So, I decided to check out the D2: Resurrected multiplayer beta and after 2 minutes of playing my Sophos Antivirus closed the game.
"A Dynamic Shellcode exploit was prevented, the application Diablo2: Resurrected Multiplayer Beta was closed to prevent unwanted access to your system."
No idea what that even means, so I googled it:
Dynamic Shellcode Protection is designed to prevent active adversaries from achieving one of their most sought-after goals: using remote access agents to gain “hands on keyboard” privileges.
Suspicious behavior includes identifying processes that create a remote agent inside another process. This allows attackers to come in through one application and migrate to another application while maintaining a connection to their command-and-control systems. It also gives them the ability to hide their tracks and establish persistence on the device.
A false positive? Most probably! Diablo 2 is legitimate software, from a reputable company. I could tell Sophos to pass it.
On the other side, it's Activision-Blizzard. Fuck them, my trust level toward a company that shady and scummy is zero. I'm out.
Edit:
It is repeatable and happens when just standing around in town, without ever doing anything
AND
while just sitting at the character screen.