en
Feedback
HcX更新通知

HcX更新通知

Open in Telegram

📈 Analytical overview of Telegram channel HcX更新通知

Channel HcX更新通知 (@hcxwei) in the Chinese language segment is an active participant. Currently, the community unites 18 356 subscribers, ranking 6 311 in the Technologies & Applications category and 13 690 in the China region.

📊 Audience metrics and dynamics

Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 18 356 subscribers.

According to the latest data from 11 November, 2025, the channel demonstrates stable activity. Although there has been a change in the number of participants by -303 over the last 30 days and by 0 over the last 24 hours, overall reach remains high.

  • Verification status: Not verified
  • Engagement rate (ER): The average audience engagement rate is 0%. Within the first 24 hours after publication, content typically collects N/A% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 0 views. Within the first day, a publication typically gains 0 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 0.
  • Thematic interests: Content is focused on key topics such as hcx, zip, 受害者, 科技(, data/user.

📝 Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
HcX更新频道 交流群 https://t.me/+PZk_KRq6J01jNTc1

Thanks to the high frequency of updates (latest data received on 12 November, 2025), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

18 356
Subscribers
No data24 hours
-537 days
-30330 days
Posts Archive
重启一下手机就好了

他的旧版本,病毒样本(Killed_Shell加密工具)样本分析(这个是他数个月以前的病毒样本)  ,重启设备恶意程序进程就没了,不会自动启动。(加密工具本身似乎不会执行恶意代码)注意但是被其工具加密后的文件,执行就会在后台偷偷运行病毒程序(远控,偷文件,格机) 它的旧版本的恶意代码特征会在以下路径留下curl ,rc4 ,Bash  ,正常情况下MT管理器,这个路径下是没有这几个文件,快检查自己设备下面路径有没有该文件。 /data/user/0/bin.mt.plus/files/term/tmp/ /data/user/0/bin.mt.plus/files/term/tmp/patch/

里面应该有所有服务器信息

证据在这里面

Killed_Shell旧版加密源码内含远控.zip

photo content

别人提供

photo content

主谋是朱彪,有没有人去干他的

关于 此次 偷文件风波已真相大白 所有使用过为人民服务频道 破解项目的人建议自行去刷机 你只要最近使用过他们发的破解项目 你的手机就已被偷文件并且被监听 其他的破解项目暂时不知道 为人民破解也是我认识的一个朋友做的 他自己也不知道有这个东西 纯粹是给别人当枪使用了 此次受害者预计1万台设备 受害者可以自己去举报 举报链接和证据 希望罪犯早日绳之以法

我与多名受害者遭遇远程控制、数据窃取和设备破坏的黑客攻击。犯罪嫌疑人朱彪(QQ号:3649086158)在QQ群(877942573)传播恶意软件“Killed_Shell加密_v46.sh”(4.5MB),诱导受害者运行后连接120.76.141.58(阿里云服务器),执行以下恶意行为: 远程控制设备:使用 curl -s 下载 term.sh,静默执行远程Shell命令,控制受害者设备。 数据窃取:频繁读取、写入、上传受害者文件,泄露照片、聊天记录、银行账户、支付信息等。 设备破坏:针对ARM64 ROOT设备,可能篡改Bootloader/Recovery,部分受害者手机、平板等设备无法开机、死机、无限重启,甚至刷机无法恢复。 疑似商业化运营:病毒付费传播,并通过www.killedshell.xyz 网站推广,该域名注册地重庆,长期用于恶意软件销售。 **部分受害者因设备损坏已断联,实际受害人数可能更多。**请公安机关立案调查,封禁服务器(120.76.141.58)、病毒传播网站(www.killedshell.xyz),追踪资金流向,防止进一步扩散。 举报网站https://cyberpolice.mps.gov.cn/

Repost from 小迷糊
我与多名受害者遭遇远程控制、数据窃取和设备破坏的黑客攻击。犯罪嫌疑人朱彪(QQ号:3649086158)在QQ群(877942573)传播恶意软件“Killed_Shell加密_v46.sh”(4.5MB),诱导受害者运行后连接120.76.141.58(阿里云服务器),执行以下恶意行为: 远程控制设备:使用 curl -s 下载 term.sh,静默执行远程Shell命令,控制受害者设备。 数据窃取:频繁读取、写入、上传受害者文件,泄露照片、聊天记录、银行账户、支付信息等。 设备破坏:针对ARM64 ROOT设备,篡改Bootloader/Recovery,部分受害者手机、平板等设备无法开机、死机、无限重启,甚至刷机无法恢复。 疑似商业化运营:病毒付费传播,并通过www.killedshell.xyz 网站推广,该域名注册地重庆,长期用于恶意软件销售。 部分受害者因设备损坏已断联,实际受害人数 更多。请公安机关立案调查,封禁服务器(120.76.141.58)、病毒传播网站(www.killedshell.xyz),追踪资金流向,防止进一步扩散。 举报网站https://cyberpolice.mps.gov.cn/

Killed_Shell的加密工具偷文件,远控,盗号,请立即查看自己是否中招

curl和sleep检测&杀死.sh

裤衩都被偷完了,还被格机了。

photo content

报警可提供的信息包括聊天记录阿里云服务器IP该人QQ号,该人涉嫌入侵他人手机窃取个人信息格式化数据锁机,远控偷窥屏幕.rar

兄弟们,我也中招了。

祝大家除夕快乐哦