parent
305ac2105c
commit
d5250b6d0d
@ -1,19 +1,6 @@
|
||||
# amlegit
|
||||
|
||||
reverse engineering of amlegit/xcheats.cc
|
||||
reverse engineering of amlegit/xcheats.cc this p2c sells an internal Apex cheat. Apex is protected by EAC and by the looks of this cheat/spoofer It doesnt even come
|
||||
remotely close to something that can evade a ban.
|
||||
|
||||
## overview
|
||||
|
||||
amlegit.com/xcheats.cc sell the same cheat. As of 2/15/2020 the cheat has been released as "free" whilst selling almost the same pasted software. In short the loader works as so:
|
||||
|
||||
<img src="https://git.hacks.ltd/xerox/amlegit/raw/master/images/amlegit_diagram.png"/>
|
||||
|
||||
The internal DLL is anything but undetected. Memory is not hidden, many imports, threads, directly hooking present function....
|
||||
|
||||
<img src="https://git.hacks.ltd/xerox/amlegit/raw/master/images/lapex_imports.png"/>
|
||||
|
||||
The spoofer is clearly pasted:
|
||||
|
||||
<img src="https://git.hacks.ltd/xerox/amlegit/raw/master/images/spoofer_paste.png"/>
|
||||
|
||||
<img src="https://git.hacks.ltd/xerox/amlegit/raw/master/images/nsiproxy_paste.PNG"/>
|
||||
This cheat is a blatant paste of [kdmapper](url) and [hwid spoofer](https://github.com/btbd/hwid).
|
||||
|
Loading…
Reference in new issue