Welcome to hackvshack.net Forum!
Download Free HvH CS2/CS:GO Cheats, CFG, LUA/JS Scripts, and More!
Register

Info Vape V4.22 (updated) - cloud included (1500+ users registered) | free by me [chirsbow]

chirsbow

Newbie HvHer
User ID:
267353
Messages:
8
Reactions:
0
Badges:
1
REP:
−0/0+
Level:
18
Hello, I am glad to say that I finished it.

this is FULL vape v4 fork, full website, loader, hwid lock, payment, etc.

one thing that I wanna mention all the prices are 0.00$ and no credit card info needed it's just for the feeling of "buying" vape.

if people will actually want I will also publish vape lite which almost no one wants but yeah

(Change logs, 4.22.x devlog - 3 devlogs has been pushed + daily updates)

Lunar Client Mapping has been updated and works as usual.

Showcase/Tutorial:



Supported versions:
- 1.7.10-26.2 (all versions supported)

Menu key: right shift

Cache Location: %appdata%/.vapeclient (also errors are going to be here)

How to run:
1. go to
2. Register Account
3. "Purchase" Vape V4 for 0$
4. Reset HWID (follow the instructions there)
5. Open the Loader (that will be provided here) Login and inject
6. Have Fun!

Note: it has no protection/obfuscation so if you are unsure if it's safe please reverse engineer it 🙂
 
Last edited:
bro what is that safe or rat?
is it safe?
I made it, and it's safe but before you say "you made it so that's why you say"
1. check reviews
2. please reverse engineer the loader and see by yourself what it does (it has no protection/obfuscation)
3. "it's getting flagged by virustotal" that's because the injection method "but vape v4 doesn't have that much flags" that's because vape v4 official loader is signed what means it bypass antivirus (also, sometimes you still need to disable antivirus to use official vape v4 loader you can read it from their official site: )
 
why not just make a thread under minecraft clients and just wait for approval?
I already did, but he told me that I would have to basically remove cloud because everything must be in the forums.
and I am not willing to remove the cloud as this is the whole point of it.
 
is it safe?
I made it, and it's safe but before you say "you made it so that's why you say"
1. check reviews
2. please reverse engineer the loader and see by yourself what it does (it has no protection/obfuscation)
3. "it's getting flagged by virustotal" that's because the injection method "but vape v4 doesn't have that much flags" that's because vape v4 official loader is signed what means it bypass antivirus (also, sometimes you still need to disable antivirus to use official vape v4 loader you can read it from their official site: )
working on tlauncher?
 
As much as ive searched its a bit sketchy. I dont say its a rat or safe, but after test running in sandboxes, tria.ge, virustotal. Ive gotten a few conclusions:
1. All Virustotal flags are explainable, If you read the flags in virus total you will find terms like "Gamehack" or "Malware" or "Riskware", with only microsoft marking it as trojan . Tho to my conclusions, i believe that a lot of av's dont have a specific flag for hacks and only a few having the "gamehack" flag so its seems safe in this point
2. The really sketchy part is i tried running hwid.exe and vape .exe in both tria.ge and a sandbox, and the sketchy part itself is that in tria.ge wont run, in a sandbox it requires a series of .dll's that need to be installed which wont work in a sandbox, thats sketchy but it makes sense due to it being ran on a sandbox.

Thats as much as ive tested, have fun.
Links to all reports i got:
&
 
As much as ive searched its a bit sketchy. I dont say its a rat or safe, but after test running in sandboxes, tria.ge, virustotal. Ive gotten a few conclusions:
1. All Virustotal flags are explainable, If you read the flags in virus total you will find terms like "Gamehack" or "Malware" or "Riskware", with only microsoft marking it as trojan . Tho to my conclusions, i believe that a lot of av's dont have a specific flag for hacks and only a few having the "gamehack" flag so its seems safe in this point
2. The really sketchy part is i tried running hwid.exe and vape .exe in both tria.ge and a sandbox, and the sketchy part itself is that in tria.ge wont run, in a sandbox it requires a series of .dll's that need to be installed which wont work in a sandbox, thats sketchy but it makes sense due to it being ran on a sandbox.

Thats as much as ive tested, have fun.
Links to all reports i got:
&
Reverse Engineer it easier then guessing, or being unsure. see exactly what it does - it has NO protection/obfuscation what means you can EASILY reverse it and see exactly what it does.
 
As much as ive searched its a bit sketchy. I dont say its a rat or safe, but after test running in sandboxes, tria.ge, virustotal. Ive gotten a few conclusions:
1. All Virustotal flags are explainable, If you read the flags in virus total you will find terms like "Gamehack" or "Malware" or "Riskware", with only microsoft marking it as trojan . Tho to my conclusions, i believe that a lot of av's dont have a specific flag for hacks and only a few having the "gamehack" flag so its seems safe in this point
2. The really sketchy part is i tried running hwid.exe and vape .exe in both tria.ge and a sandbox, and the sketchy part itself is that in tria.ge wont run, in a sandbox it requires a series of .dll's that need to be installed which wont work in a sandbox, thats sketchy but it makes sense due to it being ran on a sandbox.

Thats as much as ive tested, have fun.
Links to all reports i got:
&
Update:
Just like the creator kept saying, the file is indeed unprotected. And as much as im aware i havent found anything that screams malware, it seems safe with everything i tried and havent seen any signs of obvious malware. Injection method seems correct, files seem right, also anyone can get the payload dll " " now on virustotal scans it only got 3/64 rating which seems like just false positives, i also inspected files myself i think its safe, ill try it out and see how it does.

A suggestion for the owner, first add a source code option so its easy for us to file check,
&
Un related a suggestion unrelated to the safety of this file, create a "creator program" where ppl can sign up with someones creator code, make it available for yt-ers and more, js would be a cool thing, makes it more like vape v4 original. idk
 
i tried scanning this via chatgpt and this is what i got, i scanned both the dll, and exe.





d2651e7d.exe
File

can you see if this is safe.


I checked the uploaded d2651e7d.exe statically. I would not consider it safe to run yet.

A few things stand out:

  • It is a Windows 64-bit executable, about 1.36 MB.
  • It imports networking functions from WS2_32.dll and has WinHTTP-related strings, meaning it can communicate over the network.
  • More importantly, it contains functionality/strings associated with process injection:
    • OpenProcess
    • VirtualAllocEx
    • WriteProcessMemory
    • CreateRemoteThread
    • LoadLibrary
  • It explicitly contains strings such as:
    • Failed to inject NativeLoader.dll
    • NativeLoader.dll
    • Product DLL loading
    • Already Injected
    • Loader controller socket
    • /loader/login
  • It requests highestAvailable Windows privileges.
  • It is not digitally signed according to the PE security directory.
  • Its embedded timestamp is September 1, 2026.
That doesn't automatically mean it's malware. The wording strongly suggests this may be a DLL injector/loader, which can be legitimate for things like game modding, but the same techniques are also commonly used by malware.

I would not double-click it on your main PC yet.

If you tell me where you got this EXE / what program it's supposed to be, I can investigate the file's identity and compare its hash against known/public sources. The SHA-256 I extracted is:

05382bb9d0f2a113fad2ab4c9de271cd252ad e b75db8432c1dc91e9531f9c9a0



no other stuff that may seem like its a rat/stealer


Yeah — if you're specifically looking for RAT/stealer behavior, that's the right thing to investigate. The injection APIs alone don't prove it's a RAT.

From the static indicators I can see, I don't see an obvious smoking gun like:

  • Credential/browser password theft
  • Cookies/session-token theft
  • Discord token harvesting
  • Crypto-wallet targeting
  • Keylogging
  • Screenshot/webcam capture
  • Persistence mechanisms such as Run keys or scheduled tasks
  • Windows Defender tampering
  • Ransomware/file-encryption behavior
  • Obvious C2 commands such as a hidden reverse shell
However, there are network/loader components, including WinHTTP and the "Loader controller socket" / "/loader/login" strings. Combined with NativeLoader.dll injection, that's enough that I wouldn't call it clean without going deeper.

The SHA-256 is:

05382bb9d0f2a113fad2ab4c9de271cd252adeb75db8432c1dc91e9531f9c9a0

If you want, I can do a much deeper RAT/stealer-focused inspection of this exact EXE—looking specifically for browser/Discord token theft, credential access, persistence, C2 addresses/domains, obfuscation, anti-analysis, and suspicious Windows APIs.







NativeLoader.dll
File

now this


I checked NativeLoader.dll much more deeply, specifically for RAT/stealer indicators.

Verdict: I don't see evidence of a RAT/stealer​

This DLL is 24.5 MB and contains a large embedded Java/Vape client. The package names and classes strongly identify it as a Vape.gg Minecraft client native component, rather than a generic Windows RAT.

I specifically looked for:

  • ❌ Discord token stealing — nothing found
  • ❌ Chrome/Edge/Firefox password extraction — nothing found
  • ❌ Browser cookie databases — nothing found
  • ❌ Crypto-wallet theft — nothing found
  • ❌ Telegram credential theft — nothing found
  • ❌ Keylogger — nothing found
  • ❌ Screenshot capture — nothing found
  • ❌ Webcam capture — nothing found
  • ❌ Windows startup/Run-key persistence — nothing found
  • ❌ Credential Manager harvesting — nothing found
  • ❌ CryptUnprotectData/DPAPI usage — nothing found
The cookie strings I found are from Netty's normal HTTP cookie library, not browser-cookie harvesting. Likewise, keystroke is associated with Vape's Keystrokes HUD, and AccountCredentials is an actual Vape class for Minecraft account authentication.

Things that are expected but worth noting​

The DLL does have:

  • GetAsyncKeyState
  • Clipboard APIs
  • Network sockets
  • HTTP functionality
  • Java/Minecraft authentication code
  • Native code for injecting/bridging into Minecraft
Those sound scary in isolation, but they're consistent with what a Minecraft client/modification like Vape needs to do.

In particular, I found actual Minecraft/Xbox authentication code that communicates with Microsoft's authentication endpoints. That's very different from silently stealing browser credentials.

The DLL exports only:

  • JNI_OnLoad
  • JNI_OnUnload
and identifies itself internally as Vape421Native.dll.

One important connection​

The previous d2651e7d.exe specifically contained:

Failed to inject NativeLoader.dll
and this DLL contains the Vape native runtime.

So the two files appear to be related components of the same loader/client, rather than the EXE randomly downloading an unrelated malicious DLL.

Based on the static analysis, I don't see RAT/stealer behavior in this DLL. I would still avoid calling it 100% safe solely from static analysis, but this is substantially less suspicious than the initial EXE looked when we only saw its injection functionality.

SHA-256 of this DLL:

5a488f2f47cee1c51054829292a8db3af8daae344c7227c90ff1d58d34ef50bf
 

Who has read this thread (Total: 3) in last 1 hours View details