do not use Game.exe - ショートカット.lnk, it tries to connect to every single network on your wifi/lan, the problem doesn't stem from zetsu, but whoever shared the original game on hentaibanchi.
it even tried to connect to my roku tv >_>
FYI there seems to be nothing malicious with this shortcut, like hidden command and shit.
@orensan it launches the Windows Explorer, that would make sense.
Unless the game exe in gamedata is supposed to do bad things when it detect its parent process is explorer.exe i'd say its fine. But i wont test that.
let me correct myself, it wasn't hentaibanchi either, it seems the author also has this file in his demo as well, so either it's coming from the author himself, or someone modified his upload without his knowledge , either way it's still bringing multiple prongs even after the "game" has closed.
The shortcut looks ordinary, but lnk files CAN be used to execute malicious code, it's a documented attack vector used by bad actors in the past. Unsure, delete the shortcut, it's useless anyway.
That said, I'm confident this game is made in RPG Maker MV, and NWJS is present, which is basically a portable chromium browser for emulating web based games. And yes, MV is developed using web code like HTML, so it needs a "browser engine" to function. That could explain some of the network traffic, but not connecting to the local network... NWJS should only really 'phone home' to check for updates.
I ran a couple of tests with another MV game I have sitting around, and got similar results in the virustotal sandbox. So I dunno.
I'm not a cyber security expert, but I will always encourage that if you value anything on your computer, don't run random pirated games from unknown sources.
RPG games are also a terrible target for someone to use as their payload. The audience for this torrent is nowhere near as lucrative as an entire Discord server.
Comments - 5
orensan
death_toaster
NyaBro
orensan
Prick