DayZ
Ez a téma zárolásra került
DAYZSA Launcher : Is it safe?! Or Is it official?
Simple question in the title.
Eredetileg közzétette: Nica:
The launcher is not official but no security threats have been identified or reported. So as of now... Safe?
< >
115/37 megjegyzés mutatása
Apparently not, its the same thing as DAYZ mod launcher, full of adware/mallware.

E téma szerzője jelezte, hogy ez a hozzászólás megválaszolja a témát.
The launcher is not official but no security threats have been identified or reported. So as of now... Safe?
Legutóbb szerkesztette: Nica; 2019. ápr. 24., 10:41
Nica eredeti hozzászólása:
The launcher is not official but no security threats have been identified or reported. So as of now... Safe?

Well, as soon as I started to load some mods for a server, BitDefender 2019 said the Launcher was infected with virus (malware). I had to clean and clear it.

Thread closed please.

Legutóbb szerkesztette: KenoKereStyle; 2019. ápr. 24., 12:20
Launcher is safe. As for mods, anything goes with steam
KenoKereStyle eredeti hozzászólása:
Nica eredeti hozzászólása:
The launcher is not official but no security threats have been identified or reported. So as of now... Safe?

Well, as soon as I started to load some mods for a server, BitDefender 2019 said the Launcher was infected with virus (malware). I had to clean and clear it.

Thread closed please.
Possibly a false positive. I have ran checks on it with both Malwarebytes and F-secure and neither one flagged any issues. Are you sure you were downloading from the official DZSA launcher website?
Nica eredeti hozzászólása:
KenoKereStyle eredeti hozzászólása:

Well, as soon as I started to load some mods for a server, BitDefender 2019 said the Launcher was infected with virus (malware). I had to clean and clear it.

Thread closed please.
Possibly a false positive. I have ran checks on it with both Malwarebytes and F-secure and neither one flagged any issues. Are you sure you were downloading from the official DZSA launcher website?

Yep, DZSA launcher, the red website with 2018 trademark, released in december 2018... probably was like Sinister said, something in the mods.
Nica eredeti hozzászólása:
The launcher is not official but no security threats have been identified or reported. So as of now... Safe?

My Malwarebytes (paid) has been detecting and blocking a request from DZSA launcher to a site that attempts to install a trojan. I have been trying to find the solution which is what led me here... So there is that.

Davis Lawrence eredeti hozzászólása:
Nica eredeti hozzászólása:
The launcher is not official but no security threats have been identified or reported. So as of now... Safe?

My Malwarebytes (paid) has been detecting and blocking a request from DZSA launcher to a site that attempts to install a trojan. I have been trying to find the solution which is what led me here... So there is that.
contact the author. Thanks for letting me know, but i take it that you are not a cyber-security expert and this might just be a false-flag
VIRUSTOTAL REPORT ON: dayzsalauncher.com / www.dayzsalauncher.com

This is a snip of the VirusTotal info on dzsa launcher website/download.
Do your own research go to VirusTotal, enter dzsa url.

dayzsalauncher.com
www.dayzsalauncher.com
https://dayzsalauncher.com/#/home

Server information: dayzsalauncher.com - Registrar: 123-Reg Limited
https://www.123-reg.co.uk/

https://www.virustotal.com/gui/domain/dayzsalauncher.com/relations

Inside VirusTotal, Under -> Relations: Look in -> Files Referring
Some pretty nasty stuff.

10+ detected files embedding this domain: dayzsalauncher.com www.dayzsalauncher.com

Scanned Detections Type Name

2021-02-14 20/70 Win32 EXE TDOE_Check_Server_v4.exe
2020-08-01 41/71 Win32 EXE Command line RAR
2019-07-30 6/69 Win32 EXE DZSALauncher.exe

Whois Record for DayzSalaunCher.com
Website Title 500 SSL negotiation failed

Whois Record for DayzSalaunCher.com
https://whois.domaintools.com/dayzsalauncher.com
Registrar 123-Reg Limited
IANA ID: 1515
URL: http://www.meshdigital.com
Whois Server: whois.123-reg.co.uk

Name Servers
GREG.NS.CLOUDFLARE.COM
LEAH.NS.CLOUDFLARE.COM

Conclusion: I've downloaded and used DZSA for over a year, ran into issues after download but never connected the dots.
After this research, I will no longer use DZSA Launcher, ever.
DayZ has a launcher in Steam. Use it and be safe.

More than welcome to do your own research.
Legutóbb szerkesztette: Third Eye; 2021. ápr. 9., 3:46
More info on DZSA Launcher:


** Hybrid Analysis Technology

Submission name:
setup_dzsalauncher.exe malicious Threat Score: 85/100 AV Detection: 20% Labeled as: Win/malicious_confidence_60%
setup_dzsalauncher(1).exe ambiguous Threat Score: 85/100 AV Detection: 20% Labeled as: Win/malicious_confidence_60%

This report is generated from a file or URL submitted to this webservice on January 25th 2020 21:41:32 (UTC)
Guest System: Windows 7 32 bit, Professional, 6.1 (build 7601), Service Pack 1
Report generated by Falcon Sandbox v8.30 © Hybrid Analysis

Risk Assessment

Spyware
Found a string that may be used as part of an injection method
Persistence
Writes data to a remote process
Fingerprint
Queries process information
Reads the active computer name
Evasive
Marks file for deletion
Spreading
Opens the MountPointManager (often used to detect additional infection locations)
Network Behavior
Contacts 2 domains.
Drops executable files

* MITRE ATT&CK™ Techniques Detection
We found MITRE ATT&CK™ data in one report, this report has 17 mapped indicators.

* Spyware/Information Retrieval

Contains ability to retrieve keyboard strokes
details: GetKeyboardState@user32.dll

To see the whole report:
https://www.hybrid-analysis.com/sample/61ad236f32e5c38d76312a0b368656f1489bbeea7ae2ab091eaa76f5fc49e3e9
I stick to the native launcher for Dayz. I never use third party launchers for any game I have on steam.

The vast majority if not all third party launchers are pretty much garbage so be safe, and use the launcher designed by the development team.
Legutóbb szerkesztette: MycroftCanadaNS; 2021. ápr. 9., 8:14
It's bad enough we have Microsoft Windows 10 crammed down our throats. The spyware system masquerading as a operating system. Win10 is the worst. Going deep and digging through Win10. Conclusion: They created Windows 10 with one thing in mind. Data Mining and spying, that's all Win10 is good for. Everything defaults to ON out of the box, like swiss cheese. The PowerShell, omg. Good luck disabling or uninstalling PowerShell, a serious security threat.

Windows 10 Is Spyware
What is different with the newest iteration of Windows is that Microsoft is directly involved in that spying and data-mining and has built the entire operating system in such a way as to allow it.
https://thenewamerican.com/windows-10-is-spyware/

Windows 10 is possibly the worst spyware ever made
Buried in the service agreement is permission to poke through everything on your PC.
https://www.networkworld.com/article/2956574/windows-10-privacy-spyware-settings-user-agreement.html
Legutóbb szerkesztette: Third Eye; 2021. ápr. 10., 10:36
MycroftCanadaNS eredeti hozzászólása:
I stick to the native launcher for Dayz. I never use third party launchers for any game I have on steam.

The vast majority if not all third party launchers are pretty much garbage so be safe, and use the launcher designed by the development team.
:steamthumbsup::steamthumbsup::steamthumbsup:
LooP eredeti hozzászólása:
VIRUSTOTAL REPORT ON: dayzsalauncher.com / www.dayzsalauncher.com

This is a snip of the VirusTotal info on dzsa launcher website/download.
Do your own research go to VirusTotal, enter dzsa url.

dayzsalauncher.com
www.dayzsalauncher.com
https://dayzsalauncher.com/#/home

Server information: dayzsalauncher.com - Registrar: 123-Reg Limited
https://www.123-reg.co.uk/

https://www.virustotal.com/gui/domain/dayzsalauncher.com/relations

Inside VirusTotal, Under -> Relations: Look in -> Files Referring
Some pretty nasty stuff.

10+ detected files embedding this domain: dayzsalauncher.com www.dayzsalauncher.com

Scanned Detections Type Name

2021-02-14 20/70 Win32 EXE TDOE_Check_Server_v4.exe
2020-08-01 41/71 Win32 EXE Command line RAR
2019-07-30 6/69 Win32 EXE DZSALauncher.exe

Whois Record for DayzSalaunCher.com
Website Title 500 SSL negotiation failed

Whois Record for DayzSalaunCher.com
https://whois.domaintools.com/dayzsalauncher.com
Registrar 123-Reg Limited
IANA ID: 1515
URL: http://www.meshdigital.com
Whois Server: whois.123-reg.co.uk

Name Servers
GREG.NS.CLOUDFLARE.COM
LEAH.NS.CLOUDFLARE.COM

Conclusion: I've downloaded and used DZSA for over a year, ran into issues after download but never connected the dots.
After this research, I will no longer use DZSA Launcher, ever.
DayZ has a launcher in Steam. Use it and be safe.

More than welcome to do your own research.

you have reassured my long lost faith in humanity. this information is astounding. ill be spreading the news. alot of my friends use DZSA launcher. i have it aswell.

as for anyone trying to block it, sounds like 2 outbound connections, thats firewall related, or modem related. you can block the entire domain.
< >
115/37 megjegyzés mutatása
Laponként: 1530 50

Közzétéve: 2019. ápr. 24., 10:33
Hozzászólások: 37