As with most forms of theft and laundering, it's not really that clever.
>> This document records behavior established from static analysis of the retail TotalA.exe. It is a clean-room behavioral contract, not a source translation. It deliberately omits executable addresses, data-image offsets, and raw decompiler names. The phrases established, supported inference, and unknown distinguish what the analysis proves from what remains a useful but unverified interpretation.
The evidence is the executable's own control and data flow, its PE import table, and its embedded string vocabulary. Nothing here is taken from another engine, a capture, or a reimplementation.
Step 1: Ask an LLM to decompile a binary, wash it into a "clean" description of the binary in its own format (a bunch of .MD files, one might suppose) and then build a new binary from that description.
Step 2: Nothing.
Is this really going to hold up in court?