Author Topic: My Steam/Unity game is being marked suspicious?  (Read 1676 times)

0 Members and 1 Guest are viewing this topic.

Offline JayRI

  • Newbie
  • *
  • Posts: 1
My Steam/Unity game is being marked suspicious?
« on: October 03, 2022, 03:41:36 PM »
Hi,

I'm the developer for a PC Steam game "Airship: Kingdoms Adrift" (Here: https://store.steampowered.com/app/1597310/Airship_Kingdoms_Adrift/)

Users in my community have been reporting that our game is marked by Avast as a suspicious file, even though it was packaged and compiled by Unity. The screenshot is below:



Please help check this out and see what we can do to avoid this in the future.

Thank you!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: My Steam/Unity game is being marked suspicious?
« Reply #1 on: October 03, 2022, 04:32:45 PM »
Quote
Please help check this out and see what we can do to avoid this in the future.
https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438



Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89015
  • No support PMs thanks
Re: My Steam/Unity game is being marked suspicious?
« Reply #2 on: October 03, 2022, 05:57:33 PM »
@  JayRI
Is the file digitally signed as that may help.

From your screenshot, this file has been sent to the Avast Threat Labs, where it could well be considered a False Positive.

Though it didn't trigger full malware alert.  Did there happen to be any more information in the See details option in your screenshot ?

Does this file/game include any anti-cheat function  ?
The reason I mention this is that could well trigger suspicion of what it is trying to do.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: My Steam/Unity game is being marked suspicious?
« Reply #3 on: October 04, 2022, 03:50:36 PM »
Hi JayRI,

Not necessarily it is that the software as such is being flagged,
but it could well be that the IP, that it is being served up from is.
See -> https://sitereport.netcraft.com/?url=https://23.194.105.162
with a nine red out of ten risk rating -
so it may well be akamai-server related,

However not detected nor flagged at VT:
https://www.virustotal.com/gui/url/cbb9039851a03f0c6a2c09a9c9a42d1283d928d4d6d695c54dde22a74cc18f3a/details
nor this being flagged either here: https://www.virustotal.com/gui/ip-address/23.194.105.162/relations

Well probably the akamai server missing security headers is being flagged as an issue-
because see the overall CSP status. with a meagre D-status scan result here: https://securityheaders.com/?q=https%3A%2F%2Fstore.steampowered.com%2Fapp%2F1597310%2FAirship_Kingdoms_Adrift%2F

Wait for a final verdict from avast team members, as they are the only ones to come and unblock
as it is their definitions.

We here are just volunteers with relative knowledge in the field of cold recon and error-hunting website security.

polonus (volunteer 3rd-party cold reconnaissance website security analyst and website error-hunter)
« Last Edit: October 04, 2022, 03:52:31 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!