Reversal X Mods (бесплатные премиум-приложения для Android)
Ir al canal en Telegram
Anything worth while. Share and support us @reversemoda
Mostrar másEl país no está especificadoTecnologías y Aplicaciones27 963
2 263
Suscriptores
+1024 horas
+937 días
+32930 días
Archivo de publicaciones
🏜🏜🏜🏜🏜🏜🏜🏜🏜
➽: 𝗠𝘂𝗻𝗼𝘄𝗮𝘁𝗰𝗵 𝗩𝗜𝗣 :➽
🏜🏜🏜🏜🏜🏜🏜🏜🏜
🪀 𝗡𝗘𝗪 𝗨𝗣𝗗𝗔𝗧𝗘 🪀
🎗𝗥𝗘𝗗𝗜𝗥𝗘𝗖𝗧 𝗗𝗢𝗪𝗡𝗟𝗢𝗔𝗗𝗦
├ Tap Download - Chrome opens automatically with the real video file link (CDN direct).
└ Download any movies or series straight from Chrome to your file manager as you requested for.
‼️ 𝗡𝗕: 𝗜𝗻𝗰𝗮𝘀𝗲 𝘂 𝘀𝗲𝗲 𝘀𝗲𝗿𝘃𝗲𝗿 𝗼𝗳𝗳𝗹𝗶𝗻𝗲 𝗱𝗶𝗮𝗹𝗼𝗴 𝘀𝘄𝗶𝘁𝗰𝗵 𝘁𝗼 u𝗿 𝗻𝗼𝗿𝗺𝗮𝗹 𝗻𝗲𝘁𝘄𝗼𝗿𝗸 𝘁𝗼 𝗱𝗼 𝘁𝗵𝗲 𝘃𝗲𝗿𝗶𝗳𝗶𝗰𝗮𝘁𝗶𝗼𝗻 𝗮𝗳𝘁𝗲𝗿 𝘁𝗵𝗮𝘁 𝘂 𝗰𝗮𝗻 𝘀𝘄𝗶𝘁𝗰𝗵 𝘁𝗼 𝗩𝗣𝗡 𝗼𝗿 𝗪𝗶𝗙𝗶.
➖➖➖➖➖➖➖➖➖
🕹 Released By :
逆转 X 模组
🔗 Share To Support Us:
➖➖➖➖➖➖➖➖➖
🍄 If you are a Telegram Premium subscriber, boost our channel.
🚨 Tap here: https://t.me/boost/reversemoda
✨ It's free to tap. It doesn't bite. Try it
🥹 If you are muted after joining the group because you failed to answer the maths question, exit group and join again.
🥰 It's a beautiful day. A brand new week.
💯 Greetings from ReversalxTeam to everyone.
🧀 @reversemoda
Take mic, tell us why you don’t react or share updates. 🤨
Someone showed me this on Telegram. It is very silly. It is clearly masquerading as "Free GPT and Claude". Anyone with half a brain knows this is malicious, but people will still fall for it.
People asked what it is. I have some free time. I poked it with a stick,
People discussing it said it is XMRig. That is not entirely accurate. This is not XMRig. This is flagged as XMRig from Triage and VirusTotal because it does indeed drop XMRig, but it is much more than that. This is a (maybe new) information stealer packaged with XMRig as a double whammy.
This malware is interesting because of a few things:
1. It is position independent, they care enough to be evasive and strip out a majority of dependencies. This is usually indicative of more serious malware.
2. They .zip it delivers from the "Free GPT and Claude" is intentionally bloated (payload inflation). It is 97MB, which may evade a majority of anti-malware product (initially) due to it's large size. It packages itself with FFMpeg and various other audio codecs.
3. It accesses Microsoft Outlook e-mails, accesses Chrome stuff using the COM IElevationService, looks for any SFTP credentials
It (currently) does not have any matching YARA rules from AV vendors. The closest approximation is LummaStealer. My knowledge base on the Information Stealer scene is out-of-date (it changes a lot). However, on first initial glance this appears like a new information stealer. Again, this should be taken with a grain of salt.
It's also worth noting the domain it exfiltrates to does not appear in any malware reports. The domain is unique, and the payload does not match any existing YARA rules (it's behavioral characteristics do, but not a specific malware family), so this is actually a pretty interesting sample.
A lookup though shows this is an emerging malware campaign. It first appeared around the end of May. This is (probably) a known Threat Actor who has switched it up a bit (or it's MaaS, whatever though).
The malware appears online masquerading as various products.
- ecore-sourceproject
- LogiDA
- GPT_Claude_Free
- CortexSystems.v3.4.2.Stable
- TikTokBot-v2.2
- CortexLauncher
Funny enough, this malware would have been much, much, much, MUCH more evasive if they didn't package it with XMRig. VirusTotal and Triage immediately flagged it because after it establishes persistence, and steals any credentials on the machine, it pulls XMRig to turn into a cryptocurrency miner.
If they did not pull the XMRig binary this stealer would be much more quiet. I have no idea why they decided to burn their OPSEC with XMRig.
C2: dfwioeiofwr-dot-info
Payload (and associated families from the C2)
027d576c6b5512d661081aaeeeb8e611f95a469ccf5ba35e0a390e8814334d05
5dcc599cf48227e65ea49d2708d08704fd1cb7e3b89736718d0d8e557857c49c
5e8b40b0b7512e1a1355374fb0cf34bfdf1260ebdb80a353c8f9da2490beeed3
6a0c332296b017220fc2b522da653fce36a8a3c5c79de0200d61c5fc31eb89ce
a2f8ebf65d54a4d9c8b720d01da77ad796683f1a5b8bd3d08738d7df4365f8a
9d4aaa9842c947756b7c128c432292732098fb71d247ef0bce60368563572da3
c4caca93e2291c018e701c217b7d232c534e4dd142042a59aa4d32754ef3022a
❌ If you see this anywhere, don't download.
💯 Run.
🏜🏜🏜🏜🏜🏜🏜🏜🏜
➽: 𝗦𝗮𝗽𝗮 𝗧𝗩 𝗣𝗿𝗲𝗺𝗶𝘂𝗺 :➽
🏜🏜🏜🏜🏜🏜🏜🏜🏜
🪀 𝗖𝗢𝗠𝗜𝗡𝗚 𝗦𝗢𝗢𝗡 🪀
⏳ 𝗦𝗔𝗣𝗔 𝗧𝗩 𝗣𝗥𝗘𝗠𝗜𝗨𝗠
├ 百度加固 bypassed ✅
├ Sapa TV Premium is
│ currently loading
├ We are working on it
│ behind the scenes
└ Once released, if you see it
anywhere, know for sure
it's from Reversal X Group 😂
➖➖➖➖➖➖➖➖➖
🕹 Released By :
逆转 X 模组
🔗 Share To Support Us
➖➖➖➖➖➖➖➖➖
🪀 𝗪𝗛𝗔𝗧 𝗜𝗧 𝗗𝗢𝗘𝗦 🪀
🔓 𝗗𝗘𝗖𝗢𝗠𝗣𝗜𝗟𝗘 & 𝗦𝗖𝗔𝗡
├ Decompiles APK with apktool.
├ Scans all .smali files automatically.
└ Auto‑detects XOR cipher methods (static, Strings`n String, 4‑byte keys)
⚡ 𝗗𝗘𝗖𝗢𝗗𝗘 𝗫𝗢𝗥 𝗦𝗧𝗥𝗜𝗡𝗚𝗦
├ Extracts encrypted const‑string values
├ Uses packed‑switch + xor‑int/lit8 patterns
├ Auto‑calculates key from smali logic
└ Decodes to readable plaintext
🎗 𝗣𝗔𝗧𝗖𝗛 & 𝗥𝗘𝗕𝗨𝗜𝗟𝗗
├ Replaces encrypted strings inline (optional)
├ Rebuilds only classes*.dex (keeps resources)
└ Outputs a fully deobfuscated APK
🧹 𝗘𝗫𝗧𝗥𝗔 𝗙𝗘𝗔𝗧𝗨𝗥𝗘𝗦
├ Multi‑threaded (uses all CPU cores)
├ Real‑time progress bar
└ Clean temp files after run
➖➖➖➖➖➖➖➖➖
📦 𝗜𝗡𝗦𝗧𝗔𝗟𝗟𝗔𝗧𝗜𝗢𝗡 (𝗧𝗲𝗿𝗺𝘂𝘅)
➖➖➖➖➖➖➖➖➖
pkg update && pkg upgrade -y
pkg install openjdk-21 -y
pkg install python apktool -y
java -jar /storage/emulated/0/MT2/dump/dumper.jar /storage/emulated/0/MT2/dump/app.apk /storage/emulated/0/MT2/dump/app_decoded.apk
‼️ 𝗡𝗕: 𝗪𝗼𝗿𝗸𝘀 𝗼𝗻 𝗮𝗻𝘆 𝗫𝗢𝗥‑𝗲𝗻𝗰𝗿𝘆𝗽𝘁𝗲𝗱 𝗔𝗣𝗞, 𝗧𝗵𝗮𝘁 𝘂𝘀𝗲𝘀 𝗮 𝟰‑𝗯𝘆𝘁𝗲 𝗸𝗲𝘆 𝗶𝗻 𝘀𝗺𝗮𝗹𝗶.
➖➖➖➖➖➖➖➖➖
🕹 Released By :
逆转 X 模组
➖➖➖➖➖➖➖➖➖🏜🏜🏜🏜🏜🏜🏜🏜
➽: 𝗔𝗥𝗠 𝗨𝗟𝗧𝗥𝗔 :➽
𝗗𝗘𝗫 𝗦𝗧𝗥𝗜𝗡𝗚𝗦 𝗗𝗨𝗠𝗣𝗘𝗥
➽: 𝗔𝗥𝗠 𝗨𝗟𝗧𝗥𝗔 :➽
🏜🏜🏜🏜🏜🏜🏜🏜
