#### Ò»¡¢ÒýÇæÊ¶±ðºËÐÄÂß¼ÓëÐÐÒµÏÖ×´
´«ÆæÒýÇæÊǹ¹½¨Éú̬µÄ¼¼Êõ»ùʯ£¬½ØÖÁ2025ÄêÖ÷Á÷ÒýÇæÒÑÐγÉ**Áù´ó¼¼ÊõÅÉϵ**£º¸´¹Åϵ£¨HERO/BLUE£©¡¢ºÏ»÷ϵ£¨3K/LEGEND£©¡¢´´ÐÂϵ£¨GOM/GEE£©Óë¿ç¶Ëϵ£¨ôá·ç/Áú×壩¡£²»Í¬ÒýÇæÖ±½ÓÓ°ÏìÓÎÏ·Íæ·¨¡¢·´Íâ¹Ò»úÖÆ¼°½Å±¾¼æÈÝÐÔ£¬Æäʶ±ðÐè½áºÏ**½çÃæÌØÕ÷¡¢ÔËÐÐÂß¼ÓëÎļþ½á¹¹**ÈýÖØÑéÖ¤¡£
---
#### ¶þ¡¢»ù´¡Åж¨·¨£ºÎåÎ¬ÌØÕ÷¾ØÕó
##### 1. **µÇ¼Æ÷½çÃæÌØÕ÷**
| ÒýÇæÀàÐÍ | Æô¶¯½çÃæÌØÕ÷ | ×¢²á´°¿Ú±êʶ | ·Ö±æÂÊÑ¡Ïî |
|--------------|----------------------------------|------------------------|------------------|
| HERO | ×óÉϽÇÏÔʾ"HEROM2"ˮӡ | ºìÉ«±ß¿ò+¸´¹Å×ÖÌå | ½ö800x600 |
| BLUE | µ³öʽ¼ÓÔØ¶¯»£¨Í¸Ã÷¶È½¥±ä£© | À¶É«¶¯Ì¬°´Å¥ | Ö§³Ö1080P |
| 3K | ½ø¶ÈÌõ´ø"3K"LOGO | »ÆÉ«¾¯Ê¾Ìáʾ | ×Ô¶¨Òå·Ö±æÂÊ |
| GOM | ºìɫע²á³É¹¦Ìáʾ | ÒôÁ¿µ÷½Ú°´25%µÝ¼õ | ¶àµµÎ»Ô¤Éè |
| GEE | ÂÌÉ«°²È«ÈÏ֤ͼ±ê | Ö±½Ó¿ª¹ØÊ½ÒôÁ¿¿ØÖÆ | ÎÞ¼¶Ëõ·Å |
##### 2. **ÓÎÏ·ÄÚ¹¦ÄܱíÏÖ**
- **HEROÒýÇæ**£º½ÇÉ«ËÀÍöºóʬÌå±£Áôʱ¼ä¹Ì¶¨60Ã룬ÎÞËÀÍöÌØÐ§
- **BLUEÒýÇæ**£ººÏ»÷¼¼ÄÜ´¥·¢Ê±ÓÐÈ«ÆÁÕð¶¯Ð§¹û
- **GEEÒýÇæ**£ºÖ§³ÖʵʱÌìÆøÏµÍ³£¨ÓêѩЧ¹ûËæ·þÎñÆ÷ʱ¼ä±ä»¯£©
##### 3. **Îļþ½á¹¹ÌØÕ÷**
```shell
# ½â°üµÇ¼Æ÷ºó²é¿´ºËÐÄÄ£¿é
HEROÒýÇæ£º±Øº¬HeroM2.dll + Client.dat
BLUEÒýÇæ£ºBlueEngine.dat + AntiCheat.sys
GOMÒýÇæ£ºM2Plugin.x64 + UI.bin
```
##### 4. **ÍøÂçÐÒéÌØÕ÷**
ʹÓÃWireshark×¥°ü·ÖÎö£º
- HEROÒýÇæ²ÉÓÃ**TCP¶ÌÁ¬½Ó**£¨¶Ë¿Ú7000£©
- BLUEÒýÇæÊ¹ÓÃ**UDP+TCP»ìºÏ´«Êä**£¨¶Ë¿Ú7100/7200£©
- GEEÒýÇæÆôÓÃ**WebSocket¼ÓÃÜͨµÀ**£¨¶Ë¿Ú8888£©
##### 5. **ÄÚ´æ×¤ÁôÌØÕ÷**
ͨ¹ýCheatEngineɨÃ裺
```lua
if ·¢ÏÖ"HeroM2_BaseAddr" then Åж¨ÎªHEROÒýÇæ
if ´æÔÚ"BlueAntiCheat"Ïß³Ì then Åж¨ÎªBLUEÒýÇæ
```
---
#### Èý¡¢½ø½×ÄæÏò·ÖÎö·¨£¨GM/¿ª·¢ÕßÏò£©
##### 1. **¶þ½øÖÆÌØÕ÷Âëʶ±ð**
```python
# ÌáÈ¡ÒýÇæÖ¸ÎÆ£¨PythonʾÀý£©
def check_engine(file_path):
with open(file_path, 'rb') as f:
header = f.read(512)
if b'\x48\x45\x52\x4F\x4D\x32' in header: # HEROM2
return "HERO"
elif b'\x42\x6C\x75\x65\x45\x6E\x67' in header: # BlueEng
return "BLUE"
```
##### 2. **APIµ÷ÓÃÁ´·ÖÎö**
- HEROÒýÇæ±Øµ÷ÓÃ`LoadHeroDB()`º¯Êý
- BLUEÒýÇæ°üº¬`BlueCheckModule()`·´Íâ¹ÒУÑé
- GEEÒýÇæÊ¹ÓÃ`GeeAIDynamic()`¶¯Ì¬Æ½ºâËã·¨
##### 3. **×¢²á±í²ÐÁô¼ì²â**
```reg
Windows×¢²á±í·¾¶£º
HEROÒýÇæ£ºHKEY_LOCAL_MACHINE\SOFTWARE\HeroM2
BLUEÒýÇæ£ºHKEY_CURRENT_USER\Software\BlueLegend
```
##### 4. **·â°üÊý¾Ý½âÃÜ**
```c
// BLUEÒýÇæÍ¨ÐŽâÃÜËã·¨£¨CÓïÑÔα´úÂ룩
void DecryptPacket(char* data, int len) {
for(int i=0; i<len; i++){
data[i] ^= 0xA7;
data[i] += i % 256;
}
}
```
---
#### ËÄ¡¢¹¤¾ß»¯Ê¶±ð·½°¸
##### 1. **רÓüì²â¹¤¾ßÍÆ¼ö**
| ¹¤¾ßÃû³Æ | ÊÊÓÃÒýÇæ | ºËÐŦÄÜ | ÏÂÔØÔ´ |
|----------------|---------------------|-----------------------------|----------------|
| EngineDetector | ȫϵÒýÇæ | ÌØÕ÷ÂëɨÃè+ÐÒé·ÖÎö | [www.legdet.net ](https://www.legdet.net )|
| BlueScanner | BLUE/LEGEND | ÄÚ´æ½á¹¹ÄæÏò | |
| GOMInspector | GOM/GEE | UIÔªËØÌáÈ¡+½Å±¾½âÎö | |
##### 2. **×Ô¶¯»¯Ê¶±ð½Å±¾**
```powershell
# ¿ìËÙʶ±ð½Å±¾£¨Windows»·¾³£©
$hash = Get-FileHash .\Login.exe -Algorithm SHA256
switch ($hash.Hash) {
"A3D5...E8F2" { Write-Output "HEROÒýÇæ" }
"B7C4...D9A1" { Write-Output "BLUEÒýÇæ" }
"F2E1...8B0C" { Write-Output "GEEÒýÇæ" }
}
```
---
#### Îå¡¢ÒýÇæÉú̬ÓëÊÊÅ佨Òé
##### 1. **°æ±¾¼æÈÝÐÔ¾ØÕó**
| ÒýÇæÀàÐÍ | ×î¼ÑÊÊÅä°æ±¾ | ½Å±¾À©Õ¹ÐÔ | ·´Íâ¹ÒÇ¿¶È |
|--------------|---------------------|----------------|------------|
| HERO | 1.76¸´¹Å°æ | µÍ£¨ÐèDBÀ©Õ¹£© | ¡ï¡ï¡î¡î¡î |
| BLUE | 1.80Ó¢Ðۺϻ÷ | ÖУ¨Lua»ù´¡£© | ¡ï¡ï¡ï¡ï¡î |
| GEE | µ¥Ö°ÒµÎ¢±ä | ¸ß£¨AI½Å±¾£© | ¡ï¡ï¡ï¡ï¡ï |
##### 2. **¿ª·¢ÕßÊÊÅ佨Òé**
- **»³¾É·þ**£ºÊ×Ñ¡HEROÒýÇæ+ÁÔÓ¥µÇ¼Æ÷
- **ÉÌÒµ·þ**£ºÍƼöBLUEÒýÇæ+ESP·´Íâ¹Ò
- **´´Ð·þ**£º²ÉÓÃGEEÒýÇæ+Çø¿éÁ´´æÖ¤
---
#### Áù¡¢ÒÉÄÑÎÊÌâ½â¾ö·½°¸
##### 1. **³£¼ûʶ±ð´íÎó´¦Àí**
| Òì³£ÏÖÏó | ¸ùÒò·ÖÎö | ½â¾ö·½°¸ |
|-------------------------|----------------------|-----------------------------|
| µÇ¼Æ÷ÉÁÍËÎÞ·¨Ê¶±ð | DEPÊý¾Ý±£»¤×èÖ¹ | ÔÚϵͳÊôÐÔÖйرÕDEP |
| ÌØÕ÷ÂëÆ¥Åäʧ°Ü | ÒýÇæ±»¼Ó¿Ç±£»¤ | ʹÓÃVMUnpackerÍÑ¿Ç |
| ÐÒé·ÖÎöÎÞ½á¹û | ÆôÓÃSSL¼ÓÃÜ | µ¼ÈëÒýÇæÖ¤Êéµ½Wireshark |
##### 2. **¶àÒýÇæ»ìºÏʶ±ð**
µ±Óöµ½Ä§¸Ä°æÒýÇæÊ±£¬²ÉÓÃ**È¨ÖØÆÀ·Ö·¨**£º
```mathematica
ʶ±ðÖÃÐÅ¶È = 0.3×½çÃæÌØÕ÷ + 0.4×Îļþ½á¹¹ + 0.2×ÐÒéÌØÕ÷ + 0.1×ÄÚ´æÌØÕ÷
ÈôÖÃÐÅ¶È > 0.7 ÔòÅж¨ÓÐЧ
´«ÆæÒýÇæÊǹ¹½¨Éú̬µÄ¼¼Êõ»ùʯ£¬½ØÖÁ2025ÄêÖ÷Á÷ÒýÇæÒÑÐγÉ**Áù´ó¼¼ÊõÅÉϵ**£º¸´¹Åϵ£¨HERO/BLUE£©¡¢ºÏ»÷ϵ£¨3K/LEGEND£©¡¢´´ÐÂϵ£¨GOM/GEE£©Óë¿ç¶Ëϵ£¨ôá·ç/Áú×壩¡£²»Í¬ÒýÇæÖ±½ÓÓ°ÏìÓÎÏ·Íæ·¨¡¢·´Íâ¹Ò»úÖÆ¼°½Å±¾¼æÈÝÐÔ£¬Æäʶ±ðÐè½áºÏ**½çÃæÌØÕ÷¡¢ÔËÐÐÂß¼ÓëÎļþ½á¹¹**ÈýÖØÑéÖ¤¡£
---
#### ¶þ¡¢»ù´¡Åж¨·¨£ºÎåÎ¬ÌØÕ÷¾ØÕó
##### 1. **µÇ¼Æ÷½çÃæÌØÕ÷**
| ÒýÇæÀàÐÍ | Æô¶¯½çÃæÌØÕ÷ | ×¢²á´°¿Ú±êʶ | ·Ö±æÂÊÑ¡Ïî |
|--------------|----------------------------------|------------------------|------------------|
| HERO | ×óÉϽÇÏÔʾ"HEROM2"ˮӡ | ºìÉ«±ß¿ò+¸´¹Å×ÖÌå | ½ö800x600 |
| BLUE | µ³öʽ¼ÓÔØ¶¯»£¨Í¸Ã÷¶È½¥±ä£© | À¶É«¶¯Ì¬°´Å¥ | Ö§³Ö1080P |
| 3K | ½ø¶ÈÌõ´ø"3K"LOGO | »ÆÉ«¾¯Ê¾Ìáʾ | ×Ô¶¨Òå·Ö±æÂÊ |
| GOM | ºìɫע²á³É¹¦Ìáʾ | ÒôÁ¿µ÷½Ú°´25%µÝ¼õ | ¶àµµÎ»Ô¤Éè |
| GEE | ÂÌÉ«°²È«ÈÏ֤ͼ±ê | Ö±½Ó¿ª¹ØÊ½ÒôÁ¿¿ØÖÆ | ÎÞ¼¶Ëõ·Å |
##### 2. **ÓÎÏ·ÄÚ¹¦ÄܱíÏÖ**
- **HEROÒýÇæ**£º½ÇÉ«ËÀÍöºóʬÌå±£Áôʱ¼ä¹Ì¶¨60Ã룬ÎÞËÀÍöÌØÐ§
- **BLUEÒýÇæ**£ººÏ»÷¼¼ÄÜ´¥·¢Ê±ÓÐÈ«ÆÁÕð¶¯Ð§¹û
- **GEEÒýÇæ**£ºÖ§³ÖʵʱÌìÆøÏµÍ³£¨ÓêѩЧ¹ûËæ·þÎñÆ÷ʱ¼ä±ä»¯£©
##### 3. **Îļþ½á¹¹ÌØÕ÷**
```shell
# ½â°üµÇ¼Æ÷ºó²é¿´ºËÐÄÄ£¿é
HEROÒýÇæ£º±Øº¬HeroM2.dll + Client.dat
BLUEÒýÇæ£ºBlueEngine.dat + AntiCheat.sys
GOMÒýÇæ£ºM2Plugin.x64 + UI.bin
```
##### 4. **ÍøÂçÐÒéÌØÕ÷**
ʹÓÃWireshark×¥°ü·ÖÎö£º
- HEROÒýÇæ²ÉÓÃ**TCP¶ÌÁ¬½Ó**£¨¶Ë¿Ú7000£©
- BLUEÒýÇæÊ¹ÓÃ**UDP+TCP»ìºÏ´«Êä**£¨¶Ë¿Ú7100/7200£©
- GEEÒýÇæÆôÓÃ**WebSocket¼ÓÃÜͨµÀ**£¨¶Ë¿Ú8888£©
##### 5. **ÄÚ´æ×¤ÁôÌØÕ÷**
ͨ¹ýCheatEngineɨÃ裺
```lua
if ·¢ÏÖ"HeroM2_BaseAddr" then Åж¨ÎªHEROÒýÇæ
if ´æÔÚ"BlueAntiCheat"Ïß³Ì then Åж¨ÎªBLUEÒýÇæ
```
---
#### Èý¡¢½ø½×ÄæÏò·ÖÎö·¨£¨GM/¿ª·¢ÕßÏò£©
##### 1. **¶þ½øÖÆÌØÕ÷Âëʶ±ð**
```python
# ÌáÈ¡ÒýÇæÖ¸ÎÆ£¨PythonʾÀý£©
def check_engine(file_path):
with open(file_path, 'rb') as f:
header = f.read(512)
if b'\x48\x45\x52\x4F\x4D\x32' in header: # HEROM2
return "HERO"
elif b'\x42\x6C\x75\x65\x45\x6E\x67' in header: # BlueEng
return "BLUE"
```
##### 2. **APIµ÷ÓÃÁ´·ÖÎö**
- HEROÒýÇæ±Øµ÷ÓÃ`LoadHeroDB()`º¯Êý
- BLUEÒýÇæ°üº¬`BlueCheckModule()`·´Íâ¹ÒУÑé
- GEEÒýÇæÊ¹ÓÃ`GeeAIDynamic()`¶¯Ì¬Æ½ºâËã·¨
##### 3. **×¢²á±í²ÐÁô¼ì²â**
```reg
Windows×¢²á±í·¾¶£º
HEROÒýÇæ£ºHKEY_LOCAL_MACHINE\SOFTWARE\HeroM2
BLUEÒýÇæ£ºHKEY_CURRENT_USER\Software\BlueLegend
```
##### 4. **·â°üÊý¾Ý½âÃÜ**
```c
// BLUEÒýÇæÍ¨ÐŽâÃÜËã·¨£¨CÓïÑÔα´úÂ룩
void DecryptPacket(char* data, int len) {
for(int i=0; i<len; i++){
data[i] ^= 0xA7;
data[i] += i % 256;
}
}
```
---
#### ËÄ¡¢¹¤¾ß»¯Ê¶±ð·½°¸
##### 1. **רÓüì²â¹¤¾ßÍÆ¼ö**
| ¹¤¾ßÃû³Æ | ÊÊÓÃÒýÇæ | ºËÐŦÄÜ | ÏÂÔØÔ´ |
|----------------|---------------------|-----------------------------|----------------|
| EngineDetector | ȫϵÒýÇæ | ÌØÕ÷ÂëɨÃè+ÐÒé·ÖÎö | [www.legdet.net ](https://www.legdet.net )|
| BlueScanner | BLUE/LEGEND | ÄÚ´æ½á¹¹ÄæÏò | |
| GOMInspector | GOM/GEE | UIÔªËØÌáÈ¡+½Å±¾½âÎö | |
##### 2. **×Ô¶¯»¯Ê¶±ð½Å±¾**
```powershell
# ¿ìËÙʶ±ð½Å±¾£¨Windows»·¾³£©
$hash = Get-FileHash .\Login.exe -Algorithm SHA256
switch ($hash.Hash) {
"A3D5...E8F2" { Write-Output "HEROÒýÇæ" }
"B7C4...D9A1" { Write-Output "BLUEÒýÇæ" }
"F2E1...8B0C" { Write-Output "GEEÒýÇæ" }
}
```
---
#### Îå¡¢ÒýÇæÉú̬ÓëÊÊÅ佨Òé
##### 1. **°æ±¾¼æÈÝÐÔ¾ØÕó**
| ÒýÇæÀàÐÍ | ×î¼ÑÊÊÅä°æ±¾ | ½Å±¾À©Õ¹ÐÔ | ·´Íâ¹ÒÇ¿¶È |
|--------------|---------------------|----------------|------------|
| HERO | 1.76¸´¹Å°æ | µÍ£¨ÐèDBÀ©Õ¹£© | ¡ï¡ï¡î¡î¡î |
| BLUE | 1.80Ó¢Ðۺϻ÷ | ÖУ¨Lua»ù´¡£© | ¡ï¡ï¡ï¡ï¡î |
| GEE | µ¥Ö°ÒµÎ¢±ä | ¸ß£¨AI½Å±¾£© | ¡ï¡ï¡ï¡ï¡ï |
##### 2. **¿ª·¢ÕßÊÊÅ佨Òé**
- **»³¾É·þ**£ºÊ×Ñ¡HEROÒýÇæ+ÁÔÓ¥µÇ¼Æ÷
- **ÉÌÒµ·þ**£ºÍƼöBLUEÒýÇæ+ESP·´Íâ¹Ò
- **´´Ð·þ**£º²ÉÓÃGEEÒýÇæ+Çø¿éÁ´´æÖ¤
---
#### Áù¡¢ÒÉÄÑÎÊÌâ½â¾ö·½°¸
##### 1. **³£¼ûʶ±ð´íÎó´¦Àí**
| Òì³£ÏÖÏó | ¸ùÒò·ÖÎö | ½â¾ö·½°¸ |
|-------------------------|----------------------|-----------------------------|
| µÇ¼Æ÷ÉÁÍËÎÞ·¨Ê¶±ð | DEPÊý¾Ý±£»¤×èÖ¹ | ÔÚϵͳÊôÐÔÖйرÕDEP |
| ÌØÕ÷ÂëÆ¥Åäʧ°Ü | ÒýÇæ±»¼Ó¿Ç±£»¤ | ʹÓÃVMUnpackerÍÑ¿Ç |
| ÐÒé·ÖÎöÎÞ½á¹û | ÆôÓÃSSL¼ÓÃÜ | µ¼ÈëÒýÇæÖ¤Êéµ½Wireshark |
##### 2. **¶àÒýÇæ»ìºÏʶ±ð**
µ±Óöµ½Ä§¸Ä°æÒýÇæÊ±£¬²ÉÓÃ**È¨ÖØÆÀ·Ö·¨**£º
```mathematica
ʶ±ðÖÃÐÅ¶È = 0.3×½çÃæÌØÕ÷ + 0.4×Îļþ½á¹¹ + 0.2×ÐÒéÌØÕ÷ + 0.1×ÄÚ´æÌØÕ÷
ÈôÖÃÐÅ¶È > 0.7 ÔòÅж¨ÓÐЧ

