Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Open Source game that's been around forever, question about contacted IPs and response from Mods/Devs on the issue

0
Medium
Published: 07/22/2026 (07/22/2026, 04:34:19 UTC)
Source: Reddit Cybersecurity

Description

A discussion on Reddit raised concerns about the open-source game Cataclysm: Dark Days Ahead (version 0.I) contacting an external IP address, which triggered VirusTotal behavioral flags. The developers explained some false positives related to file detection but were dismissive regarding the IP contact questions. No confirmed malicious activity or exploitation is reported. The community member sought clarification due to perceived dismissiveness and unexplained network behavior.

Reddit Discussion

r/cybersecurity·posted by u/Melodic_Oak
00

My question is in regards to a game called "Cataclysm Dark Days Ahead"

It's an open-source project that's been around for many years. I played it a lot in the past, and it caught my interest again recently, as they released a new stable version on their GitHub: https://github.com/CleverRaven/Cataclysm-DDA/releases/tag/0.I

I usually tend to be a little paranoid, and like to check things, so I ran the zip, and the exe though VirusTotal.

Both came back with results:

The ZIP: https://www.virustotal.com/gui/file/cc69c15de637af5a95456fdb1df7a42090be93ee36f2341835ae8b499d747c73

The EXE: https://www.virustotal.com/gui/file/94f14503c807f99a5cd2b9ebfcd389892589dbcaac95bbbbe81e62a7efa54954/behavior

I'm sure the vast majority of behavioral flags are false positives. When I asked them about some of them, they were able to explain the Bloodhound flag on the ZIP as being a false positive, relating to it detecting files that ended with "_containers.json"

https://imgur.com/a/BxkhOxV

The explanation made sense to me, so I moved on to my next issue, that the exe appears to be contacting a single IP address: https://www.virustotal.com/gui/ip-address/162.159.36.2

https://imgur.com/a/mPoGaCf

https://imgur.com/a/MTsB3WY

When I asked about this, I felt like, as where my other question they were very ready and willing to answer and help with, they were aggressively dismissive of my IP concern (Moderator and Dev posts are whited out, while mine are greyed out):

https://imgur.com/a/tUnzzqz

https://imgur.com/a/G7MvLSv

https://imgur.com/a/n7fDAAg

Which felt a little strange. I don't know why a contact IP would be listed if absolutely no communication is happening? And if there really isn't, why the devs (that were actively engaging with me on this) wouldn't readily have an explanation as to why it's not happening, but *says* that it is? I felt a little weirded out by the exchange, honestly.

The "again we can't help you find something that isn't happening" and the "I'm pretty certain your virustotal is freaking out" both seem needlessly rude and dismissive, but also, and I fully admit I could be wrong about this, incorrect.

Again, I'm not accusing the devs or mods of anything other than maybe being a little stand-offish about it, but I'd be very curious to have an explanation as to *why* this is happening. My questions come from a place of caution, and curiosity. I admit my ignorance because I want to learn.

Any thoughts, explanations, and whatnot are incredibly appreciated.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 04:37:02 UTC

Technical Analysis

The open-source game Cataclysm: Dark Days Ahead, specifically the 0.I release, was analyzed by a user who found VirusTotal behavioral flags on the executable and ZIP files. The ZIP's flagged behavior was explained by the developers as a false positive related to files ending with '_containers.json'. However, the executable appeared to contact a single IP address (162.159.36.2), raising user concerns. The developers and moderators responded dismissively to inquiries about this network activity without providing a clear explanation. No evidence of malicious code or remote code execution exploitation is presented, and no official vendor advisory or patch information is available.

Potential Impact

There is no confirmed impact or exploitation associated with this observation. The flagged behaviors appear to be false positives or unexplained network activity without demonstrated malicious intent. No known exploits or vulnerabilities have been confirmed in the game version discussed.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official advisory or patch information is available and no confirmed malicious activity is reported, users should monitor official channels for updates. The developers have addressed some false positives but have not clarified the network contact behavior. No urgent remediation is indicated based on current information.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":20,"reasons":["external_link","newsworthy_keywords:rce","non_newsworthy_keywords:question,vs","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["rce"],"foundNonNewsworthy":["question","vs"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a6048e89c2644c7f85c736b

Added to database: 07/22/2026, 04:36:56 UTC

Last enriched: 07/22/2026, 04:37:02 UTC

Last updated: 07/22/2026, 06:21:52 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses