𝐁-𝐓𝐈𝐊 𝐌𝐎𝐃𝐒 𝐋𝐄𝐀𝐑𝐍𝐈𝐍𝐆🧑💻🌍🚀🏙
الذهاب إلى القناة على Telegram
HATERS FUXK U AND UR DREAMS TO PUT ME DOWN , GO FUXKK UR SELF CHAT GROUP :-- @btikmodslearningchat https://telegra.ph/DISCLAIMER-02-27-35 https://telegra.ph/Disclaimer-11-25-17 https://telegra.ph/Dont-support-any-illegal-activities-06-28
إظهار المزيد1 024
المشتركون
+324 ساعات
+197 أيام
+6730 أيام
أرشيف المشاركات
Repost from EXPLOIT ACADEMY
I am deleting this channel, so save everything you have within half an hour. After this, you will never see the exploit academy channel again.
T H A N K. Y O U
DON'T ASK RESONS 😌
Repost from 𝙓𝙄𝙉𝙊𝙓 𝙓𝙍
-------------------------------------------------- [>] LEAK BY : @Stark8xi [>] PROJECT : Epstein_gd v2
--------------------------------------------------
[>] CREDIT : @Stark8xi
[>] CHANNEL : https://t.me/XINOXXR
[>] CHANNEL : https://t.me/sentry9x
--------------------------------------------------
[!] WARNING : Please don't remove my credit 💀
[!] NOTICE : For Educational Use Only
--------------------------------------------------
[>] PASS : https://t.me/XINOXXR
--------------------------------------------------Give the ff version of which you want anogs and other libs analyzation ok Send me the ffm or ff apk in dm ok 👍 @btikmodslearningownerr Send fast ok guyzz today I'll work on it and give you results then u all make bypass of it ok guyzz Give apk and max reactions
NOP: C0 03 5F D6 (RET)
=====================================================================
END OF LIST - 30 FUNCTIONS + GLOBALS + STRINGS
=====================================================================
`
share with credits or else you are gay , haha
join for more :-- @btikmodslearningg=====================================================================
FUNCTION 23: fcn.001b25bc
=====================================================================
RVA: 0x001b25bc
Purpose: REAL report generator - called by AnoSDKGetReportData
Patch: Early return 0
=====================================================================
FUNCTION 24: fcn.001b5ae0
=====================================================================
RVA: 0x001b5ae0
Purpose: Report builder - called by AnoSDKGetReportData3
Patch: Early return 0
=====================================================================
FUNCTION 25: fcn.001bca14
=====================================================================
RVA: 0x001bca14
Purpose: Report generator v4 - called by AnoSDKGetReportData4
Patch: Early return 0
=====================================================================
FUNCTION 26: fcn.004c0af4
=====================================================================
RVA: 0x004c0af4
Purpose: Network receive wrapper - recvfrom + callback
Patch: Hook recvfrom / Block callback
=====================================================================
FUNCTION 27: fcn.00497184
=====================================================================
RVA: 0x00497184
Purpose: Buffer write with overflow checking
Patch: Hook to block writes
=====================================================================
FUNCTION 28: fcn.0023da48
=====================================================================
RVA: 0x0023da48
Purpose: Linked list add - stores anti-cheat data
Patch: Hook to block additions
=====================================================================
FUNCTION 29: fcn.002d0140
=====================================================================
RVA: 0x002d0140
Purpose: String copy with max 32 chars
Patch: Hook to log/corrupt
=====================================================================
FUNCTION 30: fcn.004e0ff8
=====================================================================
RVA: 0x004e0ff8
Purpose: Anti-cheat state management + debugger detection
Patch: Always return false
=====================================================================
INTERNAL FUNCTION: fcn.001ba124
=====================================================================
RVA: 0x001ba124
Purpose: Called by AnoSDKInit - internal initialization
Patch: NOP call
=====================================================================
INTERNAL FUNCTION: fcn.004b62e4
=====================================================================
RVA: 0x004b62e4
Purpose: Encryption/obfuscation setup
Patch: NOP call
=====================================================================
INTERNAL FUNCTION: fcn.004d8360
=====================================================================
RVA: 0x004d8360
Purpose: Logging function - prints anti-cheat logs
Patch: NOP / Suppress
=====================================================================
GLOBAL DATA ADDRESSES
=====================================================================
0x50f5a8 → Entry point function pointer
0x50ec30 → Function pointer for AnoSDKGetReportData2
0x50ebe8 → Pointer source for AnoSDKGetReportData2
0x54fbd0 → Report buffer
0x54fbd2 → Report buffer 2
0x54fc60 → Report counter
0x55a088 → Network callback pointer
0x56911c → Mutex for thread safety
0x569144 → Condition variable for waiting
=====================================================================
RECOMMENDED PATCH BYTES (ARM64)
=====================================================================
Return 0: 00 00 80 D2 C0 03 5F D6 (MOV W0, #0; RET)
Return 1: 20 00 80 D2 C0 03 5F D6 (MOV W0, #1; RET)
=====================================================================
FUNCTION 12: AnoSDKIoctl
=====================================================================
RVA: 0x001c6e40
Size: 1264 bytes
Purpose: IO control operations - anti-cheat communication
Patch: Return 0 immediately
=====================================================================
FUNCTION 13: AnoSDKFree
=====================================================================
RVA: 0x001c7330
Size: 1332 bytes
Purpose: Free allocated resources
Patch: NOP entire function
=====================================================================
FUNCTION 14: AnoSDKGetReportData2
=====================================================================
RVA: 0x001c7864
Size: 108 bytes
Purpose: Report collection v2 - uses global function ptr
Real Func: Global pointer @ 0x50ec30
States: 0x5e3f88c, -0x591d808b, -0x1f96ec1b, -0x3138b4ec,
-0x207343f0, -0x47717616, -0x789ed605, -0x52fb3d62,
0x7d6e00e6, 0x43f9233d
Patch: Return 0 at 0x001c7864
=====================================================================
FUNCTION 15: AnoSDKGetReportData3
=====================================================================
RVA: 0x001c78d0
Size: 108 bytes
Purpose: Report collection v3 - calls fcn.001b5ae0
Real Func: fcn.001b5ae0
States: 0x53c22c4, 0x124a994, -0x5cc4f949, -0x3d969b3f,
0x2d918ee6, 0x2210b4c0, -0x21041361, -0x721110c1,
-0x37d87060, 0x1dc9dde5, -0x246e2c2c
Patch: Return 0 at 0x001c78d0
=====================================================================
FUNCTION 16: AnoSDKDelReportData3
=====================================================================
RVA: 0x001c793c
Size: 1568 bytes
Purpose: Delete/cleanup report data v3
Patch: NOP entire function
=====================================================================
FUNCTION 17: AnoSDKGetReportData4
=====================================================================
RVA: 0x001c7f5c
Size: 776 bytes
Purpose: Report collection v4 - calls fcn.001bca14
Real Func: fcn.001bca14
States: -0x6c068bc4, -0x199170d0, -0x17cc305d,
0x365ef1cd, 0x6dfc6b24
Patch: Early return 0 at 0x001c7f5c
=====================================================================
FUNCTION 18: AnoSDKDelReportData4
=====================================================================
RVA: 0x001c8264
Size: 1568 bytes
Purpose: Delete/cleanup report data v4
Patch: NOP entire function
=====================================================================
FUNCTION 19: AnoSDKOnRecvSignature
=====================================================================
RVA: 0x001c8884
Size: 904 bytes
Purpose: Receive and verify server signatures
Patch: Always return valid (1)
=====================================================================
FUNCTION 20: AnoSDKRegistInfoListener
=====================================================================
RVA: 0x001c8c0c
Size: 944 bytes
Purpose: Register information listener - monitors game events
Patch: NOP / Block registration
=====================================================================
FUNCTION 21: AnoSDKForExport
=====================================================================
RVA: 0x001c8fbc
Size: 108 bytes
Purpose: Export wrapper function
Patch: NOP entire function
=====================================================================
FUNCTION 22: JNI_OnLoad
=====================================================================
RVA: 0x001cb85c
Size: 580 bytes
Purpose: JNI initialization - loads Java bindings
Patch: Return 0 or NOP
`
=====================================================================
FREE FIRE - ANTI-CHEAT OFFSETS LIST
=====================================================================
Library: libanogs.so | Architecture: ARM64
=====================================================================
=====================================================================
FUNCTION 1: entry0
=====================================================================
RVA: 0x001b12c0
Purpose: Library entry point - trampoline to init function
Real Call: (**0x50f5a8)(segment.LOAD1)
Patch: NOP or overwrite pointer at 0x50f5a8
=====================================================================
FUNCTION 2: AnoSDKInit
=====================================================================
RVA: 0x001c37ac
Size: 812 bytes
Purpose: Main anti-cheat initialization
Real Call: fcn.001ba124() + fcn.004b62e4()
Patch: Early return 0 at function start
=====================================================================
FUNCTION 3: AnoSDKInitEx
=====================================================================
RVA: 0x001c3ad8
Size: 1596 bytes
Purpose: Extended anti-cheat initialization
Patch: Early return 0 at function start
=====================================================================
FUNCTION 4: AnoSDKSetUserInfo
=====================================================================
RVA: 0x001c4114
Size: 1028 bytes
Purpose: Device fingerprinting - collects user data
Patch: NOP entire function
=====================================================================
FUNCTION 5: AnoSDKSetUserInfoWithLicense
=====================================================================
RVA: 0x001c4518
Size: 1676 bytes
Purpose: User info with license validation
Patch: NOP entire function / Always return valid
=====================================================================
FUNCTION 6: AnoSDKOnPause
=====================================================================
RVA: 0x001c4ba4
Size: 1060 bytes
Purpose: Called when app goes background - triggers checks
Patch: NOP entire function
=====================================================================
FUNCTION 7: AnoSDKOnResume
=====================================================================
RVA: 0x001c4fc8
Size: 1260 bytes
Purpose: Called when app resumes - reinitializes checks
Patch: NOP entire function
=====================================================================
FUNCTION 8: AnoSDKGetReportData
=====================================================================
RVA: 0x001c54b4
Size: 1388 bytes
Purpose: PRIMARY report collection - device info, root, debug
Real Func: fcn.001b25bc
States: -0x227367df, 0x6ba4f2d, -0x10e68180, -0x3f32e2c4,
-0x501721ad, 0x3a702cf2, -0x6fdff5ef, -0x489e39e6
Patch: Early return 0 at 0x001c54b4
=====================================================================
FUNCTION 9: AnoSDKDelReportData
=====================================================================
RVA: 0x001c5a20
Size: 1988 bytes
Purpose: Delete/cleanup report data after sending
Patch: NOP entire function
=====================================================================
FUNCTION 10: AnoSDKOnRecvData
=====================================================================
RVA: 0x001c61e4
Size: 844 bytes
Purpose: Receive data from server - processes responses
Patch: Hook & block / NOP entire function
=====================================================================
FUNCTION 11: AnoSDKIoctlOld
=====================================================================
RVA: 0x001c6530
Size: 2320 bytes
Purpose: Legacy IO control operations
Patch: Return 0 immediately// ============================================
case -0x59dfa0b9:
// CRITICAL CALL 3: Setup encryption/obfuscation
fcn.004b62e4(flag, 0);
state_val2 = 0xbed798bb;
state_val1 = 0xd6715301;
current_state = 0x68a6cbba; // Go to STATE 5
break;
// ============================================
// STATE 5: 0x68a6cbba (RETURN)
// ============================================
case 0x68a6cbba:
return; // Function exits successfully
// ============================================
// STATE 6: -0x7ad399fd (ERROR EXIT)
// ============================================
case -0x7ad399fd:
// If something went wrong, call with different args
fcn.004b62e4(flag, 0xffffffee);
return; // Function exits with error
}
}
}
/*
* =====================================================================
* KEY INSIGHTS:
* =====================================================================
*
* 1. O-LLVM FLATTENING: This function uses O-LLVM control flow flattening.
* The real logic is hidden inside a state machine. The state variable
* (current_state) determines which block executes.
*
* 2. fcn.001ba124(): This is called twice. It likely initializes internal
* structures or sets up the anti-cheat environment.
*
* 3. fcn.004b62e4(): This is the encryption/obfuscation setup function.
* It takes a flag and a parameter. The flag comes from arg1 being
* negative - this might indicate debug mode or special state.
*
* 4. MAGIC VALUES: The values 0x89f4, 0x3507, 0x3b40 are stored in
* stack variables. These are likely encryption keys or seeds.
*
* 5. PATCH OPPORTUNITY: The best patch is to replace the first few
* instructions with "MOV W0, #0; RET" - this makes the function
* return immediately without initializing anything.
*
* =====================================================================
*/
void AnoSDKInit(int64_t arg1)
{
// ========== LOCAL VARIABLES ==========
uint32_t temp1; // uVar1 - Temporary arithmetic value
uint32_t temp2; // uVar2 - Temporary arithmetic value
uint *stack_ptr; // puVar3 - Stack pointer
uint state_val1; // uStack_7c - State value 1
uint state_val2; // uStack_78 - State value 2
int current_state; // iStack_74 - CURRENT STATE MACHINE STATE
uint32_t *ptr1; // puStack_70 - Pointer 1
uint32_t *ptr2; // puStack_68 - Pointer 2
uint *ptr3; // puStack_60 - Pointer 3
uint8_t flag; // uStack_51 - Condition flag
// ========== INITIALIZATION ==========
stack_ptr = auStack_80; // Point to stack buffer
current_state = -0x15a25ce7; // START STATE
// ========== STATE MACHINE LOOP ==========
while (true)
{
switch (current_state)
{
// ============================================
// STATE 1: -0x15a25ce7 (INITIALIZATION)
// ============================================
case -0x15a25ce7:
// Setup stack pointers
ptr1 = stack_ptr - 4; // Allocate 4 bytes
ptr2 = stack_ptr - 8; // Allocate 8 bytes
stack_ptr = stack_ptr - 12; // Allocate 12 bytes
ptr3 = stack_ptr;
// Store magic values in stack
*ptr1 = 0x89f4; // Store 0x89f4
temp1 = *ptr1; // Read back
*ptr2 = 0x3507; // Store 0x3507
temp2 = *ptr2; // Read back
// Set up state values (obfuscation)
state_val2 = 0x3b3e5711;
state_val1 = 0x9baff5db;
// COMPLEX ARITHMETIC CONDITION (Obfuscation)
// This check is meaningless - just obfuscation
// It decides which state to go to next
if ((temp2 | ~temp1) + (temp1 & temp2) +
(temp1 & ~temp2) + 1 == (temp1 & temp2))
{
current_state = -0x1411a7cc; // Go to STATE 2
}
else
{
current_state = -0x5f6e5d36; // Go to STATE 3
}
break;
// ============================================
// STATE 2: -0x1411a7cc (CALL REAL INIT)
// ============================================
case -0x1411a7cc:
// CRITICAL CALL 1: Initialize something
fcn.001ba124(arg1 & 0xFFFFFFFF);
state_val2 = 0x36aba38e;
state_val1 = 0x963a0144;
current_state = -0x5f6e5d36; // Go to STATE 3
break;
// ============================================
// STATE 3: -0x5f6e5d36 (CALL REAL INIT 2)
// ============================================
case -0x5f6e5d36:
// CRITICAL CALL 2: Initialize something again
fcn.001ba124(arg1 & 0xFFFFFFFF);
// Set flag based on arg1 being negative
flag = (arg1 < 0);
// Store magic value
*ptr3 = 0x3b40;
state_val1 = 0x7e26f042;
state_val2 = 0xd806af05;
current_state = -0x59dfa0b9; // Go to STATE 4
break;
// ============================================
// STATE 4: -0x59dfa0b9 (ENCRYPTION SETUP)
/*
* =====================================================================
* FUNCTION: AnoSDKInit
* OFFSET: 0x001c37ac
* SIZE: 812 bytes
* LIBRARY: libanogs.so
* =====================================================================
*
* PURPOSE:
* --------
* This is the MAIN ANTI-CHEAT INITIALIZATION function. It sets up
* everything needed for the anti-cheat system to run, including:
* - Encryption/obfuscation setup
* - State initialization
* - Memory allocation
*
* ARGUMENTS:
* ----------
* arg1 (int64_t) → Game context / user data
* This is passed from the game when it calls the SDK
*
* RETURN VALUE:
* -------------
* None (void)
*
* =====================================================================
* FLOW DIAGRAM:
* =====================================================================
*
* ┌─────────────────────┐
* │ AnoSDKInit() │
* │ arg1 = context │
* └──────────┬──────────┘
* │
* ▼
* ┌─────────────────────┐
* │ SETUP STACK │
* │ Initialize local │
* │ variables │
* └──────────┬──────────┘
* │
* ▼
* ┌───────────────────────────────────┐
* │ STATE: -0x15a25ce7 (INIT) │
* │ Store magic values: │
* │ - *puStack_70 = 0x89f4 │
* │ - *puStack_68 = 0x3507 │
* │ Check arithmetic condition │
* │ If true → STATE -0x1411a7cc │
* │ If false → STATE -0x5f6e5d36 │
* └──────────────────┬────────────────┘
* │
* ┌─────────────────┴─────────────────┐
* │ │
* ▼ ▼
* ┌────────────────────────────┐ ┌────────────────────────────┐
* │ STATE: -0x1411a7cc │ │ STATE: -0x5f6e5d36 │
* │ (CALL REAL INIT) │ │ (CALL REAL INIT 2) │
* │ │ │ │
* │ Call fcn.001ba124(arg1) │──▶│ Call fcn.001ba124(arg1) │
* │ │ │ Set flag = arg1 < 0 │
* │ Next: -0x5f6e5d36 │ │ Next: -0x59dfa0b9 │
* └────────────────────────────┘ └────────────────────────────┘
* │
* ▼
* ┌────────────────────────────┐
* │ STATE: -0x59dfa0b9 │
* │ (ENCRYPTION SETUP) │
* │ │
* │ Call fcn.004b62e4(flag,0) │
* │ │
* │ Next: 0x68a6cbba │
* └────────────────────────────┘
* │
* ▼
* ┌────────────────────────────┐
* │ STATE: 0x68a6cbba │
* │ (RETURN) │
* │ │
* │ return │
* └────────────────────────────┘
*
* =====================================================================
* PSEUDOCODE:
* =====================================================================
*/
wow reactions pe reactions i like that, give these type of supports and get paid things for free here👽🗿😮💨
Koi amir banda 1 star peldo👽
One rich person gift 1 star to this channel👽
and i have more do you all want more of this informations to make bypass? on your own??
spam reactions and also gift 1 star to this channel rich peoples🥲
=====================================================================
FREE FIRE - ANALYZED ANTI-CHEAT OFFSETS ( remember this is made by btikk)
share with credits or else your religion is gay
=====================================================================
Library: libanogs.so
Architecture: ARM64 (aarch64)
Date: [Current]
=====================================================================
NOTE: Only functions that have been fully analyzed via pseudocode
breakdown are included in this file.
=====================================================================
FUNCTION 1: AnoSDKGetReportData
=====================================================================
OFFSET: 0x001c54b4
SIZE: 1388 bytes (0x56C)
TYPE: GLOBAL FUNC
LIBRARY: libanogs.so
REAL FUNCTION: fcn.001b25bc
PURPOSE:
Primary report data collection function.
Collects device information, root status, debug flags,
memory scans, and prepares report for server.
STATE MACHINE (O-LLVM Flattened):
-0x227367df → INITIALIZATION (Setup stack pointers)
0x6ba4f2d → SETUP (Call fcn.004b62e4 encryption init)
-0x10e68180 → ARITHMETIC (Obfuscated math operations)
-0x3f32e2c4 → CONDITION (Check arithmetic result)
-0x501721ad → BRANCH (Decide call or skip)
0x3a702cf2 → CALL REAL (fcn.001b25bc)
-0x6fdff5ef → SKIP (Bypass real function)
-0x489e39e6 → RETURN (Return report data)
REAL CALL:
fcn.001b25bc() at state 0x3a702cf2
RETURN VALUE:
uStack_68 - Report data from fcn.001b25bc()
WORKING:
1. Initializes stack and pointers
2. Calls fcn.004b62e4(1,4) for encryption setup
3. Performs obfuscated arithmetic (no real logic)
4. Checks condition flag
5. If flag = 1 → calls fcn.001b25bc() to generate report
6. If flag = 0 → skips to return
7. Returns report data
PATCH METHOD:
Option 1: Early return at function start
Option 2: Patch state -0x6fdff5ef to always skip
Option 3: NOP the call to fcn.001b25bc
RECOMMENDED PATCH:
Replace first instructions at 0x001c54b4 with:
MOV W0, #0
RET
(Hex: 00 00 80 D2 C0 03 5F D6)
=====================================================================
FUNCTION 2: AnoSDKGetReportData2
=====================================================================
OFFSET: 0x001c7864
SIZE: 108 bytes (0x6C)
TYPE: GLOBAL FUNC
LIBRARY: libanogs.so
REAL FUNCTION: Global function pointer @ 0x50ec30
PURPOSE:
Report data collection version 2.
Uses a global function pointer to generate report data.
STATE MACHINE (O-LLVM Flattened):
0x5e3f88c → MAIN (Get pointer from 0x50ebe8)
-0x591d808b → CHECK (Check if pointer valid)
-0x1f96ec1b → SETUP PTR (Get func ptr from 0x50ec30)
-0x3138b4ec → CALL REAL ((**(*func_ptr + 0x28))(func_ptr))
-0x207343f0 → INIT BUFFER (Setup 0x54fbd0)
-0x47717616 → STORE (*0x54fbd0 = *ptr1, counter++)
-0x789ed605 → READ (Check *ptr1 < 0x81)
-0x52fb3d62 → PREPARE RETURN (uStack_98 = uStack_90)
0x7d6e00e6 → RETURN (return uStack_98)
0x43f9233d → LOG (fcn.004d8360 log)
REAL CALL:
(**(*func_ptr + 0x28))(func_ptr)
Where func_ptr = **0x50ec30
RETURN VALUE:
uStack_98 - Report data from global function
WORKING:
1. Gets pointer from **0x50ebe8
2. Checks if valid
3. Gets function pointer from **0x50ec30
4. Calls function at offset 0x28 of that pointer
5. Stores result in global buffer at 0x54fbd0
6. Increments counter at 0x54fc60
7. Returns report data
GLOBAL DATA ADDRESSES:
0x54fbd0 → Report buffer
0x54fbd2 → Report buffer 2
0x54fc60 → Report counter
0x50ec30 → Function pointer
0x50ebe8 → Pointer source
PATCH METHOD:
Option 1: Return 0 at function start
Option 2: NOP the call to global function
Option 3: Patch the global pointer to point to dummy function
RECOMMENDED PATCH:
Replace first instructions at 0x001c7864 with:
MOV W0, #0
RET
(Hex: 00 00 80 D2 C0 03 5F D6)=====================================================================
FUNCTION 3: AnoSDKGetReportData3
=====================================================================
OFFSET: 0x001c78d0
SIZE: 108 bytes (0x6C)
TYPE: GLOBAL FUNC
LIBRARY: libanogs.so
REAL FUNCTION: fcn.001b5ae0
PURPOSE:
Report data collection version 3.
Makes multiple calls to fcn.001b5ae0 with different parameters.
STATE MACHINE (O-LLVM Flattened):
0x53c22c4 → INIT (Setup stack pointers)
0x124a994 → SETUP (Store magic values)
-0x5cc4f949 → ARITHMETIC (Obfuscated math)
-0x3d969b3f → CONDITION (Complex check)
0x2d918ee6 → BRANCH (Decide normal/alternate)
0x2210b4c0 → CALL SETUP (Store more values)
-0x21041361 → CALL REAL (fcn.001b5ae0(0x32,0,ptr1,0x3f,0))
-0x721110c1 → MORE SETUP (fcn.001b5ae0(0x25,0,ptr1,0,0))
-0x37d87060 → PREPARE RETURN (uStack_68 = *ptr1)
0x1dc9dde5 → RETURN (return uStack_68)
-0x246e2c2c → ALTERNATE PATH (fcn.001b5ae0(0x67,0,ptr1,0xffffffd7,0))
REAL CALL:
fcn.001b5ae0(0x32, 0, ptr1, 0x3f, 0)
fcn.001b5ae0(0x25, 0, ptr1, 0, 0)
fcn.001b5ae0(0x67, 0, ptr1, 0xffffffd7, 0) [Alternate path]
RETURN VALUE:
*ptr1 (uStack_68) - Data from buffer
WORKING:
1. Initializes stack and sets up pointers
2. Stores magic values (0x41c1, 0x9018, 0xbaa1)
3. Performs obfuscated arithmetic operations
4. Checks condition to decide normal or alternate path
5. Normal path:
a. Calls fcn.001b5ae0(0x32, 0, ptr1, 0x3f, 0)
b. Calls fcn.001b5ae0(0x25, 0, ptr1, 0, 0)
6. Alternate path:
a. Calls fcn.001b5ae0(0x67, 0, ptr1, 0xffffffd7, 0)
7. Returns data from ptr1 buffer
KEY PARAMETERS:
0x32 → First call parameter
0x25 → Second call parameter
0x67 → Alternate call parameter
0x3f → First call arg4
0xffffffd7 → Alternate call arg4FUNCTION 4: AnoSDKGetReportData4
OFFSET: 0x001c7f5c
REAL FUNCTION: fcn.001bca14
PURPOSE:
Report data collection version 4.
Direct call to fcn.001bca14 with arg1.
STATE MACHINE (O-LLVM Flattened):
-0x6c068bc4 → INIT (Store 0xe294 to ptr1, 0xf499 to ptr2)
-0x199170d0 → SETUP (Store 0xa61e to ptr3, 0x7f07 to ptr4)
-0x17cc305d → CALL (fcn.001bca14(arg1 & 0xFFFFFFFF))
0x365ef1cd → RETURN (return uStack_58)
0x6dfc6b24 → ALT RETURN (fcn.001bca14(arg1 & 0xFFFFFFFF))
REAL CALL:
fcn.001bca14(arg1 & 0xFFFFFFFF)
RETURN VALUE:
uStack_58 / uVar2 - Report data from fcn.001bca14
WORKING:
1. Sets up stack and pointer
2. Stores magic values (0xe294, 0xf499, 0xa61e, 0x7f07)
3. Calls fcn.001bca14(arg1 & 0xFFFFFFFF)
4. Returns result
ARGUMENT:
arg1 → Passed to real function as (arg1 & 0xFFFFFFFF)
PATCH METHOD:
Option 1: Early return at function start
Option 2: NOP the call to fcn.001bca14
Option 3: Return 0 directly
INTERNAL FUNCTIONS (Called by Above)
1. fcn.001b25bc
→ Called by: AnoSDKGetReportData
→ Purpose: Actual report data generator
→ Patch: Return 0 early
2. fcn.001b5ae0
→ Called by: AnoSDKGetReportData3
→ Purpose: Report builder with parameters
→ Patch: Return 0 early
3. fcn.001bca14
→ Called by: AnoSDKGetReportData4
→ Purpose: Report data generator v4
→ Patch: Return 0 early
GLOBAL DATA ADDRESSES
0x50ec30 → Function pointer for AnoSDKGetReportData2
0x50ebe8 → Pointer source for AnoSDKGetReportData2
0x54fbd0 → Report buffer
0x54fbd2 → Report buffer 2
0x54fc60 → Report counter
``
=====================================================================
FREE FIRE - ANALYZED ANTI-CHEAT OFFSETS
=====================================================================
Library: libanogs.so
Architecture: ARM64 (aarch64)
Date: [Current]
=====================================================================
NOTE: Only functions that have been fully analyzed via pseudocode
breakdown are included in this file.
=====================================================================
FUNCTION 1: AnoSDKGetReportData
=====================================================================
OFFSET: 0x001c54b4
SIZE: 1388 bytes (0x56C)
TYPE: GLOBAL FUNC
LIBRARY: libanogs.so
REAL FUNCTION: fcn.001b25bc
PURPOSE:
Primary report data collection function.
Collects device information, root status, debug flags,
memory scans, and prepares report for server.
STATE MACHINE (O-LLVM Flattened):
-0x227367df → INITIALIZATION (Setup stack pointers)
0x6ba4f2d → SETUP (Call fcn.004b62e4 encryption init)
-0x10e68180 → ARITHMETIC (Obfuscated math operations)
-0x3f32e2c4 → CONDITION (Check arithmetic result)
-0x501721ad → BRANCH (Decide call or skip)
0x3a702cf2 → CALL REAL (fcn.001b25bc)
-0x6fdff5ef → SKIP (Bypass real function)
-0x489e39e6 → RETURN (Return report data)
REAL CALL:
fcn.001b25bc() at state 0x3a702cf2
RETURN VALUE:
uStack_68 - Report data from fcn.001b25bc()
WORKING:
1. Initializes stack and pointers
2. Calls fcn.004b62e4(1,4) for encryption setup
3. Performs obfuscated arithmetic (no real logic)
4. Checks condition flag
5. If flag = 1 → calls fcn.001b25bc() to generate report
6. If flag = 0 → skips to return
7. Returns report data
PATCH METHOD:
Option 1: Early return at function start
Option 2: Patch state -0x6fdff5ef to always skip
Option 3: NOP the call to fcn.001b25bc
RECOMMENDED PATCH:
Replace first instructions at 0x001c54b4 with:
MOV W0, #0
RET
(Hex: 00 00 80 D2 C0 03 5F D6)
=====================================================================
FUNCTION 2: AnoSDKGetReportData2
=====================================================================
OFFSET: 0x001c7864
SIZE: 108 bytes (0x6C)
TYPE: GLOBAL FUNC
LIBRARY: libanogs.so
REAL FUNCTION: Global function pointer @ 0x50ec30
PURPOSE:
Report data collection version 2.
Uses a global function pointer to generate report data.
STATE MACHINE (O-LLVM Flattened):
0x5e3f88c → MAIN (Get pointer from 0x50ebe8)
-0x591d808b → CHECK (Check if pointer valid)
-0x1f96ec1b → SETUP PTR (Get func ptr from 0x50ec30)
-0x3138b4ec → CALL REAL ((**(*func_ptr + 0x28))(func_ptr))
-0x207343f0 → INIT BUFFER (Setup 0x54fbd0)
-0x47717616 → STORE (*0x54fbd0 = *ptr1, counter++)
-0x789ed605 → READ (Check *ptr1 < 0x81)
-0x52fb3d62 → PREPARE RETURN (uStack_98 = uStack_90)
0x7d6e00e6 → RETURN (return uStack_98)
0x43f9233d → LOG (fcn.004d8360 log)
REAL CALL:
(**(*func_ptr + 0x28))(func_ptr)
Where func_ptr = **0x50ec30
RETURN VALUE:
uStack_98 - Report data from global function
WORKING:
1. Gets pointer from **0x50ebe8
2. Checks if valid
3. Gets function pointer from **0x50ec30
4. Calls function at offset 0x28 of that pointer
5. Stores result in global buffer at 0x54fbd0
6. Increments counter at 0x54fc60
7. Returns report data
GLOBAL DATA ADDRESSES:
0x54fbd0 → Report buffer
0x54fbd2 → Report buffer 2
0x54fc60 → Report counter
0x50ec30 → Function pointer
0x50ebe8 → Pointer source
PATCH METHOD:
Option 1: Return 0 at function start
Option 2: NOP the call to global function
Option 3: Patch the global pointer to point to dummy function
RECOMMENDED PATCH:
Replace first instructions at 0x001c7864 with:
MOV W0, #0
RET
(Hex: 00 00 80 D2 C0 03 5F D6)=====================================================================
GLOBAL DATA ADDRESSES
=====================================================================
0x50ec30 → Function pointer for AnoSDKGetReportData2
0x50ebe8 → Pointer source for AnoSDKGetReportData2
0x54fbd0 → Report buffer
0x54fbd2 → Report buffer 2
0x54fc60 → Report counter
=====================================================================
SUMMARY TABLE
=====================================================================
FUNCTION | RVA | SIZE | REAL FUNCTION
-----------------------------|-----------|------|------------------
AnoSDKGetReportData | 0x001c54b4| 1388 | fcn.001b25bc
AnoSDKGetReportData2 | 0x001c7864| 108 | Global ptr @ 0x50ec30
AnoSDKGetReportData3 | 0x001c78d0| 108 | fcn.001b5ae0
AnoSDKGetReportData4 | 0x001c7f5c| 776 | fcn.001bca14
=====================================================================
RECOMMENDED PATCH BYTES (ARM64)
=====================================================================
Return 0:
00 00 80 D2 C0 03 5F D6
(MOV W0, #0; RET)
Return 1:
20 00 80 D2 C0 03 5F D6
(MOV W0, #1; RET)
NOP / Skip:
C0 03 5F D6
(RET)
=====================================================================
END OF FILE
=====================================================================ˋˋˋ
