GameIndustry.eu /  Reviews / Zombie Army 4: Dead War
Crusader Kings II

Zombie Army 4: Dead War

Publisher: Rebellion
Released: 2020
Steam ID: 694280
Genre: Shooter
System:  
Hosts entries:

Screens:
deleted discussion
deleted posting
za4 services
Features
Privacy agreement:  
Personal data:  
Forced online:  
DRM:  
Third party:  
Advertising:  
Launcher:  
Social Networks:  
Data octopus:  
Bild
Hitler’s hordes are back for more in this spine-chilling shooter from the makers of Sniper Elite 4! Abominable occult enemies, epic weapons and a harrowing new campaign for 1-4 players await in 1940s Europe, as you fight to save humankind from undead Armageddon!

  Zombie Army 4: Dead War Review

Beside of NO privacy policy, NO information or additional options for customers, there is a lot in Zombie Army 4: Dead War from Rebellion which should actually be passed on directly to competent data protection authorities.

Related forum discussion was anonymously removed without warning or hint in Steam. Unfortunately, a common procedure and behaviour when developers, publisher or Valve Corporation do not like something.

The related forum discussion was anonymously removed in Steam without warning or hint during 24 hours from the game hub.

Here is an overview for what customers can expect with this product and and also a small overview in excerpts, where the product phones, or what data it sends

Involved files - SHA1 hashes (Hash Update 22.02.2021)


- za4_dx12.exe - 97a1355ff88afebc6031eba9c192b30093014bb8
- za4_vulkan.exe - 7e98d159fbe3b244a00ad7367b34f358f7b693ce
- za4.exe - b88ab89b955e0f49992b841208cb210b8e6cc81f

Launcher


Is completly unnecessary. It's just there for advertising and Affiliate and Scrollbartracking (Launcher Javascript) and users who click on social network icons will be delivered to Facebook Trackingpixel, Twitter Ads, Google Analytics, Adsense, YouTube Stats and Doubleclick and much more.

Google Analytics and Doubleclick from Launcher


Used Google Analytics Account: UA-79368876-1
 Referal http://reb.to/ga6hh8kis leading to:

https://forum.rebellion.co.uk/?utm_source=ZA4%20Steam%20Launcher%20Base&utm_medium=Forum%20Button&utm_campaign=Steam%20Zombie%20Army%204%20Launcher&utm_content=Rebellion%20Forum%20Page

dl https://forum.rebellion.co.uk/?utm_source=ZA4%20Steam%20Launcher%20Base&utm_medium=Forum%20Button&utm_campaign=Steam%20Zombie%20Army%204%20Launcher&utm_content=Rebellion%20Forum%20Page

v 1
_v j88 <i>SDK Version Number</i>
a 1535323913 <i>Google AdSense linking number</i>
t pageview <i>Used Tracking behaviour</i>
_s 1 <i>Hit sequence</i>
dl https://forum.rebellion.co.uk/?utm_source=ZA4%20Steam%20Launcher%20Base&utm_medium=Forum%20Button&utm_campaign=Steam%20Zombie%20Army%204%20Launcher&utm_content=Rebellion%20Forum%20Page <i>Document location URL - Referal Target with Affiliate values</i>
ul de <i>User language</i>
de UTF-8
dt Rebellion Forums <i>Title of the opened Site/Source</i>
sd 24-bit
sr 2560x1440 <i>Full resolution</i>
vp 1249x1185 <i>Specifies the viewable area of the browser / device.</i>
je 0 <i>Java Enabled (0 = no, 1 = yes)</i>
_u IEBAAAABAAAAAC~ <i>Check analytics.js</i>
jid 1584332714 <i>jid variable is censored in Steam, JIID means, that Google Analytics Cookies can be tied to Google Doubleclick</i>
gjid 1074610571 <i>Tracking code version</i>
cid 28054912.1613678006 <i>User Identification with Timestamp</i>
tid UA-79368876-1 <i>Rebellion Account ID</i>
_gid 1592786491.1613678006 <i>Used to find differences between users</i>
_r 1
_slc 1
z 258779865 <i>Cache Buster</i>

Twitter and Google Analytics


Of course there is another used Google Analytics Account: UA-30775-67
 <i>http://reb.to/lt8tnd6</i>

https://twitter.com/zombiearmy?utm_source=ZA4%20Steam%20Launcher%20Base&utm_medium=Twitter%20Button&utm_campaign=Steam%20Zombie%20Army%204%20Launcher&utm_content=Zombie%20Army%20Twitter%20Page

v 1
_v j88
aip 1
a 1939409274
t pageview
_s 1
dl https://twitter.com/zombiearmy?utm_source=ZA4%20Steam%20Launcher%20Base&utm_medium=Twitter%20Button&utm_campaign=Steam%20Zombie%20Army%204%20Launcher&utm_content=Zombie%20Army%20Twitter%20Page
dp /anon/profile/tweets
ul en-us
de UTF-8
dt IGNORED
sd 24-bit
sr 1000x1000
vp 983x1000
je 0
_u YEBAAUQAAAAAAC~
jid 190466867
gjid 1345484390
cid 656863323.1613729404
tid UA-30775-67
sf 10
_gid 1919062803.1613729404
_r 1
_slc 1
z 1835764541

Launcher Hostnames


 Remote Address launcher-content.rebellion.co.uk/138.68.117.110:443
https://launcher-content.rebellion.co.uk
content2.webdev.rebellion.co.uk
 http://launcher-content.rebellion.co.uk/ZombieArmy4Steam/launcher/banners//20210216_pre-order_250.jpg
http://launcher-content.rebellion.co.uk/ZombieArmy4Steam/launcher/news.html?uniqid=602e3f584ee4b
http://launcher-content.rebellion.co.uk/ZombieArmy4Steam/launcher/jquery.min.js

Denuvo Anti-Tamper


Denuvo Anti-Tamper which is mentioned on the Storepage when starting the game from Launcher:
 54.72.220.34, 52.17.173.247, 52.208.190.137, 52.49.218.253 , 52.18.94.153, 54.194.195.183, 52.49.61.71
srv01.codefusion.technology
cf-revalidation-1750743123.eu-west-1.elb.amazonaws.com
srv02.codefusion.technology
srv03.codefusion.technology
support.codefusion.technology

Rebellion encrypted stuff


Similar adress is active in Strange Brigade from the same company
 nephelus.rebellion.net
nephelus.do.rebellion.net - 139.59.199.85
athena.rebellion.net/api - 46.101.64.59

Epic Games Spyware


And my favourite, Epic Games Spyware, Datarouter Telemetry, Websocket Traffic/Heartbeat phoning home every 30 seconds and forced Onlinemode tied to telemetry and Analytics. Same counts for as example for Satisfactory from another company.

Which is also nice to see, is the correlation ID
It's an worldwide unique tracking identifier

 api.epicgames.dev

https://api.epicgames.dev/sdk/v1/default?platformId=WIN
https://api.epicgames.dev/sdk/v1/product/949e8d3f1abe4e358fd608eb99d2abb9?platformId=WIN&deploymentId=68d2628827de4ad597c9a15c3a06ae29

https://api.epicgames.dev/auth/v1/oauth/token
https://api.epicgames.dev/auth/v1/turn/credentials?service=turn&username=
https://api.epicgames.dev/auth/v1/users
https://api.epicgames.dev/notifications/v1/68d2628827de4ad597c9a15c3a06ae29/connect
 POST /user/v3/product-users/search HTTP/1.1
Host: api.epicgames.dev
Content-Type: application/json
Accept: application/json
Authorization: Bearer xxxxx TOKEN here
X-Epic-Correlation-ID: EOS-Akbm8EpPAUaL5TsLA-5c7g-dXW4Kyq0FEaN8s3yHlJNEw-TU-12x7tYEWdMXTCbHpulA
User-Agent: EOS-SDK/1.8.0-14316386 (Windows/6.2.9200.1.256.64bit) ZA4/2021.02.15.1005644
X-EOS-Version: 1.8.0-14316386
Accept-Encoding: gzip, deflate
Content-Length: 55

{"productUserIds":["00023c8d7dab48a791e9eada3968be8e"]}

https://api.epicgames.dev/user/v3/product-users/search
{
"productUsers" : {
"00023c8d7dab48a791e9eada3968be8e" : {
"accounts" : [
{
"accountId" : "76561198113455411",
"displayName" : "ペンギン",
"identityProviderId" : "steam",
"lastLogin" : "2021-02-19T09:58:21Z"
}
]
}
}
}
{
"productUserIds" : [ "00023c8d7dab48a791e9eada3968be8e" ]
}

 POST /datarouter/api/v1/public/data/clients?AppID=949e8d3f1abe4e358fd608eb99d2abb9&AppVersion=1.8.0-14316386&AppEnvironment=dfd2530e80e4425d801913b0879be444&UploadType=eteventstream&SessionID=F2D4097343F5C67601FBE09D2CB76275 HTTP/1.1
Host: api.epicgames.dev
Content-Type: application/json
Accept: application/json
X-Epic-Correlation-ID: EOS-Akbm8EpPAUaL5TsLA-5c7g-dXW4Kyq0FEaN8s3yHlJNEw-MgOtm2teHk-Op1R56crRNQ
User-Agent: EOS-SDK/1.8.0-14316386 (Windows/6.2.9200.1.256.64bit) ZA4/2021.02.15.1005644
X-EOS-Version: 1.8.0-14316386
Authorization: F2D4097343F5C67601FBE09D2CB76275
Accept-Encoding: gzip, deflate
Content-Length: 104

{"Events":[{"EventName":"GameHeartbeat","platform":"Windows 8 6.2.9200.1.256.64bit","source":"client"}]}

https://api.epicgames.dev/telemetry/data/datarouter/api/v1/public/data?SessionID=%7BB6BA0F43-440E-A044-6B7A-DCB272078977%7D&AppID=EOSSDK.PhaseRelease.ReleaseBuild&AppVersion=1.8.0-14316386%20-%20%2B%2BEOSSDK%2BRelease-1.8-CL-14316386&UserID=&AppEnvironment=Production&UploadType=sdkevents

{
"Events" : [
{
"ApiName" : "EOS_P2P_ReceivePacket",
"ComponentName" : "P2PClient",
"DateOffset" : "+00:00:56.953",
"DeploymentId" : "68d2628827de4ad597c9a15c3a06ae29",
"DurationSeconds" : 60,00000000000000,
"EventName" : "UsageMetric",
"FailureCount" : 0,
"InvalidUsageCount" : 0,
"ProductId" : "949e8d3f1abe4e358fd608eb99d2abb9",
"ProductName" : "ZA4",
"ProductVersion" : "2021.02.15.1005644",
"SandboxId" : "dfd2530e80e4425d801913b0879be444",
"SuccessCount" : 7198,
"ThrottledCount" : 0,
"UserAgent" : "EOS-SDK/1.8.0-14316386 (Windows/6.2.9200.1.256.64bit) ZA4/2021.02.15.1005644"
}
]
}


https://api.epicgames.dev/datarouter/api/v1/public/data/clients?AppID=949e8d3f1abe4e358fd608eb99d2abb9&AppVersion=1.8.0-14316386&AppEnvironment=dfd2530e80e4425d801913b0879be444&UploadType=eteventstream&SessionID=C849F6174ECFCD88FCE1BDBB6C4F7C40

Websocket Heartbeat


Around evry 30 seconds a callback to Epic Games
 wss://api.epicgames.dev/notifications/v1/68d2628827de4ad597c9a15c3a06ae29/connect

Text Thu Feb 18 20:07:09 CET 2021 Thu Feb 18 20:07:09 CET 2021 CONNECTED
version:1.2-Epic
heart-beat:30000,30000
Text Thu Feb 18 20:07:10 CET 2021 Thu Feb 18 20:07:10 CET 2021 RECEIPT
receipt-id:sub-1
Text Thu Feb 18 20:07:39 CET 2021 Thu Feb 18 20:07:39 CET 2021
Text Thu Feb 18 20:08:09 CET 2021 Thu Feb 18 20:08:09 CET 2021
Text Thu Feb 18 20:08:39 CET 2021 Thu Feb 18 20:08:39 CET 2021
Text Thu Feb 18 20:09:10 CET 2021 Thu Feb 18 20:09:10 CET 2021
Text Thu Feb 18 20:09:40 CET 2021 Thu Feb 18 20:09:40 CET 2021
Text Thu Feb 18 20:10:40 CET 2021 Thu Feb 18 20:10:40 CET 2021

Conclusion


Disable or Block? Congratulations. You have a worthless product. Even the single player campaign won't work because in addition to Denuvo with forced activation, these services also have a counterproductive effect on the customer.

Again, Developers and Publisher like Rebellion from UK do not care about current laws, or even Customers. They honestly give a fuck on them/us. They even have the nerve to steal data and simply take it. No Opt-In/No Opt-Out. No additional option.

We as customers therefore pay twice (as always?). Not to talk about the ridiculous DLC policy for this product.

It's not the first product from Rebellion i tested. They're getting greedy and Rebellion should improve in this regard as soon as possible or they should pay us for every kilobyte which is send.

And i bet there will be few mini patches without real content soon, to refresh Denuvo Anti-Tamper.

<i>Edit 22.02.2021:</i> As predicted, not even a week later, the first "patch" an update has been installed.

Related data (prepared for hosts security) is already published under Zombie Army 4: Dead War

Thanks for reading and your interest in my work

Additional content


A summary can be read in a <a href="https://gameindustry.eu/firmenkatalog/rebellion-development-ltd/">Rebellion Development, Ltd. company overview</a> with few additional details about company behaviour and crosslinks.

  Rules for posting comments can be found in the F.A.Q.