- Joined
- Jan 5, 2018
- Messages
- 5
- Reaction score
- 0
Hi,
We had a handful of MacOS Ventura new (over the last few months) installs that had the compromised version of 3CX installed. Even after removing the app and the Application Support 3CX directory, as soon as those machines are active on our network, the Router ATP reports having to block access the the list of known compromised address's reported from he 3CX app malware.
I appreciate those addresses are now disabled but I would like to put an end to this activity. My question is what other files could be causing it? Is it possible other settings on those machine are now altered and can they be fixed without complete reinstall?
As many of my previous 3CX installs were legacy ones, they were pre the malware version. These appear good, as is the latest version.
So far:
Thanks,
Robin
We had a handful of MacOS Ventura new (over the last few months) installs that had the compromised version of 3CX installed. Even after removing the app and the Application Support 3CX directory, as soon as those machines are active on our network, the Router ATP reports having to block access the the list of known compromised address's reported from he 3CX app malware.
I appreciate those addresses are now disabled but I would like to put an end to this activity. My question is what other files could be causing it? Is it possible other settings on those machine are now altered and can they be fixed without complete reinstall?
As many of my previous 3CX installs were legacy ones, they were pre the malware version. These appear good, as is the latest version.
So far:
- I am only still getting attempts to access the bad addresses from Mac’s that had the compromised installs. Not the PC’s
- Once the app and the directory ~/Library/Application Support/3CX Desktop App are deleted the attempts to access the bad sites are still present
- I think all will be Ventura (as they are the installs I did during the active compromise) so Apples latest protection is not stopping it
- Having, Bitdefender, SentinelOne or running MalwareBytes does not stop it on the machines
- Is it possible it is not a file now and some settings were changed on the machines it was on?
- Is it possible a different app has been hit with the same issue? So far I can only see X_Trader that had a similar issue but a hell of a coincidence this is only on machines that had the 3CX app on
Thanks,
Robin