reverse engineering of amlegit/xcheats.cc
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
xerox 305ac2105c
Add LICENSE
5 years ago
ida_pages Paste V1.1 5 years ago
images Paste V1.1 5 years ago
LICENSE Add LICENSE 5 years ago
README.md Update README.md 5 years ago
buffer_dump.dll Paste V1.1 5 years ago
buffer_dump.i64 Paste V1.1 5 years ago
driver.sys Paste V1.1 5 years ago
driver.sys.i64 Paste V1.1 5 years ago
inject_dump.dll Paste V1.1 5 years ago
inject_dump.i64 Paste V1.1 5 years ago
lapex.dll Paste V1.1 5 years ago
lapex.dll.i64 Paste V1.1 5 years ago
llauncher_dump.exe Paste V1.1 5 years ago
llauncher_dump.i64 Paste V1.1 5 years ago
mmap_dump.dll Paste V1.1 5 years ago
mmap_dump.i64 Paste V1.1 5 years ago

README.md

amlegit

reverse engineering of amlegit/xcheats.cc

overview

amlegit.com/xcheats.cc sell the same cheat. As of 2/15/2020 the cheat has been released as "free" whilst selling almost the same pasted software. In short the loader works as so:

The internal DLL is anything but undetected. Memory is not hidden, many imports, threads, directly hooking present function....

The spoofer is clearly pasted: