Aggressive new PairIP variant ⚠️🚨

Trusted by over 1.6 million members since 2014 — why not join them?
Log in or Register to join us!

Snailsoft

∞ and beyond!
Staff Member
Moderator
SB Mod Squad ⭐
✔ Approved Releaser
Active User
Member for 2 years
I was passed along a mod request and it has produced some alarming results.
It is a confirmed PairIP protection plus I suspect other protection or severely ramped up defense.
It is blocking most scan and modding tools.
It is actively attacking and deleting RE tools on root.
1000265217.png

1000265322.png

@Sbenny
@LadyOnePunch
 

Sbenny

A crazy scientist
Staff Member
Admin
SB Mod Squad ⭐
✔ Approved Releaser
Active User
That's crazy OMG, how is that supposed to be able to delete external stuff at root level if it doesn't even have root privileges? This is way more serious than it looks, as if so, it could be theorically exploited by black-hat hackers to manipulate your device, given the fact it can freely walk across your root directory and do whatever it wants.
 

Snailsoft

∞ and beyond!
Staff Member
Moderator
SB Mod Squad ⭐
✔ Approved Releaser
Active User
Member for 2 years
The security itself does not need root, nor does it seem to have this capacity on non-rooted devices, however, when I switched to rooted Android (where many of my RE tools are) it uninstalled APKtools-M and MT without my permission. APPS Permission is automatic. It was able to remove LP not based on package name, rather, the default icon.
It is using a VM that is feeding testing tools so much information that they fail, sort of like a Honey Pot.
I am still working on it but I am having to do things at the source level, manually, limited tools.
 

Snailsoft

∞ and beyond!
Staff Member
Moderator
SB Mod Squad ⭐
✔ Approved Releaser
Active User
Member for 2 years
The 💯+ temperatures 🔥 are hampering my efforts, though I have made progress on this project.
I compared it to several release sites and find that while all use the latest PairIP protection, it is the one from China that has the added code.
I have bypassed PairIP enough to decompile the game.
Removed numerous malicious codes.
Removed a Remote Administrator Trojan apk.
Removed all but the required permissions.

1000265471.png
1000265472.png
1000265473.png
1000265474.png
1000265475.png


Hope to have it fully torn down and safe for release soon.
 

Daniel

Hunter of Sbennytopia
From the Hell
Member for 6 years
@Snailsoft In your post as you mentioned that this added code was only in the Chinese version, isn't it highly against Google's ethics and policies to include code that can remove applications without the user's consent?
 

Snailsoft

∞ and beyond!
Staff Member
Moderator
SB Mod Squad ⭐
✔ Approved Releaser
Active User
Member for 2 years
Not in the least.
Google has long supported trojans and remote administrative code of their own design as well as apps that employ many sorts of malware.
What Google lies about publicly and what they practice are quite different as most modders can attest to when removing a plethora of malware from apps that Google has approved.
Further, many countries, such as China, do not have legal restrictions on what government can do. Adding additional code to existing code is perfectly acceptable if it serves Communist interest.
 

Snailsoft

∞ and beyond!
Staff Member
Moderator
SB Mod Squad ⭐
✔ Approved Releaser
Active User
Member for 2 years
Also, take a look at this more recent post.
The use of system level trojans in Android is not restricted to combative governments, rather, it is something being deployed by most corporations involved with Android.
 

Snailsoft

∞ and beyond!
Staff Member
Moderator
SB Mod Squad ⭐
✔ Approved Releaser
Active User
Member for 2 years
For your protection, you must allow corporations to decide what you want to have installed in your equipment.
Perfectly acceptable thinking in dictatorships.

Fortunately, the world still has modders.
 
Top