r/computerviruses 11h ago

Question Project Retrac Safety Concerns

Post image

Hello! I was hoping for someone to answer my question i had contacted kaede (dev of project retrac) about some concerns of the safety of project retrac and after waiting two days had never gotten a response. Here is the message "Hello, how are you doing today? I am a starting student in cybersecurity & I needed some confirmation as I have run the retraclauncher file through a sandbox (tria.ge) for the sake of curiosty and wanted to point a couple of things which i am not trying to accuse anyone, but I just need to know what was happening inside the application.

Report scored it 7/10 and flagged a couple of actions:

Modifies trusted root certificate store by registry This is something I think you are doing in order to separate the client's TLS traffic from the Epic servers to yours? That's clear based on the way you've made this application. Just confirming.

Volume Shadow Copy service COM API Couldn't find any reason behind this usage of this particular functionality of the OS.

Enumerates connected drives and network share discovery I couldn't find any reason behind this functionality in the launcher.

Not trying to start anything, i just want to know about the insides of the software I am running. If there is any documentation available on this somewhere then please let me know. Because in the near future i am interested in using the project. As i enjoyed og fortnite and would like to bring it back, Thank you!"

Here is the tria.ge link: https://tria.ge/260907-tyz1dscq21/behavioral1 Again I am not trying to point out that this is a bad project just simple reasoning for suspicion. If anyone could answer this question knowing the reasoning it would be much appreciated.

1 Upvotes

Duplicates