Sinisterly
Leak SpyNote v6.5 Cracked 2020 - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Remote Administration & Stress Testing (https://sinister.ly/Forum-Remote-Administration-Stress-Testing)
+--- Thread: Leak SpyNote v6.5 Cracked 2020 (/Thread-Leak-SpyNote-v6-5-Cracked-2020)

Pages: 1 2 3 4 5


RE: SpyNote v6.5 Cracked 2020 - mothered - 10-04-2020

(10-04-2020, 01:45 PM)fritz Wrote: I don't mind taking some risks for the sake of curiosity.  xD
Curiosity has Its consequences.

Be sure to keep your sensitive data Isolated.


RE: SpyNote v6.5 Cracked 2020 - amc83 - 10-04-2020

(10-04-2020, 03:42 PM)mothered Wrote:
(10-04-2020, 01:45 PM)fritz Wrote: I don't mind taking some risks for the sake of curiosity.  xD
Curiosity has Its consequences.

Be sure to keep your sensitive data Isolated.
try kinnie


RE: SpyNote v6.5 Cracked 2020 - fritz - 10-04-2020

(10-04-2020, 03:42 PM)mothered Wrote:
(10-04-2020, 01:45 PM)fritz Wrote: I don't mind taking some risks for the sake of curiosity.  xD
Curiosity has Its consequences.

Be sure to keep your sensitive data Isolated.

Well I don't have any sensitive data on my VMs


RE: SpyNote v6.5 Cracked 2020 - fritz - 10-04-2020

So I tried building an apk, it seems to work except it got stuck on signing it. Probably a problem with certificates, probably easy fix.

Here is the new analysis :

Code:
Detailed report of suspicious malware actions: Checked for debuggers Checked for Microsoft Management Console software presence Code injection in process: C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp Code injection in process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe Code injection in process: C:\Windows\System32\icacls.exe Code injection in process: C:\Windows\SysWOW64\chcp.com Code injection in process: C:\Windows\SysWOW64\cmd.exe Code injection in process: C:\Windows\SysWOW64\WerFault.exe Created a mutex named: .NET CLR Data_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET CLR Networking 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET CLR Networking_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET Data Provider for Oracle_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET Data Provider for SqlServer_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET Memory Cache 4.0_Perf_Library_Lock_PID_6b8 Created a mutex named: .NETFramework_Perf_Library_Lock_PID_6b8 Created a mutex named: BITS_Perf_Library_Lock_PID_6b8 Created a mutex named: ESENT_Perf_Library_Lock_PID_6b8 Created a mutex named: Global\CLR_PerfMon_WrapMutex Created a mutex named: Lsa_Perf_Library_Lock_PID_6b8 Created a mutex named: LSM_Perf_Library_Lock_PID_6b8 Created a mutex named: MSDTC Bridge 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: MSDTC Bridge 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: MSDTC_Perf_Library_Lock_PID_6b8 Created a mutex named: MSSCNTRS_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfDisk_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfNet_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfOS_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfProc_Perf_Library_Lock_PID_6b8 Created a mutex named: rdyboost_Perf_Library_Lock_PID_6b8 Created a mutex named: RemoteAccess_Perf_Library_Lock_PID_6b8 Created a mutex named: ServiceModelEndpoint 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: ServiceModelOperation 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: ServiceModelService 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: SMSvcHost 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: SMSvcHost 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: Spooler_Perf_Library_Lock_PID_6b8 Created a mutex named: TapiSrv_Perf_Library_Lock_PID_6b8 Created a mutex named: Tcpip_Perf_Library_Lock_PID_6b8 Created a mutex named: TermService_Perf_Library_Lock_PID_6b8 Created a mutex named: UGatherer_Perf_Library_Lock_PID_6b8 Created a mutex named: UGTHRSVC_Perf_Library_Lock_PID_6b8 Created a mutex named: usbhub_Perf_Library_Lock_PID_6b8 Created a mutex named: Windows Workflow Foundation 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: Windows Workflow Foundation 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: WmiApRpl_Perf_Library_Lock_PID_6b8 Created a mutex named: WSearchIdxPi_Perf_Library_Lock_PID_6b8 Created an event named: Global\CLR_PerfMon_DoneEnumEvent Created an event named: Global\CLR_PerfMon_StartEnumEvent Created an event named: Global\CPFATE_1720_v4.0.30319 Created an event named: Global\CPFATE_5900_v4.0.30319 Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java  -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar"  b -f -r app-release, C:\Building-6.4\apktool Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java  -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar"  d app-release.apk, C:\Building-6.4\apktool Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java  -version, C:\Users\root\Downloads\AT Created process: C:\Program Files\Java\jre1.8.0_261\bin\java.exe, java  -jar C:\Building-6.4\apktool\SignApk.jar C:\Building-6.4\apktool\certificate.pem C:\Building-6.4\apktool\key.pk8 C:\Building-6.4\apktool\app-release\dist\app-release.apk C:\Building-6.4\apktool\out\client.apk, C:\Program Files\Java\jre1.8.0_261\bin Created process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe, "C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe"  n -160, C:\Users\root\Downloads\AT Created process: C:\Windows\system32\chcp.com, chcp  65001 , C:\Building-6.4\apktool Created process: null, "C:\Windows\explorer.exe" "C:\Building-6.4\apktool\out", null Created process: null, "cmd.exe", C:\Users\root\Downloads\AT Created process: null, C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp p --forced-package-id 127 --min-sdk-version 10 --target-sdk-version 22 --version-code 1 --version-name 6.4.4 --no-version-vectors -F C:\Users\root\AppData\Local\Temp\APKTOOL8645836706554158331.tmp -0 arsc -0 png -0 res/drawable-hdpi/abc_ab_share_pack_mtrl_alpha.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00001.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00012.9.png -0 res/drawable-hdpi/abc_cab_background_top_mtrl_alpha.9.png -, null Created process: null, C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M, null Defined file type created: C:\Building-6.4\apktool\apktool.bat Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Data\Linkage\Export = .NET CLR Data Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Networking\Linkage\Export = .NET CLR Networking Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for Oracle\Linkage\Export = .NET Data Provider for Oracle Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for SqlServer\Linkage\Export = .NET Data Provider for SqlServer Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Performance\1008 = A07730EF809AD601 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Start = 00000003 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DcomLaunch = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DPS = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\gpsvc = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\Lsa\Performance\1008 = C5AA7AEF809AD601 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\rdyboost\Performance\1023 = 2AD35EF0809AD601 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\RpcSs = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\SamSs = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrkWks = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrustedInstaller = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiServiceHost = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiSystemHost = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WmiApRpl\Performance\1008 = 2FB07BF0809AD601 Detected keylogger functionality Detected privilege modification Detected process privilege elevation Enumerated running processes Error reporting dialog change: machine\software\microsoft\windows\windows error reporting\dontshowui = 00000001 Got computer name Got input locale identifiers Got system default language ID Got volume information Locked screen Queried DNS: eafddirect.msedge.net Queried DNS: encrypted-tbn0.gstatic.com Queried DNS: fonts.gstatic.com Queried DNS: k-ring.msedge.net Queried DNS: virustotal.lan Queried DNS: wpad.lan Queried DNS: www.google.com Queried DNS: www.virustotal.com Slept over 2 minutes Terminated process: C:\Windows\SysWOW64\cmd.exe This executable was detected by an antivirus software: 8 vendors from virustotal.com (2020-09-27) Traces of Max++ Used a pipe for inter-process communication

It looks pretty clean. I wonder about those Queries though, maybe that's a problem with BSA itself (I don't see why would this app call virustotal).
I just noticed the code injections though, that might not be normal, not really sure as JRE could be responsible ? I'd guess it's normal for cmd.exe at least.

And here is the VT of the APK generated : https://www.virustotal.com/gui/file/c6c8e1e731c4d69c2ee7f8fdc7943ebd09b0cc096fb0d8a8c29f8986d11c3ff4/detection

Next plan is to try it (I need a safe Android environnement first) and look at the connexions.


RE: SpyNote v6.5 Cracked 2020 - mothered - 10-05-2020

(10-04-2020, 04:47 PM)fritz Wrote: Well I don't have any sensitive data on my VMs
Malware and the like can circumvent VMs, and Infect the Host/physical machine.

It's good practice to have a dedicated Host system (with a VM as the Guest) solely used for testing purposes.


RE: SpyNote v6.5 Cracked 2020 - miso - 10-05-2020

(10-04-2020, 08:26 PM)fritz Wrote: So I tried building an apk, it seems to work except it got stuck on signing it. Probably a problem with certificates, probably easy fix.

Here is the new analysis :

Code:
Detailed report of suspicious malware actions: Checked for debuggers Checked for Microsoft Management Console software presence Code injection in process: C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp Code injection in process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe Code injection in process: C:\Windows\System32\icacls.exe Code injection in process: C:\Windows\SysWOW64\chcp.com Code injection in process: C:\Windows\SysWOW64\cmd.exe Code injection in process: C:\Windows\SysWOW64\WerFault.exe Created a mutex named: .NET CLR Data_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET CLR Networking 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET CLR Networking_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET Data Provider for Oracle_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET Data Provider for SqlServer_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET Memory Cache 4.0_Perf_Library_Lock_PID_6b8 Created a mutex named: .NETFramework_Perf_Library_Lock_PID_6b8 Created a mutex named: BITS_Perf_Library_Lock_PID_6b8 Created a mutex named: ESENT_Perf_Library_Lock_PID_6b8 Created a mutex named: Global\CLR_PerfMon_WrapMutex Created a mutex named: Lsa_Perf_Library_Lock_PID_6b8 Created a mutex named: LSM_Perf_Library_Lock_PID_6b8 Created a mutex named: MSDTC Bridge 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: MSDTC Bridge 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: MSDTC_Perf_Library_Lock_PID_6b8 Created a mutex named: MSSCNTRS_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfDisk_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfNet_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfOS_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfProc_Perf_Library_Lock_PID_6b8 Created a mutex named: rdyboost_Perf_Library_Lock_PID_6b8 Created a mutex named: RemoteAccess_Perf_Library_Lock_PID_6b8 Created a mutex named: ServiceModelEndpoint 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: ServiceModelOperation 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: ServiceModelService 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: SMSvcHost 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: SMSvcHost 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: Spooler_Perf_Library_Lock_PID_6b8 Created a mutex named: TapiSrv_Perf_Library_Lock_PID_6b8 Created a mutex named: Tcpip_Perf_Library_Lock_PID_6b8 Created a mutex named: TermService_Perf_Library_Lock_PID_6b8 Created a mutex named: UGatherer_Perf_Library_Lock_PID_6b8 Created a mutex named: UGTHRSVC_Perf_Library_Lock_PID_6b8 Created a mutex named: usbhub_Perf_Library_Lock_PID_6b8 Created a mutex named: Windows Workflow Foundation 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: Windows Workflow Foundation 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: WmiApRpl_Perf_Library_Lock_PID_6b8 Created a mutex named: WSearchIdxPi_Perf_Library_Lock_PID_6b8 Created an event named: Global\CLR_PerfMon_DoneEnumEvent Created an event named: Global\CLR_PerfMon_StartEnumEvent Created an event named: Global\CPFATE_1720_v4.0.30319 Created an event named: Global\CPFATE_5900_v4.0.30319 Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java  -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar"  b -f -r app-release, C:\Building-6.4\apktool Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java  -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar"  d app-release.apk, C:\Building-6.4\apktool Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java  -version, C:\Users\root\Downloads\AT Created process: C:\Program Files\Java\jre1.8.0_261\bin\java.exe, java  -jar C:\Building-6.4\apktool\SignApk.jar C:\Building-6.4\apktool\certificate.pem C:\Building-6.4\apktool\key.pk8 C:\Building-6.4\apktool\app-release\dist\app-release.apk C:\Building-6.4\apktool\out\client.apk, C:\Program Files\Java\jre1.8.0_261\bin Created process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe, "C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe"  n -160, C:\Users\root\Downloads\AT Created process: C:\Windows\system32\chcp.com, chcp  65001 , C:\Building-6.4\apktool Created process: null, "C:\Windows\explorer.exe" "C:\Building-6.4\apktool\out", null Created process: null, "cmd.exe", C:\Users\root\Downloads\AT Created process: null, C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp p --forced-package-id 127 --min-sdk-version 10 --target-sdk-version 22 --version-code 1 --version-name 6.4.4 --no-version-vectors -F C:\Users\root\AppData\Local\Temp\APKTOOL8645836706554158331.tmp -0 arsc -0 png -0 res/drawable-hdpi/abc_ab_share_pack_mtrl_alpha.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00001.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00012.9.png -0 res/drawable-hdpi/abc_cab_background_top_mtrl_alpha.9.png -, null Created process: null, C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M, null Defined file type created: C:\Building-6.4\apktool\apktool.bat Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Data\Linkage\Export = .NET CLR Data Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Networking\Linkage\Export = .NET CLR Networking Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for Oracle\Linkage\Export = .NET Data Provider for Oracle Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for SqlServer\Linkage\Export = .NET Data Provider for SqlServer Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Performance\1008 = A07730EF809AD601 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Start = 00000003 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DcomLaunch = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DPS = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\gpsvc = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\Lsa\Performance\1008 = C5AA7AEF809AD601 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\rdyboost\Performance\1023 = 2AD35EF0809AD601 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\RpcSs = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\SamSs = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrkWks = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrustedInstaller = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiServiceHost = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiSystemHost = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WmiApRpl\Performance\1008 = 2FB07BF0809AD601 Detected keylogger functionality Detected privilege modification Detected process privilege elevation Enumerated running processes Error reporting dialog change: machine\software\microsoft\windows\windows error reporting\dontshowui = 00000001 Got computer name Got input locale identifiers Got system default language ID Got volume information Locked screen Queried DNS: eafddirect.msedge.net Queried DNS: encrypted-tbn0.gstatic.com Queried DNS: fonts.gstatic.com Queried DNS: k-ring.msedge.net Queried DNS: virustotal.lan Queried DNS: wpad.lan Queried DNS: www.google.com Queried DNS: www.virustotal.com Slept over 2 minutes Terminated process: C:\Windows\SysWOW64\cmd.exe This executable was detected by an antivirus software: 8 vendors from virustotal.com (2020-09-27) Traces of Max++ Used a pipe for inter-process communication

It looks pretty clean. I wonder about those Queries though, maybe that's a problem with BSA itself (I don't see why would this app call virustotal).
I just noticed the code injections though, that might not be normal, not really sure as JRE could be responsible ? I'd guess it's normal for cmd.exe at least.

And here is the VT of the APK generated : https://www.virustotal.com/gui/file/c6c8e1e731c4d69c2ee7f8fdc7943ebd09b0cc096fb0d8a8c29f8986d11c3ff4/detection

Next plan is to try it (I need a safe Android environnement first) and look at the connexions.
i also have problem with apk signing, if i knew how to do it i'd also propose cracks of android apps.

what is the app supposed to do?


RE: SpyNote v6.5 Cracked 2020 - fritz - 10-05-2020

(10-05-2020, 02:47 AM)mothered Wrote:
(10-04-2020, 04:47 PM)fritz Wrote: Well I don't have any sensitive data on my VMs
Malware and the like can circumvent VMs, and Infect the Host/physical machine.

It's good practice to have a dedicated Host system (with a VM as the Guest) solely used for testing purposes.

Do you have some sources about this ? I know there has been exploits in the past, but I believe it's much more secured now. But yeah of course there is never 0 risk...

(10-05-2020, 05:58 AM)miso Wrote:
(10-04-2020, 08:26 PM)fritz Wrote: So I tried building an apk, it seems to work except it got stuck on signing it. Probably a problem with certificates, probably easy fix.

Here is the new analysis :

Code:
Detailed report of suspicious malware actions: Checked for debuggers Checked for Microsoft Management Console software presence Code injection in process: C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp Code injection in process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe Code injection in process: C:\Windows\System32\icacls.exe Code injection in process: C:\Windows\SysWOW64\chcp.com Code injection in process: C:\Windows\SysWOW64\cmd.exe Code injection in process: C:\Windows\SysWOW64\WerFault.exe Created a mutex named: .NET CLR Data_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET CLR Networking 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET CLR Networking_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET Data Provider for Oracle_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET Data Provider for SqlServer_Perf_Library_Lock_PID_6b8 Created a mutex named: .NET Memory Cache 4.0_Perf_Library_Lock_PID_6b8 Created a mutex named: .NETFramework_Perf_Library_Lock_PID_6b8 Created a mutex named: BITS_Perf_Library_Lock_PID_6b8 Created a mutex named: ESENT_Perf_Library_Lock_PID_6b8 Created a mutex named: Global\CLR_PerfMon_WrapMutex Created a mutex named: Lsa_Perf_Library_Lock_PID_6b8 Created a mutex named: LSM_Perf_Library_Lock_PID_6b8 Created a mutex named: MSDTC Bridge 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: MSDTC Bridge 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: MSDTC_Perf_Library_Lock_PID_6b8 Created a mutex named: MSSCNTRS_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfDisk_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfNet_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfOS_Perf_Library_Lock_PID_6b8 Created a mutex named: PerfProc_Perf_Library_Lock_PID_6b8 Created a mutex named: rdyboost_Perf_Library_Lock_PID_6b8 Created a mutex named: RemoteAccess_Perf_Library_Lock_PID_6b8 Created a mutex named: ServiceModelEndpoint 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: ServiceModelOperation 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: ServiceModelService 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: SMSvcHost 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: SMSvcHost 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: Spooler_Perf_Library_Lock_PID_6b8 Created a mutex named: TapiSrv_Perf_Library_Lock_PID_6b8 Created a mutex named: Tcpip_Perf_Library_Lock_PID_6b8 Created a mutex named: TermService_Perf_Library_Lock_PID_6b8 Created a mutex named: UGatherer_Perf_Library_Lock_PID_6b8 Created a mutex named: UGTHRSVC_Perf_Library_Lock_PID_6b8 Created a mutex named: usbhub_Perf_Library_Lock_PID_6b8 Created a mutex named: Windows Workflow Foundation 3.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: Windows Workflow Foundation 4.0.0.0_Perf_Library_Lock_PID_6b8 Created a mutex named: WmiApRpl_Perf_Library_Lock_PID_6b8 Created a mutex named: WSearchIdxPi_Perf_Library_Lock_PID_6b8 Created an event named: Global\CLR_PerfMon_DoneEnumEvent Created an event named: Global\CLR_PerfMon_StartEnumEvent Created an event named: Global\CPFATE_1720_v4.0.30319 Created an event named: Global\CPFATE_5900_v4.0.30319 Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java  -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar"  b -f -r app-release, C:\Building-6.4\apktool Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java  -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar"  d app-release.apk, C:\Building-6.4\apktool Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java  -version, C:\Users\root\Downloads\AT Created process: C:\Program Files\Java\jre1.8.0_261\bin\java.exe, java  -jar C:\Building-6.4\apktool\SignApk.jar C:\Building-6.4\apktool\certificate.pem C:\Building-6.4\apktool\key.pk8 C:\Building-6.4\apktool\app-release\dist\app-release.apk C:\Building-6.4\apktool\out\client.apk, C:\Program Files\Java\jre1.8.0_261\bin Created process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe, "C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe"  n -160, C:\Users\root\Downloads\AT Created process: C:\Windows\system32\chcp.com, chcp  65001 , C:\Building-6.4\apktool Created process: null, "C:\Windows\explorer.exe" "C:\Building-6.4\apktool\out", null Created process: null, "cmd.exe", C:\Users\root\Downloads\AT Created process: null, C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp p --forced-package-id 127 --min-sdk-version 10 --target-sdk-version 22 --version-code 1 --version-name 6.4.4 --no-version-vectors -F C:\Users\root\AppData\Local\Temp\APKTOOL8645836706554158331.tmp -0 arsc -0 png -0 res/drawable-hdpi/abc_ab_share_pack_mtrl_alpha.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00001.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00012.9.png -0 res/drawable-hdpi/abc_cab_background_top_mtrl_alpha.9.png -, null Created process: null, C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M, null Defined file type created: C:\Building-6.4\apktool\apktool.bat Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Data\Linkage\Export = .NET CLR Data Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Networking\Linkage\Export = .NET CLR Networking Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for Oracle\Linkage\Export = .NET Data Provider for Oracle Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for SqlServer\Linkage\Export = .NET Data Provider for SqlServer Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Performance\1008 = A07730EF809AD601 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Start = 00000003 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DcomLaunch = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DPS = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\gpsvc = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\Lsa\Performance\1008 = C5AA7AEF809AD601 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\rdyboost\Performance\1023 = 2AD35EF0809AD601 Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\RpcSs = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\SamSs = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrkWks = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrustedInstaller = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiServiceHost = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiSystemHost = created registry key Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WmiApRpl\Performance\1008 = 2FB07BF0809AD601 Detected keylogger functionality Detected privilege modification Detected process privilege elevation Enumerated running processes Error reporting dialog change: machine\software\microsoft\windows\windows error reporting\dontshowui = 00000001 Got computer name Got input locale identifiers Got system default language ID Got volume information Locked screen Queried DNS: eafddirect.msedge.net Queried DNS: encrypted-tbn0.gstatic.com Queried DNS: fonts.gstatic.com Queried DNS: k-ring.msedge.net Queried DNS: virustotal.lan Queried DNS: wpad.lan Queried DNS: www.google.com Queried DNS: www.virustotal.com Slept over 2 minutes Terminated process: C:\Windows\SysWOW64\cmd.exe This executable was detected by an antivirus software: 8 vendors from virustotal.com (2020-09-27) Traces of Max++ Used a pipe for inter-process communication

It looks pretty clean. I wonder about those Queries though, maybe that's a problem with BSA itself (I don't see why would this app call virustotal).
I just noticed the code injections though, that might not be normal, not really sure as JRE could be responsible ? I'd guess it's normal for cmd.exe at least.

And here is the VT of the APK generated : https://www.virustotal.com/gui/file/c6c8e1e731c4d69c2ee7f8fdc7943ebd09b0cc096fb0d8a8c29f8986d11c3ff4/detection

Next plan is to try it (I need a safe Android environnement first) and look at the connexions.
i also have problem with apk signing, if i knew how to do it i'd also propose cracks of android apps.

what is the app supposed to do?

You can find a list of features here for example : https://crackconnect.com/spynote/
But don't use the fake download link obviously Wink


RE: SpyNote v6.5 Cracked 2020 - TheMinister - 10-05-2020

(10-05-2020, 02:47 AM)mothered Wrote:
(10-04-2020, 04:47 PM)fritz Wrote: Well I don't have any sensitive data on my VMs
Malware and the like can circumvent VMs, and Infect the Host/physical machine.

It's good practice to have a dedicated Host system (with a VM as the Guest) solely used for testing purposes.
why we can't use sandboxie inside VMware ? : )


RE: SpyNote v6.5 Cracked 2020 - fritz - 10-05-2020

(10-05-2020, 02:21 PM)TheMinister Wrote:
(10-05-2020, 02:47 AM)mothered Wrote:
(10-04-2020, 04:47 PM)fritz Wrote: Well I don't have any sensitive data on my VMs
Malware and the like can circumvent VMs, and Infect the Host/physical machine.

It's good practice to have a dedicated Host system (with a VM as the Guest) solely used for testing purposes.
why we can't use sandboxie inside VMware ? : )

Supposing that VMs can be circumvented and Sandboxie too, well using both isn't totally secure either.


RE: SpyNote v6.5 Cracked 2020 - TheMinister - 10-05-2020

(10-05-2020, 03:36 PM)fritz Wrote:
(10-05-2020, 02:21 PM)TheMinister Wrote:
(10-05-2020, 02:47 AM)mothered Wrote: Malware and the like can circumvent VMs, and Infect the Host/physical machine.

It's good practice to have a dedicated Host system (with a VM as the Guest) solely used for testing purposes.
why we can't use sandboxie inside VMware ? : )

Supposing that VMs can be circumvented and Sandboxie too, well using both isn't totally secure either.
circumvent even with guest isolation ? that would be a hack at the VMware's system level.