a mutex named: RemoteAccess_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelEndpoint 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelOperation 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelService 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: SMSvcHost 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: SMSvcHost 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: Spooler_Perf_Library_Lock_PID_6b8
Created a mutex named: TapiSrv_Perf_Library_Lock_PID_6b8
Created a mutex named: Tcpip_Perf_Library_Lock_PID_6b8
Created a mutex named: TermService_Perf_Library_Lock_PID_6b8
Created a mutex named: UGatherer_Perf_Library_Lock_PID_6b8
Created a mutex named: UGTHRSVC_Perf_Library_Lock_PID_6b8
Created a mutex named: usbhub_Perf_Library_Lock_PID_6b8
Created a mutex named: Windows Workflow Foundation 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: Windows Workflow Foundation 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: WmiApRpl_Perf_Library_Lock_PID_6b8
Created a mutex named: WSearchIdxPi_Perf_Library_Lock_PID_6b8
Created an event named: Global\CLR_PerfMon_DoneEnumEvent
Created an event named: Global\CLR_PerfMon_StartEnumEvent
Created an event named: Global\CPFATE_1720_v4.0.30319
Created an event named: Global\CPFATE_5900_v4.0.30319
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar" b -f -r app-release, C:\Building-6.4\apktool
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar" d app-release.apk, C:\Building-6.4\apktool
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -version, C:\Users\root\Downloads\AT
Created process: C:\Program Files\Java\jre1.8.0_261\bin\java.exe, java -jar C:\Building-6.4\apktool\SignApk.jar C:\Building-6.4\apktool\certificate.pem C:\Building-6.4\apktool\key.pk8 C:\Building-6.4\apktool\app-release\dist\app-release.apk C:\Building-6.4\apktool\out\client.apk, C:\Program Files\Java\jre1.8.0_261\bin
Created process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe, "C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe" n -160, C:\Users\root\Downloads\AT
Created process: C:\Windows\system32\chcp.com, chcp 65001 , C:\Building-6.4\apktool
Created process: null, "C:\Windows\explorer.exe" "C:\Building-6.4\apktool\out", null
Created process: null, "cmd.exe", C:\Users\root\Downloads\AT
Created process: null, C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp p --forced-package-id 127 --min-sdk-version 10 --target-sdk-version 22 --version-code 1 --version-name 6.4.4 --no-version-vectors -F C:\Users\root\AppData\Local\Temp\APKTOOL8645836706554158331.tmp -0 arsc -0 png -0 res/drawable-hdpi/abc_ab_share_pack_mtrl_alpha.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00001.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00012.9.png -0 res/drawable-hdpi/abc_cab_background_top_mtrl_alpha.9.png -, null
Created process: null, C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M, null
Defined file type created: C:\Building-6.4\apktool\apktool.bat
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Data\Linkage\Export = .NET CLR Data
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Networking\Linkage\Export = .NET CLR Networking
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for Oracle\Linkage\Export = .NET Data Provider for Oracle
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for SqlServer\Linkage\Export = .NET Data Provider for SqlServer
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Performance\1008 = A07730EF809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Start = 00000003
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DcomLaunch = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DPS = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\gpsvc = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\Lsa\Performance\1008 = C5AA7AEF809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\rdyboost\Performance\1023 = 2AD35EF0809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\RpcSs = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\SamSs = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrkWks = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrustedInstaller = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiServiceHost = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiSystemHost = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WmiApRpl\Performance\1008 = 2FB07BF0809AD601
Detected keylogger functionality
Detected privilege modification
Detected process privilege elevation
Enumerated running processes
Error reporting dialog change: machine\software\microsoft\windows\windows error reporting\dontshowui = 00000001
Got computer name
Got input locale identifiers
Got system default language ID
Got volume information
Locked screen
Queried DNS: eafddirect.msedge.net
Queried DNS: encrypted-tbn0.gstatic.com
Queried DNS: fonts.gstatic.com
Queried DNS: k-ring.msedge.net
Queried DNS: virustotal.lan
Queried DNS: wpad.lan
Queried DNS: www.google.com
Queried DNS: www.virustotal.com
Slept over 2 minutes
Terminated process: C:\Windows\SysWOW64\cmd.exe
This executable was detected by an antivirus software: 8 vendors from virustotal.com (2020-09-27)
Traces of Max++
Used a pipe for inter-process communication
It looks pretty clean. I wonder about those Queries though, maybe that's a problem with BSA itself (I don't see why would this app call virustotal).
I just noticed the code injections though, that might not be normal, not really sure as JRE could be responsible ? I'd guess it's normal for cmd.exe at least.
And here is the VT of the APK generated : https://www.virustotal.com/gui/file/c6c8e1e731c4d69c2ee7f8fdc7943ebd09b0cc096fb0d8a8c29f8986d11c3ff4/detection
Next plan is to try it (I need a safe Android environnement first) and look at the connexions. i also have problem with apk signing, if i knew how to do it i'd also propose cracks of android apps.
what is the app supposed to do?
You can find a list of features here for example : https://crackconnect.com/spynote/
But don't use the fake download link obviously
RE: SpyNote v6.5 Cracked 2020 - TheMinister - 10-05-2020
(10-05-2020, 02:47 AM)mothered Wrote: (10-04-2020, 04:47 PM)fritz Wrote: Well I don't have any sensitive data on my VMs Malware and the like can circumvent VMs, and Infect the Host/physical machine.
It's good practice to have a dedicated Host system (with a VM as the Guest) solely used for testing purposes. why we can't use sandboxie inside VMware ? : )
RE: SpyNote v6.5 Cracked 2020 - fritz - 10-05-2020
(10-05-2020, 02:21 PM)TheMinister Wrote: (10-05-2020, 02:47 AM)mothered Wrote: (10-04-2020, 04:47 PM)fritz Wrote: Well I don't have any sensitive data on my VMs Malware and the like can circumvent VMs, and Infect the Host/physical machine.
It's good practice to have a dedicated Host system (with a VM as the Guest) solely used for testing purposes. why we can't use sandboxie inside VMware ? : )
Supposing that VMs can be circumvented and Sandboxie too, well using both isn't totally secure either.
RE: SpyNote v6.5 Cracked 2020 - TheMinister - 10-05-2020
(10-05-2020, 03:36 PM)fritz Wrote: (10-05-2020, 02:21 PM)TheMinister Wrote: (10-05-2020, 02:47 AM)mothered Wrote: Malware and the like can circumvent VMs, and Infect the Host/physical machine.
It's good practice to have a dedicated Host system (with a VM as the Guest) solely used for testing purposes. why we can't use sandboxie inside VMware ? : )
Supposing that VMs can be circumvented and Sandboxie too, well using both isn't totally secure either. circumvent even with guest isolation ? that would be a hack at the VMware's system level.
|