Modul๐Ÿ…พ๏ธs #AntiRetardModules
968 subscribers
67 photos
3 videos
2 files
22 links
Dedicated to expose retardation in modules.

By @Rem01Gaming
Download Telegram
Reverse Engineer of Magisk Module "PHEONIX PRO GAMING"

This shit easily became the most scummy module I ever came across, and the fact this module is literally selling for $50 makes it more ridiculous. I feel bad for the ones that bought this thing.


The module was leaked by someone that just bought this module, he came to my pm and asked me to RE this module to see what's going inside the module.
๐Ÿคฎ4
My first thing that comes to my mind is how ridiculous the price was for a literal gayming module that is probably worth half of your phone you probably used to read this, and how even gayming lunatics/idiots can buy this thing?

I meant 50 dollars for a gayming module? There are a lot of free alternatives out there that probably perform better than this shit such as Encore Tweaks.

I'm curious about how good this module is since it was $50, I go ahead and look into the module.
๐Ÿคฃ3
First this I see is the service script, and immediately I spot some missing variables here, $config and $MODPATH. Although $MODPATH is declared automatically by Magisk/KSU/AP when module installation, this is not the case with the late_start service script.

The shebang is also wrong as you can see it's system/sh instead of /system/bin/sh.

The service script itself only does setprop spectrum props. Just looking into the service script we know the script kiddie that creates this bs doesn't know shit and only cares about money.
๐Ÿคฃ2
The next is the "phx" folder, inside it it contains an executable called phx and when I run the file command to see what format it is, I'm shocked.

HOW THIS IDIOT THOUGHT THAT EXECUTABLES FOR LINUX CAN WORK ON ANDROID?

Wait doesn't Android is based on Linux?


It is based on the Linux kernel but other than that it's very different from Linux distros such as Ubuntu. Android uses musl libc while Linux distros uses GNU libc, both are not compatible with each other and hence this shit won't be able to run in Android.

This means, this fancy $50 module is just a placebo and scam. This also confirms my suspicion that this module has never been tested before it's actually bought and used by the user.
๐Ÿ”ฅ3๐Ÿคฃ1
The executable itself is not a compiled language that you may expect such as C or C++, but rather it was a shell script obfuscated with SHC (Shell Script Compiler). Let's assume the idiot that sells this shit obfuscates this script and just uses regular Linux GCC ARM64 to compile it.

It's easily detectable since SHC has unique strings on its executables.

E: neither argv[0] nor $_ works.


SHC itself can be easily deobfuscated using tools like Unshell, but since this shit was made for Linux, I have to create a Linux chroot container on my phone just to deobfuscate this script.

Even though I know this shit will not work at all, I decided to deobfuscate the script anyway. I'm curious, what is this thing doing under the hood.
โค2
phx
36.7 KB
This is the deobfuscated version of the phx script, the serial number is removed for the user's privacy and safety.

Some take on this script:
- Copy paste everywhere
- Hardcoded values everywhere
- No shfmt, horrible indentation
- Use a 16 year old governor named "interactivex"
๐Ÿ’ฉ3๐Ÿ”ฅ2๐Ÿ–•2
Autistic module just got an update ๐Ÿ‘…

So takes from this update:

- No more downloading ๐Ÿ”‘๐Ÿ“ฆ from the cloud and instead ship it directly on the zip as "bin.so" (I still wondering why she have to encode this if it will decoded in tricky store dir anyway?)
- Massive debloat of Termux ROOTFS from 80 TONS to 5 TONS ๐Ÿ‘…โœ…
- Additional untested vibe coded WebUI ๐Ÿ˜ญ๐Ÿคฎ๐Ÿคฎ


The JavaScript for KSU exec is questionable at best like how TF useragent contains MMRL's package name?????

Not only this "compatibility" check was not required (MMRL have the same API as KSU) it's blatantly wrong and AI generated code at best ๐Ÿ”ฅ๐Ÿ—‘๏ธ๐Ÿšฎ
๐Ÿ˜ฑ14โค1๐Ÿ‘1
You may be wondering why shamiko stuck in whitelist mode?

It's because you're installed that Meow-Autistic module
๐Ÿ’ฉ21๐Ÿคฃ6
logd is killed by Meow-Autistic module, a new root detection point.

Nice
๐Ÿฅฐ8๐Ÿคฎ7๐Ÿ˜4๐Ÿ‘2
Yang namanya putraxitersz mana yah ๐Ÿ˜๐Ÿ˜๐Ÿ˜
Module kamu cantik betul pgn ku cipok ๐Ÿ’‹๐Ÿ’‹๐Ÿ’‹
๐Ÿฅฐ4๐Ÿ˜ฑ2๐Ÿ˜1๐Ÿ’ฉ1
Oh yes I forgot to say something, since this new channel was created over the old one that was already killed by telegram, I won't share any files here which telegram may find violating its TOS.

All posts here are just screenshot of proof of gimmicks and some yapping, if you want to get the file, we will provide it in the group or other links later.

EDIT: https://t.me/+72Luw2utc3U2MjFl
๐Ÿ”ฅ5๐Ÿ‘3๐Ÿคฎ1๐Ÿ’ฉ1
๐Ÿ’ฅ OPEN JASA DECRYPT/ENCRYPT SHELL SCRIPT

๐Ÿ”ฅ DEOBFUSCATE SHELL SCRIPT
๐ŸŽญ ENCRYPT SHELL SCRIPT
โšก๏ธ HARGA MULAI DARI 15K*

โžก๏ธ Langsung PM Admin @Rem01Gaming

*Harga jasa sesuai situasi & kondisi
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ’ฉ22๐Ÿคฎ7โค2๐Ÿ‘2
Modul๐Ÿ…พ๏ธs #AntiRetardModules
logd is killed by Meow-Autistic module, a new root detection point. Nice
Heya! A PoC detection for Meowna module is ready, will publish it very soon ๐Ÿ‘…๐Ÿ‘…๐Ÿ‘…
๐Ÿ˜7๐Ÿคฎ2๐Ÿ’ฉ2๐Ÿ”ฅ1
Introducing The Meowna Detector!

A prove-of-concept of fatal blunder on the Integrity Box module by Meownaโ€”a root-hiding module that spectacularly backfires by killing logd (Androidโ€™s logger daemon).

Integrity Box promises Strong Play Integrity ๐ŸŸข๐ŸŸข๐ŸŸข and root hiding, while in the reality this module isn't more than vibe coded project with one massive blunder which is killing logd.

There's no reason whatsoever to include a kill logger into a root hiding module or any modules since this was futile meant it will cause root detection. The irony was this module was supposed to hide root but actually opened a new root detection itself.

If you have installed any module by Meowna remove it immediately since it was useless. Everything that the module does is configurate things that you can do yourself.

BOYCOTT MEOWNA TOGETHER WITH IT'S MODULES!

๐Ÿ”— https://github.com/Rem01Gaming/meowna_detector
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ˜26๐Ÿคฎ11๐Ÿ‘5๐Ÿฅฐ2
Forwarded from ๐— ๐—˜๐—ข๐—ช๐—ป๐—ฎ ๐Ÿ’…
Bro wants attention maybe for some subscribers for his dead project & channel
๐Ÿคฃ45๐Ÿ’ฏ2๐Ÿ‘1๐Ÿฅฐ1
This media is not supported in your browser
VIEW IN TELEGRAM
โค1๐Ÿ‘1
Modul๐Ÿ…พ๏ธs #AntiRetardModules
Huh? My lsposed fine without killing logd ๐Ÿฆ
I don't understand, why you would close a detection with another detection loophole?
๐Ÿ’ฏ15