Probaly it's just trigger on dev used protect in exe (descripted like enigmaprotector.com).
Full report on anyrun
You must be registered to see the links
Okay I analyzed it deeper, from what I understand a XOR inverted url was found in the executable code, which triggered a detection. That url being enigmaprotector site, which is in turn is a type of DRM.
Mayhaps the game uses enigmaprotector and validates through it, but the address is XOR'rd in the game code to make it harder to crack, in turn causing AVs to trip out as xoring a URL could also be used to obfuscate addresses in actual malicious software?
Source: 50% I'm a software engineer, other 50% talking out of my ass because I'm a business software engi not gamedev nor am I good with cybersec.