jennymax193
Just Crazy
Hi everyone,
I am currently reverse-engineering and analyzing the Android mobile game Evo Defense: Merge TD (published by Shiyue Games / 诗悦网络).
Target Profile:
Zygote: Process com.evodefensetd.gp (PID: xxxx) exited cleanly (0)
There is no crash dump, no SIGSEGV, and no ANR dialog.
I am currently reverse-engineering and analyzing the Android mobile game Evo Defense: Merge TD (published by Shiyue Games / 诗悦网络).
Target Profile:
- Game Title: Evo Defense: Merge TD
- Package Name: com.evodefensetd.gp
- Game Version: 1.1.1 (VersionCode: 10101)
- Main Activity: com.shiyuegame.fswy.GameMainActivity
- Engine: Unity HybridCLR (Huatuo CIL runtime)
- Architecture: ARM64 (arm64-v8a)
Security & Anti-Cheat Stack:
Through static and runtime binary triage, I discovered the game uses a dual-layer protection mechanism:- Commercial Protector (FairGuard / ZZProtect):
- lib/arm64-v8a/libZzprotect.so (~5.44 MB, heavily obfuscated with OLLVM Control Flow Flattening).
- Its DT_NEEDED imports libFairGuard.so.
- It decrypts assets/bin/Data/Managed/Metadata/global-metadata.dat in memory upon Unity bootstrap (the raw metadata header magic is scrambled with 0x6D2E8F48 instead of standard 0xFAB11BAF).
- In-House Anti-Tamper & Risk Control SDK (Shiyue SYCheck):
- Java layer: com.sy.check.plugin (SYRiskControl, AntiMemHack, BridgeCheatingDetector, RiskDecisionEngine).
- Native engine: lib/arm64-v8a/libdvstat.so (~1.4 MB).
- Strings reveal active detection for GameGuardian, Frida gadgets, memory scanners reading /proc/self/mem and /proc/self/pagemap, decoy page checksum traps, ptrace attachment, and clock drift.
The Issue (The T+40s Delayed Exit Trap):
After patching and launching the APK on an Android 12/14 emulator (OnePlus / ASUS profiles), the game runs smoothly, renders the splash screen, and enters the main UI. However, consistently at T+40.78 seconds, the process silently dies with a clean exit:Zygote: Process com.evodefensetd.gp (PID: xxxx) exited cleanly (0)
There is no crash dump, no SIGSEGV, and no ANR dialog.
Findings So Far:
- At around T+38s, background threads (Thread-33 checking battery sysfs / /system/bin/sh via BatteryBroadcastReceiver and Thread 4947 querying Settings.Global.adb_enabled via AsyncBase) trigger risk telemetry.
- RiskDecisionEngine evaluates the anomaly score and calls AbstractBase.AbstractBase, which ultimately executes System.exit(0).
- Attempting to hook Bionic libc exit, _exit, or _Exit in native C++ using trampolines causes stability issues / crashes inside ARM-to-x86 translation layers (Houdini/NDK translator).
Questions for the Community:
- For anyone who has worked on Shiyue Games titles (using com.sy.check / libdvstat.so), is the kill decision enforced purely from Dalvik (System.exit(0)), or does libdvstat.so also dispatch kernel syscalls (exit_group, kill(SIGKILL)) directly?
- What is the cleanest way to completely silence or stub out com.sy.check.plugin.utils.BridgeCheatingDetector and SYRiskControl without breaking the game's initialization lifecycle?
- Has anyone successfully dumped the decrypted global-metadata.dat from memory when libZzprotect.so / FairGuard is active on this specific game?