ForlaxPy

Members
  • Content Count

    732
  • Last visited

Posts posted by ForlaxPy


  1. Hello there,

     

    So I had a vouch of this Crypter and as a I tested it and analyzed how it works I would like to share with you with a think about it.

    First of all The UI is so clean and easy to use so anyone could just take his exe there and crypt it.

     

    DBQzQbR.png

     

     

    It has also a lot of obfuscations features such as Controll Flow - Methods and strings/value Renamers - IlDasm - Anti Tamper and much more!

     

    Z2i92wb.png

    oEwBzmo.png

     

    When it comes to protecting the your exe src it does a great job as well! So not anyone with these public unpcker will be able to get his hand into your src code.

     

    HNtPCbD.png

    aL4lCse.png

     

    Also for the main feature? Is it FUD? Well I tried it and here it what I got.

     

    Before:

    ZoWQMP7.png

     

    After:

     

    3cWuT1R.png


  2. ati0D17.png

    [align=center]NULLEHASH NOOBHASH DECRYPTOR (MD5 + SHA1)

     

    This tool will decrypt most of your MD5 and SHA1 passwords

     

    Info :

     

    1 - Check Decryption Server status on startup  :ezy:  ッ

    2 - Please do not go over 200 threads ! (100-150 recommended). Server will ignore your requests if threads number is high

    3 - Passwords will be checked if MD5 or SHA1 by the tool and saved in 5 Text Files (MD5 - MD5 Not Found, SHA1, SHA1 Not Found, Unsupported)

    4 - This version was changed alot. i first included more passwords type then decided to go with 2 most common. More will be added later in the update

    5 - SHA1 success rate is not very high. Next update will include "RETRY" for not found passwords with other servers once a better servers are found

    6 - This is first release. Expect bugs 

     

    Press Enter or type anything when it starts

     

    Screenshot :[/align]

     

    9eDYgbl.png

     

    5UAy9Vw.png

     

    [hide]

    DL: https://anonfile.com/Ofxdj1seb5/NulleHash_KX99_rar [Last Checked as clean 1-30-2019]

    VirusTotal: https://www.virustotal.com/#/file/a5e7850887a63262627b70f747f8c4287219db5e7c7f77c394114e5d0a0d268f/detection

    [/hide]


  3. Well first of all Hello.

    In the couple last days I asked a friend for his team viewer it was @Devil , he had Fiddler opens as we were trying to update some API function of FAF, and when he launched up SNIPR to crack something, I noticed that he auto authenticated, and in the background I saw some requests going on inside of Fiddler. I stopped him and asked to upload that Fiddler session for me.

     

    So here is how it looks like:

     

    mreQZlI.png

     

    So as You can see I edited the screenshot to make the explanation easier. The login sent requests are our target so the first requests gonna be a version check and that's hella importatnt and PRAGMA did just released a new update where he probably patched this yesterday, but good for us I still got the previous version. The second one is the key as it sends a request to the server with a generated HWID + the given email + pass and the third one has the main SNIPR UI, yes SNIPR Form or UI or GUI or panel... (call irt whatever you want) Is saved online in his server. So all you gotta do is take the session file that I'm gonna provide you and start faking some responses using fiddler.  Using the response breakpoints. 

     

    npND3iL.png

     

    This will prevent SNIPR from getting the response until you approve it from Fiddler, so the good about this is that we can take the previous session responses that @Devil had and provide them as reponses or and that the best option is to Host these responses in a local File and to disable the cnx betwen SNIPR and PRAGMA's API. How? Easy. SNIPR is using Eazfuscator.NET as an obfuscator and I'm pretty sure that you can easily deofuscat it just by a quick search on Google. So that's basically the whole auth stage, after that you fake the third Http request you can just disable fiddler and let snipper grab the client needed files such as Configs and the others js required stuffs. So as I said above hosting these files locally and by using a little redirect trick SNIPR will work perfectly.

     

    All right so I'm a Reverser so why didn't I did this? To be honest I wanted to do this but everytime I opens my decompiler to check for where are these requests sent from I get kicked off by how many the classes are. Yes I fully decompiled it to a readable code but still gotta clean some junks. I'm sure that there is a second way to do that manually by settlng a XAMP host in the machine and redirecting these requests or by coding a program that does this but I'm kinda lazy to do that so yes Here is everything you need to know about how SNIPR works/auth. And it's still getting sold for 20$ so....

    I'm ready to help anyone that is willing to continue on this project but don't expect me to do much as I already quited it.

     

     

    FAWrsdv.png

     

    WLqsKO6.png

     

    Files Needed:

     

    [hide]

    The SNIPR Files used: https://anonfile.com/2al2oar5b1/SNIPR_rar

    The Fiddler Session: https://anonfile.com/wbs3ocreb3/SNIPR_session_rar

    [/hide]

    Good Luck!

    [align=left]

    [/align]


  4. 8YHKwYC.png

     

     

    Steps:

     

    Download Anatomy files.

    Launch ShineOnEm ==> Select Anatomy

    Launch anatomy and Voila!

     

    [hide]

    DL: https://anonfile.com/rc57j6seb9/AnatomyProtected_-_Cracked_7z  [Last Time Checked as Clean 1-30-2018]

    VirusTotal: https://www.virustotal.com/#/file/865e1a356c67897b8c3b06ae7c44855f970e645d4e2b642898c881b137878c77/detection

    [/hide]


  5. et0jkrM.png

    9hWlamz.png 

    Really ?   :kappa:  

     

     

    ivP2qjh.png

     

     

    ======================================================================================================================================================

     

     

    For the auth stage just type anything or even nothing 

     

    If you get any error like this just keep on spamming OK or "X" . Not my fault I download the checker built like this  :fuck:

     

    EDt8sWM.png

     

     

    [hide]

    DL: 

    VirusTotal: https://www.virustotal.com/#/file/2abd76496a6d0e6b491f27e8d6e94b1e584e5b80b9ab97bb22fc7b348d1837df/detection

    [/hide]


  6. GODFLIX

    Account Checker w/ Pass Changer + Giftcard Checker

     

    BgH9pzO.png

     

    Just Press Enter when it ask y for Auth and Voila

     

     

    [hide]

    Press enter when it ask for Auth

    [align=center]DL: https://anonfile.com/kbZ9k4s4b6/GodFlix_Bypassed_Auth_rar [Marked as Clean 1-30-2019]

    VirusTotal: https://www.virustotal.com/#/file/5f7cc09aadec11aa8a7b08f6a9359e9f3fb9a31d689861a7d397f06d95ec75a8/detection

    [/hide][/align]