New Desktop App Build Number 18.12.425 Released

Just this message to let you know that SentinelOne has started flagging the 18.12.425 msi installer as malicious (again).

The application itself, once installed, seems to keep working and does not get flagged even after a restart.
Hi @Kenneth Geets,

We will look into this and provide you with an update as soon as we have something.

Thanks
 
Hi again,

I just want to provide a quick update that we have reached out to SentinelOne about this earlier today and waiting for a response.
 
Hi again,

I just want to provide a quick update that we have reached out to SentinelOne about this earlier today and waiting for a response.
Hi,

Do you have an update from SentinelOne ?

Regards
 
Hi @lafralle1 ,

We are in contact with them however there isn't any update at the moment. It may take some time as it is not just a simple email exchange.

We need to provide information, they need to check, there's also timezone difference etc.

Thanks for your understanding.
 
Hi all,

We received a confirmation from SentinelOne team that it is a false positive alert.

Thanks for your patience.
 
Hi all,

We received a confirmation from SentinelOne team that it is a false positive alert.

Thanks for your patience.
I saw quite a few concerning things in the SentinelOne report. Can you give more information on how it was a false positive? My team just stopped a rollout of 3CX Desktop app for our customers because of this.
 
I saw quite a few concerning things in the SentinelOne report. Can you give more information on how it was a false positive? My team just stopped a rollout of 3CX Desktop app for our customers because of this.
Hi,

Based on the information provided by the SentinelOne team after carefully analyzing the latest version (18.12.425), they concluded that the false positive alert is related to upgrade/overwrite behaviors on previously infected systems and that the package is clean.

I would suggest reaching out to SentinelOne’s support for specific technical details regarding the alert’s report if you need any clarification.

I hope this helps.
 
Good day,

Can securely download and use the Desktop App again?

Best regards
 
Good day,

Can securely download and use the Desktop App again?

Best regards
Yes. Make sure your 3CX installation is updated to latest version including all update files.
 
I have some questions, we are still on V18 Update 5. If we were to upgrade to Update 7 Final Build 18.0.7.312 (March 2023), Would our currently installed desktop apps automatically update to Desktop App Version 18.12.425? Also, after updating, if users went to download the Desktop App via the web app after they login, would they get the 18.12.425 version of the Desktop app?
 
I have some questions, we are still on V18 Update 5. If we were to upgrade to Update 7 Final Build 18.0.7.312 (March 2023), Would our currently installed desktop apps automatically update to Desktop App Version 18.12.425? Also, after updating, if users went to download the Desktop App via the web app after they login, would they get the 18.12.425 version of the Desktop app?
Yes and yes, provided you install all (stable) updates on the PBX (You have to go to the downloads section sometimes and click update on the app, although 99% of the time it does it automatically)
 
Hi there, I cannot install the client on MacOS Ventula 13.3.1 this sounds like a very bad joke, please fix it as you might lose big clients... thanks
Hi,

Can you please remove the app (if it was already on the machine) and reinstall it from scratch?

Apple had flagged the .425 app as bad, but then later reverted - leaving the currently installed app unusable.

Therefore the app will not run until it is removed and reinstalled, after which it should run fine.

Can you let us know if this helps, and if not tell us exactly at which point the installation fails?

We checked our end and the app runs fine 13.3.1 intel and M architecture machines.
 
Greetings,

We are currently in the final implementation phase of 3CX for our company and have run into a snag.

Crowdstrike is alerting on the Mac version of the Desktop app (18.12.425). Has anybody else seen this? We have installed it on 2 different machines and are receiving the same detection on both.

Crowdstrike Alert
Trigger Name: New detection
Indicators of Attack: This file meets the File Attribute ML algorithm's high-confidence threshold for malware.
Actions Taken: Prevention/Quarantine, process was blocked from execution and quarantine was attempted

Alert Details
Status: New
Severity: High
Local IP Address: (redacted)
Domain:
Username: (redacted)
Command Line: /Applications/3CX Desktop App.app/Contents/MacOS/3CX Desktop App
File Path: /Applications/3CX Desktop App.app/Contents/MacOS/3CX Desktop App

Crowdstrike Alert
Trigger Name: New detection
Indicators of Attack: This process wrote a suspicious file to disk. That associated file meets the ML algorithm's high-confidence malware detection threshold. Review the associated file.
Actions Taken: Endpoint detection, standard detection

Alert Details
Status: New
Severity: Low
Local IP Address: (redacted)
Domain:
Username: root
Command Line: /System/Library/PrivateFrameworks/DesktopServicesPriv.framework/Resources/DesktopServicesHelper
File Path: /System/Library/PrivateFrameworks/DesktopServicesPriv.framework/Versions/A/Resources/DesktopServicesHelper
Parent Process:

These alerts are affecting our rollout of 3CX, any information would be appreciated.

Thanks.
 
Hello dsapp,
I'll PM you to gather more info on this, we haven't seen this anywhere else.
 
Hi there. Engineer from CrowdStrike, here. To be clear: Falcon is not flagging the 3CX binary, I know everyone is a little twitchy, it is flagging whatever DesktopServicesHelper is writing to disk. If you read the alert:

This process wrote a suspicious file to disk. That associated file meets the ML algorithm's high-confidence malware detection threshold. Review the associated file.

I do not know a ton about the complete workings of 3CX, however, assumption is DesktopServicesHelper is a worker process that can write files to disk as required. It is whatever DesktopServicesHelper is writing that is triggering the alerts.

Recommendation would be to examine the files being written to disk by DesktopServicesHelper and ensure they are expected.

UPDATE

@dsapp appears to have pasted two detections above. I'll go one at a time. First is this one:

Crowdstrike Alert
Trigger Name: New detection
Indicators of Attack: This file meets the File Attribute ML algorithm's high-confidence threshold for malware.
Actions Taken: Prevention/Quarantine, process was blocked from execution and quarantine was attempted

Alert Details
Status: New
Severity: High
Local IP Address: (redacted)
Domain:
Username: (redacted)
Command Line: /Applications/3CX Desktop App.app/Contents/MacOS/3CX Desktop App
File Path: /Applications/3CX Desktop App.app/Contents/MacOS/3CX Desktop App

This appears to be a false positive and we've rectified it on our side. The ML model was getting overly aggressive with the 3CX binary as the previous, weaponized binary was trained upon. This has been fixed and we apologize for any heartburn, here.

Second is this:

Crowdstrike Alert
Trigger Name: New detection
Indicators of Attack: This process wrote a suspicious file to disk. That associated file meets the ML algorithm's high-confidence malware detection threshold. Review the associated file.
Actions Taken: Endpoint detection, standard detection

Alert Details
Status: New
Severity: Low
Local IP Address: (redacted)
Domain:
Username: root
Command Line: /System/Library/PrivateFrameworks/DesktopServicesPriv.framework/Resources/DesktopServicesHelper
File Path: /System/Library/PrivateFrameworks/DesktopServicesPriv.framework/Versions/A/Resources/DesktopServicesHelper
This is part of the macOS operating system and, from what I can tell, unrelated to 3CX in any way.

Code:
/System/Library/PrivateFrameworks/DesktopServicesPriv.framework/Versions/A/Resources/DesktopServicesHelper

The launching process in all cases is launchd. Falcon is flagging this binary when it is writing malicious files to disk. @dsapp I would pay attention to these alerts and ensure that you expect this behavior in your environment.

If there are any other questions please let me know.
 
Last edited:
It looks like also Microsoft Azure had removed any 3CX virtual apps and associations and all Microsoft Partners including me, were informed to start decommissioning any 3CX installations or try alternatives because they had blocked the 3CX or license activation links. I think 3CX is heading to a downfall. Time to look at Microsoft Teams Phone System.
Want to back this up with a source?

We're a high level MS partner (Solution Provider in multiple competencies, formerly the Gold Partner level) and heard nothing about this. Furthermore we haven't seen any app registrations or 365 configurations stop working.
 
Switched to VirtualPBX and works like a charm. Good luck 3cx... feel free to block and disable my account.
bravo-simon-cowell.gif
 

Forum statistics

Threads
111,994
Messages
590,183
Members
164,934
Latest member
bunthoeun.may