Sophos - DynamicShellcode exploit alert

Sophos Home endpoint protection is detecting malicious behavior.

Attack Intercepted
‘Diablo IV Retail 0.8’ has been terminated to prevent execution of malicious code.

“An attempt to exploit an application vulnerability was prevented”

DynamicShellcode in Diablo IV - Beta\Diablo IV.exe

1 Like

I just had this as well, I reported the false positive to sophos and allowed it in my dashboard with them.

Pop-up verbiage:
“Attack Intercepted ‘Diablo IV Retail 0.8’ has been terminated to prevent execution of malicious code. No malicious files were recognized as part of this attack. SmartScan will check your computer again in a few days once we learn more.”

Hey you two,

Thanks for the report. When we see this it’s typically a false positive that needs to be reported to the company that runs the software as zypherion did.

I’d make sure that sophos is fully up to date, and if it doesn’t work just reach out to sophos support so they can modify their definitions and help you allow list Diablo 4.

1 Like

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.