ar
Feedback
𝐁-𝐓𝐈𝐊 𝐌𝐎𝐃𝐒 𝐋𝐄𝐀𝐑𝐍𝐈𝐍𝐆🧑‍💻🌍🚀🏙

𝐁-𝐓𝐈𝐊 𝐌𝐎𝐃𝐒 𝐋𝐄𝐀𝐑𝐍𝐈𝐍𝐆🧑‍💻🌍🚀🏙

الذهاب إلى القناة على Telegram
1 024
المشتركون
+324 ساعات
+197 أيام
+6730 أيام
أرشيف المشاركات
Repost from EXPLOIT ACADEMY
I am deleting this channel, so save everything you have within half an hour. After this, you will never see the exploit academy channel again. T H A N K. Y O U DON'T ASK RESONS 😌

-------------------------------------------------- [>] LEAK BY   : @Stark8xi [>] PROJECT   : Epstein_gd v2
-------------------------------------------------- [>] CREDIT    : @Stark8xi [>] CHANNEL   : https://t.me/XINOXXR [>] CHANNEL   : https://t.me/sentry9x -------------------------------------------------- [!] WARNING   : Please don't remove my credit 💀 [!] NOTICE    : For Educational Use Only -------------------------------------------------- [>] PASS : https://t.me/XINOXXR --------------------------------------------------

Give the ff version of which you want anogs and other libs analyzation ok Send me the ffm or ff apk in dm ok 👍 @btikmodslearningownerr Send fast ok guyzz today I'll work on it and give you results then u all make bypass of it ok guyzz Give apk and max reactions

NOP: C0 03 5F D6 (RET) ===================================================================== END OF LIST - 30 FUNCTIONS + GLOBALS + STRINGS ===================================================================== ` share with credits or else you are gay , haha join for more :-- @btikmodslearningg

===================================================================== FUNCTION 23: fcn.001b25bc ===================================================================== RVA: 0x001b25bc Purpose: REAL report generator - called by AnoSDKGetReportData Patch: Early return 0 ===================================================================== FUNCTION 24: fcn.001b5ae0 ===================================================================== RVA: 0x001b5ae0 Purpose: Report builder - called by AnoSDKGetReportData3 Patch: Early return 0 ===================================================================== FUNCTION 25: fcn.001bca14 ===================================================================== RVA: 0x001bca14 Purpose: Report generator v4 - called by AnoSDKGetReportData4 Patch: Early return 0 ===================================================================== FUNCTION 26: fcn.004c0af4 ===================================================================== RVA: 0x004c0af4 Purpose: Network receive wrapper - recvfrom + callback Patch: Hook recvfrom / Block callback ===================================================================== FUNCTION 27: fcn.00497184 ===================================================================== RVA: 0x00497184 Purpose: Buffer write with overflow checking Patch: Hook to block writes ===================================================================== FUNCTION 28: fcn.0023da48 ===================================================================== RVA: 0x0023da48 Purpose: Linked list add - stores anti-cheat data Patch: Hook to block additions ===================================================================== FUNCTION 29: fcn.002d0140 ===================================================================== RVA: 0x002d0140 Purpose: String copy with max 32 chars Patch: Hook to log/corrupt ===================================================================== FUNCTION 30: fcn.004e0ff8 ===================================================================== RVA: 0x004e0ff8 Purpose: Anti-cheat state management + debugger detection Patch: Always return false ===================================================================== INTERNAL FUNCTION: fcn.001ba124 ===================================================================== RVA: 0x001ba124 Purpose: Called by AnoSDKInit - internal initialization Patch: NOP call ===================================================================== INTERNAL FUNCTION: fcn.004b62e4 ===================================================================== RVA: 0x004b62e4 Purpose: Encryption/obfuscation setup Patch: NOP call ===================================================================== INTERNAL FUNCTION: fcn.004d8360 ===================================================================== RVA: 0x004d8360 Purpose: Logging function - prints anti-cheat logs Patch: NOP / Suppress ===================================================================== GLOBAL DATA ADDRESSES ===================================================================== 0x50f5a8 → Entry point function pointer 0x50ec30 → Function pointer for AnoSDKGetReportData2 0x50ebe8 → Pointer source for AnoSDKGetReportData2 0x54fbd0 → Report buffer 0x54fbd2 → Report buffer 2 0x54fc60 → Report counter 0x55a088 → Network callback pointer 0x56911c → Mutex for thread safety 0x569144 → Condition variable for waiting ===================================================================== RECOMMENDED PATCH BYTES (ARM64) ===================================================================== Return 0: 00 00 80 D2 C0 03 5F D6 (MOV W0, #0; RET) Return 1: 20 00 80 D2 C0 03 5F D6 (MOV W0, #1; RET)

===================================================================== FUNCTION 12: AnoSDKIoctl ===================================================================== RVA: 0x001c6e40 Size: 1264 bytes Purpose: IO control operations - anti-cheat communication Patch: Return 0 immediately ===================================================================== FUNCTION 13: AnoSDKFree ===================================================================== RVA: 0x001c7330 Size: 1332 bytes Purpose: Free allocated resources Patch: NOP entire function ===================================================================== FUNCTION 14: AnoSDKGetReportData2 ===================================================================== RVA: 0x001c7864 Size: 108 bytes Purpose: Report collection v2 - uses global function ptr Real Func: Global pointer @ 0x50ec30 States: 0x5e3f88c, -0x591d808b, -0x1f96ec1b, -0x3138b4ec, -0x207343f0, -0x47717616, -0x789ed605, -0x52fb3d62, 0x7d6e00e6, 0x43f9233d Patch: Return 0 at 0x001c7864 ===================================================================== FUNCTION 15: AnoSDKGetReportData3 ===================================================================== RVA: 0x001c78d0 Size: 108 bytes Purpose: Report collection v3 - calls fcn.001b5ae0 Real Func: fcn.001b5ae0 States: 0x53c22c4, 0x124a994, -0x5cc4f949, -0x3d969b3f, 0x2d918ee6, 0x2210b4c0, -0x21041361, -0x721110c1, -0x37d87060, 0x1dc9dde5, -0x246e2c2c Patch: Return 0 at 0x001c78d0 ===================================================================== FUNCTION 16: AnoSDKDelReportData3 ===================================================================== RVA: 0x001c793c Size: 1568 bytes Purpose: Delete/cleanup report data v3 Patch: NOP entire function ===================================================================== FUNCTION 17: AnoSDKGetReportData4 ===================================================================== RVA: 0x001c7f5c Size: 776 bytes Purpose: Report collection v4 - calls fcn.001bca14 Real Func: fcn.001bca14 States: -0x6c068bc4, -0x199170d0, -0x17cc305d, 0x365ef1cd, 0x6dfc6b24 Patch: Early return 0 at 0x001c7f5c ===================================================================== FUNCTION 18: AnoSDKDelReportData4 ===================================================================== RVA: 0x001c8264 Size: 1568 bytes Purpose: Delete/cleanup report data v4 Patch: NOP entire function ===================================================================== FUNCTION 19: AnoSDKOnRecvSignature ===================================================================== RVA: 0x001c8884 Size: 904 bytes Purpose: Receive and verify server signatures Patch: Always return valid (1) ===================================================================== FUNCTION 20: AnoSDKRegistInfoListener ===================================================================== RVA: 0x001c8c0c Size: 944 bytes Purpose: Register information listener - monitors game events Patch: NOP / Block registration ===================================================================== FUNCTION 21: AnoSDKForExport ===================================================================== RVA: 0x001c8fbc Size: 108 bytes Purpose: Export wrapper function Patch: NOP entire function ===================================================================== FUNCTION 22: JNI_OnLoad ===================================================================== RVA: 0x001cb85c Size: 580 bytes Purpose: JNI initialization - loads Java bindings Patch: Return 0 or NOP

` ===================================================================== FREE FIRE - ANTI-CHEAT OFFSETS LIST ===================================================================== Library: libanogs.so | Architecture: ARM64 ===================================================================== ===================================================================== FUNCTION 1: entry0 ===================================================================== RVA: 0x001b12c0 Purpose: Library entry point - trampoline to init function Real Call: (**0x50f5a8)(segment.LOAD1) Patch: NOP or overwrite pointer at 0x50f5a8 ===================================================================== FUNCTION 2: AnoSDKInit ===================================================================== RVA: 0x001c37ac Size: 812 bytes Purpose: Main anti-cheat initialization Real Call: fcn.001ba124() + fcn.004b62e4() Patch: Early return 0 at function start ===================================================================== FUNCTION 3: AnoSDKInitEx ===================================================================== RVA: 0x001c3ad8 Size: 1596 bytes Purpose: Extended anti-cheat initialization Patch: Early return 0 at function start ===================================================================== FUNCTION 4: AnoSDKSetUserInfo ===================================================================== RVA: 0x001c4114 Size: 1028 bytes Purpose: Device fingerprinting - collects user data Patch: NOP entire function ===================================================================== FUNCTION 5: AnoSDKSetUserInfoWithLicense ===================================================================== RVA: 0x001c4518 Size: 1676 bytes Purpose: User info with license validation Patch: NOP entire function / Always return valid ===================================================================== FUNCTION 6: AnoSDKOnPause ===================================================================== RVA: 0x001c4ba4 Size: 1060 bytes Purpose: Called when app goes background - triggers checks Patch: NOP entire function ===================================================================== FUNCTION 7: AnoSDKOnResume ===================================================================== RVA: 0x001c4fc8 Size: 1260 bytes Purpose: Called when app resumes - reinitializes checks Patch: NOP entire function ===================================================================== FUNCTION 8: AnoSDKGetReportData ===================================================================== RVA: 0x001c54b4 Size: 1388 bytes Purpose: PRIMARY report collection - device info, root, debug Real Func: fcn.001b25bc States: -0x227367df, 0x6ba4f2d, -0x10e68180, -0x3f32e2c4, -0x501721ad, 0x3a702cf2, -0x6fdff5ef, -0x489e39e6 Patch: Early return 0 at 0x001c54b4 ===================================================================== FUNCTION 9: AnoSDKDelReportData ===================================================================== RVA: 0x001c5a20 Size: 1988 bytes Purpose: Delete/cleanup report data after sending Patch: NOP entire function ===================================================================== FUNCTION 10: AnoSDKOnRecvData ===================================================================== RVA: 0x001c61e4 Size: 844 bytes Purpose: Receive data from server - processes responses Patch: Hook & block / NOP entire function ===================================================================== FUNCTION 11: AnoSDKIoctlOld ===================================================================== RVA: 0x001c6530 Size: 2320 bytes Purpose: Legacy IO control operations Patch: Return 0 immediately

// ============================================ case -0x59dfa0b9: // CRITICAL CALL 3: Setup encryption/obfuscation fcn.004b62e4(flag, 0); state_val2 = 0xbed798bb; state_val1 = 0xd6715301; current_state = 0x68a6cbba; // Go to STATE 5 break; // ============================================ // STATE 5: 0x68a6cbba (RETURN) // ============================================ case 0x68a6cbba: return; // Function exits successfully // ============================================ // STATE 6: -0x7ad399fd (ERROR EXIT) // ============================================ case -0x7ad399fd: // If something went wrong, call with different args fcn.004b62e4(flag, 0xffffffee); return; // Function exits with error } } } /* * ===================================================================== * KEY INSIGHTS: * ===================================================================== * * 1. O-LLVM FLATTENING: This function uses O-LLVM control flow flattening. * The real logic is hidden inside a state machine. The state variable * (current_state) determines which block executes. * * 2. fcn.001ba124(): This is called twice. It likely initializes internal * structures or sets up the anti-cheat environment. * * 3. fcn.004b62e4(): This is the encryption/obfuscation setup function. * It takes a flag and a parameter. The flag comes from arg1 being * negative - this might indicate debug mode or special state. * * 4. MAGIC VALUES: The values 0x89f4, 0x3507, 0x3b40 are stored in * stack variables. These are likely encryption keys or seeds. * * 5. PATCH OPPORTUNITY: The best patch is to replace the first few * instructions with "MOV W0, #0; RET" - this makes the function * return immediately without initializing anything. * * ===================================================================== */

void AnoSDKInit(int64_t arg1) { // ========== LOCAL VARIABLES ========== uint32_t temp1; // uVar1 - Temporary arithmetic value uint32_t temp2; // uVar2 - Temporary arithmetic value uint *stack_ptr; // puVar3 - Stack pointer uint state_val1; // uStack_7c - State value 1 uint state_val2; // uStack_78 - State value 2 int current_state; // iStack_74 - CURRENT STATE MACHINE STATE uint32_t *ptr1; // puStack_70 - Pointer 1 uint32_t *ptr2; // puStack_68 - Pointer 2 uint *ptr3; // puStack_60 - Pointer 3 uint8_t flag; // uStack_51 - Condition flag // ========== INITIALIZATION ========== stack_ptr = auStack_80; // Point to stack buffer current_state = -0x15a25ce7; // START STATE // ========== STATE MACHINE LOOP ========== while (true) { switch (current_state) { // ============================================ // STATE 1: -0x15a25ce7 (INITIALIZATION) // ============================================ case -0x15a25ce7: // Setup stack pointers ptr1 = stack_ptr - 4; // Allocate 4 bytes ptr2 = stack_ptr - 8; // Allocate 8 bytes stack_ptr = stack_ptr - 12; // Allocate 12 bytes ptr3 = stack_ptr; // Store magic values in stack *ptr1 = 0x89f4; // Store 0x89f4 temp1 = *ptr1; // Read back *ptr2 = 0x3507; // Store 0x3507 temp2 = *ptr2; // Read back // Set up state values (obfuscation) state_val2 = 0x3b3e5711; state_val1 = 0x9baff5db; // COMPLEX ARITHMETIC CONDITION (Obfuscation) // This check is meaningless - just obfuscation // It decides which state to go to next if ((temp2 | ~temp1) + (temp1 & temp2) + (temp1 & ~temp2) + 1 == (temp1 & temp2)) { current_state = -0x1411a7cc; // Go to STATE 2 } else { current_state = -0x5f6e5d36; // Go to STATE 3 } break; // ============================================ // STATE 2: -0x1411a7cc (CALL REAL INIT) // ============================================ case -0x1411a7cc: // CRITICAL CALL 1: Initialize something fcn.001ba124(arg1 & 0xFFFFFFFF); state_val2 = 0x36aba38e; state_val1 = 0x963a0144; current_state = -0x5f6e5d36; // Go to STATE 3 break; // ============================================ // STATE 3: -0x5f6e5d36 (CALL REAL INIT 2) // ============================================ case -0x5f6e5d36: // CRITICAL CALL 2: Initialize something again fcn.001ba124(arg1 & 0xFFFFFFFF); // Set flag based on arg1 being negative flag = (arg1 < 0); // Store magic value *ptr3 = 0x3b40; state_val1 = 0x7e26f042; state_val2 = 0xd806af05; current_state = -0x59dfa0b9; // Go to STATE 4 break; // ============================================ // STATE 4: -0x59dfa0b9 (ENCRYPTION SETUP)

/* * ===================================================================== * FUNCTION: AnoSDKInit * OFFSET: 0x001c37ac * SIZE: 812 bytes * LIBRARY: libanogs.so * ===================================================================== * * PURPOSE: * -------- * This is the MAIN ANTI-CHEAT INITIALIZATION function. It sets up * everything needed for the anti-cheat system to run, including: * - Encryption/obfuscation setup * - State initialization * - Memory allocation * * ARGUMENTS: * ---------- * arg1 (int64_t) → Game context / user data * This is passed from the game when it calls the SDK * * RETURN VALUE: * ------------- * None (void) * * ===================================================================== * FLOW DIAGRAM: * ===================================================================== * * ┌─────────────────────┐ * │ AnoSDKInit() │ * │ arg1 = context │ * └──────────┬──────────┘ * │ * ▼ * ┌─────────────────────┐ * │ SETUP STACK │ * │ Initialize local │ * │ variables │ * └──────────┬──────────┘ * │ * ▼ * ┌───────────────────────────────────┐ * │ STATE: -0x15a25ce7 (INIT) │ * │ Store magic values: │ * │ - *puStack_70 = 0x89f4 │ * │ - *puStack_68 = 0x3507 │ * │ Check arithmetic condition │ * │ If true → STATE -0x1411a7cc │ * │ If false → STATE -0x5f6e5d36 │ * └──────────────────┬────────────────┘ * │ * ┌─────────────────┴─────────────────┐ * │ │ * ▼ ▼ * ┌────────────────────────────┐ ┌────────────────────────────┐ * │ STATE: -0x1411a7cc │ │ STATE: -0x5f6e5d36 │ * │ (CALL REAL INIT) │ │ (CALL REAL INIT 2) │ * │ │ │ │ * │ Call fcn.001ba124(arg1) │──▶│ Call fcn.001ba124(arg1) │ * │ │ │ Set flag = arg1 < 0 │ * │ Next: -0x5f6e5d36 │ │ Next: -0x59dfa0b9 │ * └────────────────────────────┘ └────────────────────────────┘ * │ * ▼ * ┌────────────────────────────┐ * │ STATE: -0x59dfa0b9 │ * │ (ENCRYPTION SETUP) │ * │ │ * │ Call fcn.004b62e4(flag,0) │ * │ │ * │ Next: 0x68a6cbba │ * └────────────────────────────┘ * │ * ▼ * ┌────────────────────────────┐ * │ STATE: 0x68a6cbba │ * │ (RETURN) │ * │ │ * │ return │ * └────────────────────────────┘ * * ===================================================================== * PSEUDOCODE: * ===================================================================== */

wow reactions pe reactions i like that, give these type of supports and get paid things for free here👽🗿😮‍💨

Koi amir banda 1 star peldo👽 One rich person gift 1 star to this channel👽 and i have more do you all want more of this informations to make bypass? on your own?? spam reactions and also gift 1 star to this channel rich peoples🥲

=====================================================================
FREE FIRE - ANALYZED ANTI-CHEAT OFFSETS ( remember this is made by btikk)
share with credits or else your religion is gay
=====================================================================
Library: libanogs.so
Architecture: ARM64 (aarch64)
Date: [Current]
=====================================================================

NOTE: Only functions that have been fully analyzed via pseudocode
      breakdown are included in this file.

=====================================================================
FUNCTION 1: AnoSDKGetReportData
=====================================================================

OFFSET:     0x001c54b4
SIZE:       1388 bytes (0x56C)
TYPE:       GLOBAL FUNC
LIBRARY:    libanogs.so

REAL FUNCTION:  fcn.001b25bc

PURPOSE:
    Primary report data collection function.
    Collects device information, root status, debug flags,
    memory scans, and prepares report for server.

STATE MACHINE (O-LLVM Flattened):
    -0x227367df  → INITIALIZATION (Setup stack pointers)
    0x6ba4f2d    → SETUP (Call fcn.004b62e4 encryption init)
    -0x10e68180  → ARITHMETIC (Obfuscated math operations)
    -0x3f32e2c4  → CONDITION (Check arithmetic result)
    -0x501721ad  → BRANCH (Decide call or skip)
    0x3a702cf2   → CALL REAL (fcn.001b25bc)
    -0x6fdff5ef  → SKIP (Bypass real function)
    -0x489e39e6  → RETURN (Return report data)

REAL CALL:
    fcn.001b25bc() at state 0x3a702cf2

RETURN VALUE:
    uStack_68 - Report data from fcn.001b25bc()

WORKING:
    1. Initializes stack and pointers
    2. Calls fcn.004b62e4(1,4) for encryption setup
    3. Performs obfuscated arithmetic (no real logic)
    4. Checks condition flag
    5. If flag = 1 → calls fcn.001b25bc() to generate report
    6. If flag = 0 → skips to return
    7. Returns report data

PATCH METHOD:
    Option 1: Early return at function start
    Option 2: Patch state -0x6fdff5ef to always skip
    Option 3: NOP the call to fcn.001b25bc

RECOMMENDED PATCH:
    Replace first instructions at 0x001c54b4 with:
    MOV W0, #0
    RET
    (Hex: 00 00 80 D2 C0 03 5F D6)

=====================================================================
FUNCTION 2: AnoSDKGetReportData2
=====================================================================

OFFSET:     0x001c7864
SIZE:       108 bytes (0x6C)
TYPE:       GLOBAL FUNC
LIBRARY:    libanogs.so

REAL FUNCTION:  Global function pointer @ 0x50ec30

PURPOSE:
    Report data collection version 2.
    Uses a global function pointer to generate report data.

STATE MACHINE (O-LLVM Flattened):
    0x5e3f88c    → MAIN (Get pointer from 0x50ebe8)
    -0x591d808b  → CHECK (Check if pointer valid)
    -0x1f96ec1b  → SETUP PTR (Get func ptr from 0x50ec30)
    -0x3138b4ec  → CALL REAL ((**(*func_ptr + 0x28))(func_ptr))
    -0x207343f0  → INIT BUFFER (Setup 0x54fbd0)
    -0x47717616  → STORE (*0x54fbd0 = *ptr1, counter++)
    -0x789ed605  → READ (Check *ptr1 < 0x81)
    -0x52fb3d62  → PREPARE RETURN (uStack_98 = uStack_90)
    0x7d6e00e6   → RETURN (return uStack_98)
    0x43f9233d   → LOG (fcn.004d8360 log)

REAL CALL:
    (**(*func_ptr + 0x28))(func_ptr)
    Where func_ptr = **0x50ec30

RETURN VALUE:
    uStack_98 - Report data from global function

WORKING:
    1. Gets pointer from **0x50ebe8
    2. Checks if valid
    3. Gets function pointer from **0x50ec30
    4. Calls function at offset 0x28 of that pointer
    5. Stores result in global buffer at 0x54fbd0
    6. Increments counter at 0x54fc60
    7. Returns report data

GLOBAL DATA ADDRESSES:
    0x54fbd0  → Report buffer
    0x54fbd2  → Report buffer 2
    0x54fc60  → Report counter
    0x50ec30  → Function pointer
    0x50ebe8  → Pointer source

PATCH METHOD:
    Option 1: Return 0 at function start
    Option 2: NOP the call to global function
    Option 3: Patch the global pointer to point to dummy function

RECOMMENDED PATCH:
    Replace first instructions at 0x001c7864 with:
    MOV W0, #0
    RET
    (Hex: 00 00 80 D2 C0 03 5F D6)

===================================================================== FUNCTION 3: AnoSDKGetReportData3 ===================================================================== OFFSET: 0x001c78d0 SIZE: 108 bytes (0x6C) TYPE: GLOBAL FUNC LIBRARY: libanogs.so REAL FUNCTION: fcn.001b5ae0 PURPOSE: Report data collection version 3. Makes multiple calls to fcn.001b5ae0 with different parameters. STATE MACHINE (O-LLVM Flattened): 0x53c22c4 → INIT (Setup stack pointers) 0x124a994 → SETUP (Store magic values) -0x5cc4f949 → ARITHMETIC (Obfuscated math) -0x3d969b3f → CONDITION (Complex check) 0x2d918ee6 → BRANCH (Decide normal/alternate) 0x2210b4c0 → CALL SETUP (Store more values) -0x21041361 → CALL REAL (fcn.001b5ae0(0x32,0,ptr1,0x3f,0)) -0x721110c1 → MORE SETUP (fcn.001b5ae0(0x25,0,ptr1,0,0)) -0x37d87060 → PREPARE RETURN (uStack_68 = *ptr1) 0x1dc9dde5 → RETURN (return uStack_68) -0x246e2c2c → ALTERNATE PATH (fcn.001b5ae0(0x67,0,ptr1,0xffffffd7,0)) REAL CALL: fcn.001b5ae0(0x32, 0, ptr1, 0x3f, 0) fcn.001b5ae0(0x25, 0, ptr1, 0, 0) fcn.001b5ae0(0x67, 0, ptr1, 0xffffffd7, 0) [Alternate path] RETURN VALUE: *ptr1 (uStack_68) - Data from buffer WORKING: 1. Initializes stack and sets up pointers 2. Stores magic values (0x41c1, 0x9018, 0xbaa1) 3. Performs obfuscated arithmetic operations 4. Checks condition to decide normal or alternate path 5. Normal path: a. Calls fcn.001b5ae0(0x32, 0, ptr1, 0x3f, 0) b. Calls fcn.001b5ae0(0x25, 0, ptr1, 0, 0) 6. Alternate path: a. Calls fcn.001b5ae0(0x67, 0, ptr1, 0xffffffd7, 0) 7. Returns data from ptr1 buffer KEY PARAMETERS: 0x32 → First call parameter 0x25 → Second call parameter 0x67 → Alternate call parameter 0x3f → First call arg4 0xffffffd7 → Alternate call arg4FUNCTION 4: AnoSDKGetReportData4 OFFSET: 0x001c7f5c REAL FUNCTION: fcn.001bca14 PURPOSE: Report data collection version 4. Direct call to fcn.001bca14 with arg1. STATE MACHINE (O-LLVM Flattened): -0x6c068bc4 → INIT (Store 0xe294 to ptr1, 0xf499 to ptr2) -0x199170d0 → SETUP (Store 0xa61e to ptr3, 0x7f07 to ptr4) -0x17cc305d → CALL (fcn.001bca14(arg1 & 0xFFFFFFFF)) 0x365ef1cd → RETURN (return uStack_58) 0x6dfc6b24 → ALT RETURN (fcn.001bca14(arg1 & 0xFFFFFFFF)) REAL CALL: fcn.001bca14(arg1 & 0xFFFFFFFF) RETURN VALUE: uStack_58 / uVar2 - Report data from fcn.001bca14 WORKING: 1. Sets up stack and pointer 2. Stores magic values (0xe294, 0xf499, 0xa61e, 0x7f07) 3. Calls fcn.001bca14(arg1 & 0xFFFFFFFF) 4. Returns result ARGUMENT: arg1 → Passed to real function as (arg1 & 0xFFFFFFFF) PATCH METHOD: Option 1: Early return at function start Option 2: NOP the call to fcn.001bca14 Option 3: Return 0 directly INTERNAL FUNCTIONS (Called by Above) 1. fcn.001b25bc → Called by: AnoSDKGetReportData → Purpose: Actual report data generator → Patch: Return 0 early 2. fcn.001b5ae0 → Called by: AnoSDKGetReportData3 → Purpose: Report builder with parameters → Patch: Return 0 early 3. fcn.001bca14 → Called by: AnoSDKGetReportData4 → Purpose: Report data generator v4 → Patch: Return 0 early GLOBAL DATA ADDRESSES 0x50ec30 → Function pointer for AnoSDKGetReportData2 0x50ebe8 → Pointer source for AnoSDKGetReportData2 0x54fbd0 → Report buffer 0x54fbd2 → Report buffer 2 0x54fc60 → Report counter `

` ===================================================================== FREE FIRE - ANALYZED ANTI-CHEAT OFFSETS ===================================================================== Library: libanogs.so Architecture: ARM64 (aarch64) Date: [Current] ===================================================================== NOTE: Only functions that have been fully analyzed via pseudocode breakdown are included in this file. ===================================================================== FUNCTION 1: AnoSDKGetReportData ===================================================================== OFFSET: 0x001c54b4 SIZE: 1388 bytes (0x56C) TYPE: GLOBAL FUNC LIBRARY: libanogs.so REAL FUNCTION: fcn.001b25bc PURPOSE: Primary report data collection function. Collects device information, root status, debug flags, memory scans, and prepares report for server. STATE MACHINE (O-LLVM Flattened): -0x227367df → INITIALIZATION (Setup stack pointers) 0x6ba4f2d → SETUP (Call fcn.004b62e4 encryption init) -0x10e68180 → ARITHMETIC (Obfuscated math operations) -0x3f32e2c4 → CONDITION (Check arithmetic result) -0x501721ad → BRANCH (Decide call or skip) 0x3a702cf2 → CALL REAL (fcn.001b25bc) -0x6fdff5ef → SKIP (Bypass real function) -0x489e39e6 → RETURN (Return report data) REAL CALL: fcn.001b25bc() at state 0x3a702cf2 RETURN VALUE: uStack_68 - Report data from fcn.001b25bc() WORKING: 1. Initializes stack and pointers 2. Calls fcn.004b62e4(1,4) for encryption setup 3. Performs obfuscated arithmetic (no real logic) 4. Checks condition flag 5. If flag = 1 → calls fcn.001b25bc() to generate report 6. If flag = 0 → skips to return 7. Returns report data PATCH METHOD: Option 1: Early return at function start Option 2: Patch state -0x6fdff5ef to always skip Option 3: NOP the call to fcn.001b25bc RECOMMENDED PATCH: Replace first instructions at 0x001c54b4 with: MOV W0, #0 RET (Hex: 00 00 80 D2 C0 03 5F D6) ===================================================================== FUNCTION 2: AnoSDKGetReportData2 ===================================================================== OFFSET: 0x001c7864 SIZE: 108 bytes (0x6C) TYPE: GLOBAL FUNC LIBRARY: libanogs.so REAL FUNCTION: Global function pointer @ 0x50ec30 PURPOSE: Report data collection version 2. Uses a global function pointer to generate report data. STATE MACHINE (O-LLVM Flattened): 0x5e3f88c → MAIN (Get pointer from 0x50ebe8) -0x591d808b → CHECK (Check if pointer valid) -0x1f96ec1b → SETUP PTR (Get func ptr from 0x50ec30) -0x3138b4ec → CALL REAL ((**(*func_ptr + 0x28))(func_ptr)) -0x207343f0 → INIT BUFFER (Setup 0x54fbd0) -0x47717616 → STORE (*0x54fbd0 = *ptr1, counter++) -0x789ed605 → READ (Check *ptr1 < 0x81) -0x52fb3d62 → PREPARE RETURN (uStack_98 = uStack_90) 0x7d6e00e6 → RETURN (return uStack_98) 0x43f9233d → LOG (fcn.004d8360 log) REAL CALL: (**(*func_ptr + 0x28))(func_ptr) Where func_ptr = **0x50ec30 RETURN VALUE: uStack_98 - Report data from global function WORKING: 1. Gets pointer from **0x50ebe8 2. Checks if valid 3. Gets function pointer from **0x50ec30 4. Calls function at offset 0x28 of that pointer 5. Stores result in global buffer at 0x54fbd0 6. Increments counter at 0x54fc60 7. Returns report data GLOBAL DATA ADDRESSES: 0x54fbd0 → Report buffer 0x54fbd2 → Report buffer 2 0x54fc60 → Report counter 0x50ec30 → Function pointer 0x50ebe8 → Pointer source PATCH METHOD: Option 1: Return 0 at function start Option 2: NOP the call to global function Option 3: Patch the global pointer to point to dummy function RECOMMENDED PATCH: Replace first instructions at 0x001c7864 with: MOV W0, #0 RET (Hex: 00 00 80 D2 C0 03 5F D6)

===================================================================== GLOBAL DATA ADDRESSES ===================================================================== 0x50ec30 → Function pointer for AnoSDKGetReportData2 0x50ebe8 → Pointer source for AnoSDKGetReportData2 0x54fbd0 → Report buffer 0x54fbd2 → Report buffer 2 0x54fc60 → Report counter ===================================================================== SUMMARY TABLE ===================================================================== FUNCTION | RVA | SIZE | REAL FUNCTION -----------------------------|-----------|------|------------------ AnoSDKGetReportData | 0x001c54b4| 1388 | fcn.001b25bc AnoSDKGetReportData2 | 0x001c7864| 108 | Global ptr @ 0x50ec30 AnoSDKGetReportData3 | 0x001c78d0| 108 | fcn.001b5ae0 AnoSDKGetReportData4 | 0x001c7f5c| 776 | fcn.001bca14 ===================================================================== RECOMMENDED PATCH BYTES (ARM64) ===================================================================== Return 0: 00 00 80 D2 C0 03 5F D6 (MOV W0, #0; RET) Return 1: 20 00 80 D2 C0 03 5F D6 (MOV W0, #1; RET) NOP / Skip: C0 03 5F D6 (RET) ===================================================================== END OF FILE =====================================================================ˋˋˋ