FinFisher/0012A3F0

Aus Piratenwiki Mirror
Zur Navigation springen Zur Suche springen

0012A3F0

Licenses

customer_license
LicenseID MachineUID SoftwareUID SoftwareName VersionMajor NotBefore ValidityStart NotAfter ValidityEnd InstallationDate LicenseFile LicenseContents Status CustomerID ProductID Deleted UserID DataEntryDate LastUpdated
458 5F:E2:FF:AC:7F:05:4A:51 00:1E:00:0A FinSpyV2 4 1354320000 2012-12-01 01:00:00 1386633600 2013-12-10 01:00:00 2012-12-06 00:17:36 License.txt MACHINE UID

5F:E2:FF:AC:7F:05:4A:51 CUSTOMER UID 0012A3F0 SOFTWARE UID 00:1E:00:0A SOFTWARE NAME FinSpyV2 AGENTS MAX NUMBER 1 TARGETS MAX NUMBER 10 NOT BEFORE 1354320000 NOT AFTER 1386633600 MOBILE NOT BEFORE 0 MOBILE NOT AFTER 0 MOBILE TARGETS MAX NUMBER 0 VERSION MAJOR 4 DEMO 0

Expired 73 16 1 5 2012-12-06 00:17:36 2014-01-09 10:15:05
459 5F:E2:FF:AC:7F:05:4A:51 00:1E:00:0A FinSpyV2 4 1354320000 2012-12-01 01:00:00 1386633600 2013-12-10 01:00:00 2012-12-06 00:17:53 License.txt MACHINE UID

5F:E2:FF:AC:7F:05:4A:51 CUSTOMER UID 0012A3F0 SOFTWARE UID 00:1E:00:0A SOFTWARE NAME FinSpyV2 AGENTS MAX NUMBER 1 TARGETS MAX NUMBER 10 NOT BEFORE 1354320000 NOT AFTER 1386633600 MOBILE NOT BEFORE 0 MOBILE NOT AFTER 0 MOBILE TARGETS MAX NUMBER 0 VERSION MAJOR 4 DEMO 0

Expired 73 1 1 5 2012-12-06 00:17:53 2014-01-09 10:15:02
664 7D:F2:88:0B:F9:22:F0:46 00:1D:00:0A FinFireWire 4 1382140800 2013-10-19 02:00:00 1414108800 2014-10-24 02:00:00 2013-10-21 15:46:44 License.txt MACHINE UID

7D:F2:88:0B:F9:22:F0:46 CUSTOMER UID 0012A3F0 SOFTWARE UID 00:1D:00:0A SOFTWARE NAME FinFireWire VERSION MAJOR 4 NOT BEFORE 1382140800 NOT AFTER 1414108800 DEMO 0

Activated 73 12 0 5 2013-10-21 15:46:44 2013-10-21 13:46:44
698 5F:E2:FF:AC:7F:05:4A:51 00:1E:00:0A FinSpyV2 4 1388188800 2013-12-28 01:00:00 1419897600 2014-12-30 01:00:00 2014-01-09 11:14:37 License.txt MACHINE UID

5F:E2:FF:AC:7F:05:4A:51 CUSTOMER UID 0012A3F0 SOFTWARE UID 00:1E:00:0A SOFTWARE NAME FinSpyV2 AGENTS MAX NUMBER 1 TARGETS MAX NUMBER 10 NOT BEFORE 1388188800 NOT AFTER 1419897600 MOBILE NOT BEFORE 0 MOBILE NOT AFTER 0 MOBILE TARGETS MAX NUMBER 0 VERSION MAJOR 4 DEMO 0

Activated 73 1 0 5 2014-01-09 11:14:37 2014-01-09 10:14:37
699 5F:E2:FF:AC:7F:05:4A:51 00:1E:00:0A FinSpyV2 4 1388188800 2013-12-28 01:00:00 1419897600 2014-12-30 01:00:00 2014-01-09 11:14:51 License.txt MACHINE UID

5F:E2:FF:AC:7F:05:4A:51 CUSTOMER UID 0012A3F0 SOFTWARE UID 00:1E:00:0A SOFTWARE NAME FinSpyV2 AGENTS MAX NUMBER 1 TARGETS MAX NUMBER 10 NOT BEFORE 1388188800 NOT AFTER 1419897600 MOBILE NOT BEFORE 0 MOBILE NOT AFTER 0 MOBILE TARGETS MAX NUMBER 0 VERSION MAJOR 4 DEMO 0

Activated 73 16 0 5 2014-01-09 11:14:51 2014-01-09 10:14:51

Support-Requests

00940BEB

TrackingID: "00940BEB"

Summary: "Connecting to the server"

Description: "Hi Martin,\r\n\r\nWe manage to eliminate the last 2 screenshots related problems that I sent prior.\r\nWe have a clean installed windows7 dell laptop.\r\nNow the hardship is to connect to the server. The connect button wouldnt switch to blue, but I can ping the server. I set the servers ip and port also, username and password are ok.\r\n\r\nAny idea?\r\n\r\nBest regards,\r\n\r\nZoltan"

ProductID: 1

TypeID: 3

FileName: "00940BEB"

StatusNotification: 1

SupportComments: "

An corresponding email has been send.

"

StatusID: 2

CustomerID: 73

Language: "en"

CreationDate: "2013-09-25 16:53:13"

LastUpdated: "2013-10-16 11:47:03"

0908AA53

TrackingID: "0908AA53"

Summary: "oops..."

Description: "https://citizenlab.org/storage/finfisher/final/fortheireyesonly.pdf"

ProductID: 1

TypeID: 1

FileName: "0908AA53"

StatusNotification: 1

SupportComments: "A suitable mail were sent"

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2013-05-02 14:02:02"

LastUpdated: "2013-05-04 16:45:38"

0E03300C

TrackingID: "0E03300C"

Summary: "update 3.5"

Description: "Dear Supporter Team!\r\n\r\nWe wanted to update our finfirewire to the new version 3.5, but the lan card does not worked on the laptop - os error message: no network device available - so we cannot connect to the internet. \r\nIs there any other way to get/download to the installations files from an other machine?\r\nCould you shared or send the original or updated files for us? \r\n\r\nThanks"

ProductID: 12

TypeID: 3

FileName: "0E03300C"

StatusNotification: 1

SupportComments: "

\r\n<pre>\r\n<pre>\r\n<pre>\r\n<pre>An corresponding email has been sent.

\r\n\r\n\r\n\r\n"

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2014-02-04 14:41:19"

LastUpdated: "2014-04-23 07:55:43"

194EF1AD

TrackingID: "194EF1AD"

Summary: "trojan generation"

Description: "Dear Support Team, We cannot generate either bootable iso image or bootable infection dongle, I attached the error massage and our software version is 4.40.1427 Please help us find a solution, Regards, Zoltan Hungary SSNS"

ProductID: 1

TypeID: 3

FileName: "194EF1AD.png"

StatusNotification: 1

SupportComments: "Dear Customer,
please be informed that an suitable mail has been sent to
the email address: balogh.peter@nbsz.gov.hu

Please see the mail below:


Dear Customer, *TrackingID:* 194EF1AD *Related Product:* FinSpy *Request Type:* Annoyance *Summary:* trojan generation *Description:* Dear Support Team, We cannot generate either bootable iso image or bootable infection dongle, I attached the error massage and our software version is 4.40.1427 Please help us find a solution, I'd like to inform you, that we have a solution for your Problem. Please find the required download link below. =\"https://www.gamma-international.de/FinFisher/0012A3F0/FinSpyAgent.4.40.zip.gpg\" class=\"moz-txt-link-freetext\">https://www.gamma-international.de/FinFisher/0012A3F0/FinSpyAgent.4.40.zip.gpg</a>

Username: 0012A3F0
Password: F1nF1sher4You

If you have any questions, please do not hesitate to contact us.

Best regards,"

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2013-11-12 11:10:24"

LastUpdated: "2013-11-13 14:43:22"

1B71C2F1

TrackingID: "1B71C2F1"

Summary: "trojan generation"

Description: "Hi,\r\n\r\nThanks for the previous answers, I managed to install the Agent to the other laptop.\r\n\r\nBut I still cannot generate infected USB dongle nor ISO image.\r\nI attached the screenshot, with the error message.\r\n\r\nRegards,\r\n\r\nZoltan"

ProductID: 1

TypeID: 3

FileName: "1B71C2F1.jpg"

StatusNotification: 1

SupportComments: "An corresponding email has been send."

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2013-09-26 08:48:46"

LastUpdated: "2013-09-27 06:22:18"

1D801515

TrackingID: "1D801515"

Summary: "certificates"

Description: "There is a zip file containing 5 certificate files in it. Should I copy them to somewhere in the newly installed windows7 environment?\r\nAs I said I can ping the server, but the connect button wouldnt change to blue and I cannot push it. If I switch back the cable to the Lenovo L420 I can connect, but cannot create infections. Thats why we prepared another laptop..."

ProductID: 1

TypeID: 3

FileName: "1D801515"

StatusNotification: 1

SupportComments: "An corresponding email has been send."

StatusID: 2

CustomerID: 73

Language: "en"

CreationDate: "2013-09-25 17:09:15"

LastUpdated: "2013-10-16 11:46:49"

306ACAEF

TrackingID: "306ACAEF"

Summary: "Connection problems"

Description: "Hello,\r\n\r\nWe have two problems with the connections to tartgets.\r\n\r\nFirst of all we tried to infect a target which is in Windows domain\r\nbehind of HTTP proxy and Cisco ASA firewall. The connection is established and\r\nthe target is online, but if we try to configure the target or\r\nwe would like to start a live session, the target goes to offline for few seconds\r\nand then online again. We get an -307 The target is offline error messages.\r\nThis case repeats continuously. \r\n\r\nWe updated the agent to 4.40 and we would like to update every online targets, and\r\nin some cases we get an -324 The target is busy running an update error messages\r\nand the update failed.\r\n\r\nRegars"

ProductID: 1

TypeID: 2

FileName: "306ACAEF"

StatusNotification: 1

SupportComments: "A  corresponding has been sent.
"

StatusID: 2

CustomerID: 73

Language: "en"

CreationDate: "2013-09-09 14:51:08"

LastUpdated: "2013-10-16 11:51:14"

413FD3BF

TrackingID: "413FD3BF"

Summary: "infect win 8.1 enterprise x64 en"

Description: "Dear Support Team,\r\n\r\nThank you for the latest solution, no we can generate usb dongle/exe agents again. \r\nBut we encountered a new issue: we cannot infect a test HP pavilion dv6 test laptop with the Finspy vith USB dongle. It looks like as it was infected, but no TCP connection builts out in between the target and relay server. I deliberately did not tick for active hiding for testing purposes, and no TCP connection was seen in netstat. I tried to deploy the infection 2 times with no success.\r\n\r\nBest regards,\r\n\r\nZoltan "

ProductID: 1

TypeID: 3

FileName: "413FD3BF"

StatusNotification: 1

SupportComments: "

\r\n<pre>An corresponding email has been send. The ticket is closed.

\r\n"

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2013-11-18 16:38:22"

LastUpdated: "2013-11-19 11:21:37"

46C00C80

TrackingID: "46C00C80"

Summary: "Cannot update again"

Description: "Hello I tried to update finspy master to 4.40 but connection to server failed.\r\nAfter it I check this:\r\nnmap -PN -p 42662 update.gamma-international.de\r\nbut port 42662 closed.\r\n\r\nDo you use other port to update now?"

ProductID: 1

TypeID: 2

FileName: "46C00C80"

StatusNotification: 1

SupportComments: ""

StatusID: 2

CustomerID: 73

Language: "en"

CreationDate: "2013-09-09 09:36:39"

LastUpdated: "2013-10-16 11:51:23"

4CF7E883

TrackingID: "4CF7E883"

Summary: "Relay"

Description: "I cannot find the new 4.40 relay installer.\r\nCould you tell me where can I find it?"

ProductID: 1

TypeID: 3

FileName: "4CF7E883"

StatusNotification: 1

SupportComments: "A corresponding email has been sent."

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2013-09-04 09:38:55"

LastUpdated: "2013-09-19 09:01:05"

56FD442E

TrackingID: "56FD442E"

Summary: "D8179365 track id answer"

Description: "Hello!\r\n\r\nWe copied the connection information to txts, and attached the sreenshots.\r\nThese are the most usually errors:\r\n- Error code 1: \r\nwe plugged the cable correctly, and the settings what we knowed, we set, but we got this this error code back sreenshot_u.png\r\n- when we thinked the hack was correct:\r\nthe hack went 1-2 minutes and we get sreenshot_w.png, but it not works.\r\n\r\nThank you!"

ProductID: 12

TypeID: 2

FileName: "56FD442E.zip"

StatusNotification: 1

SupportComments: "

\r\n<pre>\r\n<pre>An corresponding email has been sent.

\r\n\r\n"

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2014-02-26 14:09:36"

LastUpdated: "2014-05-22 09:32:39"

63950E50

TrackingID: 63950E50

Summary: "trojans lose connection"

Description: "Hello,\r\n\r\nSince we upgrade our finspy to the version 4.30, trojans go in for losing connection.\r\nI dont know what the matter is.\r\nI cut some lines from finspy_proxy and finspy_master log and attached it.\r\n\r\nRegards,"

ProductID: 1

TypeID: 2

FileName: "63950E50.log"

StatusNotification: 1

SupportComments: ""

StatusID: 2

CustomerID: 73

Language: "en"

CreationDate: "2013-04-18 10:23:44"

LastUpdated: "2013-05-02 09:49:35"

785A33CE

TrackingID: "785A33CE"

Summary: "infect win 8.1 enterprise x64 en"

Description: "Dear Support Team,\r\n\r\nI tried the infection on a completely different hardware and it doesnt work.\r\nThe test system :clean installed Windows 8.1 enterprise x64 on a Dell Inspiron Laptop.\r\nI did with the exe what you said in the last emails 1st point.\r\n\r\nRegards,\r\n\r\nZoltan"

ProductID: 1

TypeID: 3

FileName: "785A33CE"

StatusNotification: 1

SupportComments: "This bug has been fixed with the release version 4.50."

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2013-11-20 15:02:07"

LastUpdated: "2014-04-23 09:09:37"

92EE9DD3

TrackingID: "92EE9DD3"

Summary: "win8 : works but..."

Description: "Dear Armend,\r\n\r\nWe infected with the exe 2 times. 1 hour pause in between after 1 and half hour it came online. It works but the modules are pretty limited as for the configurations.\r\nIt does not work so flawlessly.\r\nWe are going to test the USB dongle infections tomorrow since its the most common in practice.\r\n\r\nRegards,\r\n\r\nZoltan"

ProductID: 1

TypeID: 3

FileName: "92EE9DD3"

StatusNotification: 1

SupportComments: "A corresponding email has been sent"

StatusID: 2

CustomerID: 73

Language: "en"

CreationDate: "2013-11-25 17:33:39"

LastUpdated: "2013-12-11 11:03:07"

949B14C3

TrackingID: "949B14C3"

Summary: "HTTP proxy does not work on port 443"

Description: "If we configure the target to use http proxy with port 443 it does not go online, while it works with port 80. Do you have any suggestion?"

ProductID: 1

TypeID: 2

FileName: "949B14C3"

StatusNotification: 1

SupportComments: "A corresponding email has been sent."

StatusID: 2

CustomerID: 73

Language: "en"

CreationDate: "2013-09-04 11:06:03"

LastUpdated: "2013-10-16 11:52:06"

97F9B942

TrackingID: "97F9B942"

Summary: "Teamviewer for win8.1 enterprise infection"

Description: "Dear Armend,\r\n\r\nWe have set up a test system with windows 8.1 enterprise 64 bit and a Teamviever on it \r\nThe Teamviewer ID: 556 716 796, password: 4092\r\nWe are online from now.\r\n\r\nRegards,\r\n\r\nZoltan"

ProductID: 1

TypeID: 2

FileName: "97F9B942"

StatusNotification: 1

SupportComments: "The Windows 8.1 Infection bug has been fixed with the 4.50 Release."

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2013-11-25 10:35:58"

LastUpdated: "2014-04-23 09:01:31"

AF7FB10B

TrackingID: "AF7FB10B"

Summary: "Cannot update."

Description: "Hello I tried to update finspy master to 4.40 but connection to server failed.\r\nAfter it I check this:\r\nnmap -PN -p 42662 update.gamma-international.de\r\nbut port 42662 closed.\r\n\r\nDo you use other port to update now?"

ProductID: 1

TypeID: 2

FileName: "AF7FB10B"

StatusNotification: 1

SupportComments: ""

StatusID: 2

CustomerID: 73

Language: "en"

CreationDate: "2013-09-04 11:39:06"

LastUpdated: "2013-10-16 11:51:53"

C4B617D5

TrackingID: "C4B617D5"

Summary: "agent creation , new install"

Description: "Dear Martin,\r\n\r\nToday the Lenovo e520 laptop you had given us had died. \r\n\r\nSince we were/are in a hurry we pulled out the HDD and switched it into another Lenovo but L420 laptop. Windows7 started, we reinstalled the graphic drivers and chipset drivers also. The Agent is OK, we see and can connect to our running targets, but we cannot create new infections neither CD nor USB. \r\n\r\nWe reinstalled the Agent and updated the windows7 but it still doesn t work, it cannot create infections. Ill attach a screenshot.\r\n\r\nIn the meantime we started a fresh windows7 install on another laptop, but got another error.\r\nWe installed all the necessary components also such as Slim, Opencodecs, dotNet etc.\r\n\r\nDo you have any idea what should we do?\r\n\r\nbest regards,\r\n\r\nZoltan"

ProductID: 1

TypeID: 3

FileName: "C4B617D5.pdf"

StatusNotification: 1

SupportComments: "

An corresponding email has been send.

"

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2013-09-25 15:18:46"

LastUpdated: "2013-09-27 06:35:37"

CD2F8889

TrackingID: "CD2F8889"

Summary: "voip differences"

Description: "Dear Support Team,\r\n\r\nId like to ask you about the differences of VOIP and VOIP Lite modules.\r\n\r\nRegards,"

ProductID: 1

TypeID: 5

FileName: "CD2F8889"

StatusNotification: 1

SupportComments: "

Dear Customer, <br /><br />please be informed that an suitable mail has been sent to <br />the email address: balogh.peter@nbsz.gov.hu<br /><br />Please see the mail below:<br /><br /><br />Dear Customer, 

\r\n

\r\n

*TrackingID:* CD2F8889 *Related Product:* FinSpy *Request Type:* New Feature *Summary:* voip differences *Description:* Dear Support Team, Id like to ask you about the differences of VOIP and VOIP Lite modules. 

\r\n

please be informed that the only difference between Voip and the Voip Lite module is that the voip Lite does not support screen capture when a call is started, but the Voip Module does.

If you have further questions, please do not hesitate to contact us.

Best regards,\r\n

<br />

"

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2013-11-12 13:34:53"

LastUpdated: "2013-11-13 14:45:13"

D8179365

TrackingID: "D8179365"

Summary: "errors"

Description: "Hello ! \r\nAfter the update, we tried some operation system WIN8 and WIN8.1, and we got back an error codes 1-7. We tried with ubuntu 12.04 too with Dell Latitude E6400.\r\nWe tried with Macbook Air 10.9.1 too, and the error codes were same.\r\nAnd sometimes it wrote to the desktop the methods were successful, but it werent. \r\nOn Win7 sometimes it works, sometimes it is not. We tried more time.\r\nPlease send a help.\r\nThank you."

ProductID: 12

TypeID: 3

FileName: "D8179365"

StatusNotification: 1

SupportComments: "

\r\n<pre>\r\n<pre>An corresponding email has been sent.

\r\n\r\n"

StatusID: 4

CustomerID: 73

Language: "en"

CreationDate: "2014-02-21 13:57:20"

LastUpdated: "2014-05-22 09:33:06"

DA9DB40D

TrackingID: "DA9DB40D"

Summary: "win8"

Description: "Dear Armend,\r\n\r\nWe did what you said during the TeamViewer session, infected and rebooted 3 times, and it never connected to the relay server.\r\nWhen you tried to help us, we had seen that you transfered a zip file after an exe. What was the difference with the zip you extracted? At first the exe didnt work for you either, and than you brought the zipped exe.\r\nWe waited an hour browsing the internet, rebooted and it doesnt connect to the relay.\r\nWe also created a skype account which is: lego256976@gmail.com, I took finsupport1 up.\r\n\r\nRegards,\r\n\r\nZoltan\r\n"

ProductID: 1

TypeID: 2

FileName: "DA9DB40D"

StatusNotification: 1

SupportComments: "A corresponding email has been sent"

StatusID: 2

CustomerID: 73

Language: "en"

CreationDate: "2013-11-25 17:07:21"

LastUpdated: "2013-12-11 11:03:26"

EB0557E1

TrackingID: "EB0557E1"

Summary: "Webcam does not work"

Description: "The webcam of HP Pavilion dv6 laptop did not work. The led of cam flashed once and thats all.\r\nWe have finspy 4.21\r\nThe operating system is Windows 7 64bit ultimate.\r\nThe case of other laptop which is Lenovo L420 the module did not work also.\r\nAfter one picture the module crashed, and generate a popup window on target - chose a video source - .\r\nSystem was 32bit windowns"

ProductID: 1

TypeID: 2

FileName: "EB0557E1"

StatusNotification: 1

SupportComments: ""

StatusID: 2

CustomerID: 73

Language: "en"

CreationDate: "2012-12-07 11:28:42"

LastUpdated: "2012-12-10 12:25:40"

Feedback

18

ID: 18

FirstName: "Peter"

To: "support@gamma-international.de"

Subject: "New release"

Description: "Hi,\r\n\r\nHow can I get the new, 4.30 release?\r\n\r\nRegards,\r\nPeter"

Language: "en"

CustomerID: 73

Timestamp: "2013-03-12 09:15:46"