False positive SentinelOne EDR alert on desktop app Version 18.12.425.0

BrendanPrice

Gold Partner
Basic Certified
Joined
Jan 31, 2022
Messages
8
Reaction score
1
Hello again - I'm hoping this is just a false positive but I'd really like someone to cast their eye over it and see if there is a problem.

https://www.virustotal.com/gui/file...3682cbceafc2d53529e089ba87aabc87fe7/detection

This is from the 3CX Desktop App Windows version 18.12.425.0 signed. As you can see EVERY AV engine considers it safe. However one YARA ruleset is triggering on "Matches rule INDICATOR_SUSPICIOUS_EXE_References_CryptoWallets by ditekSHen from ruleset indicator_suspicious at https://github.com/ditekshen/detection". I'm guessing there is just some line of code that is a false match, but I don't really know enough to find out one way or the other. Can someone double check for me please?
 
In this case, SentinelOne EDR. It flagged it as "suspicious" though and not actually malicious.
 
@BrendanPrice I will PM you to provide us with more details on this.
 
@BrendanPrice since I sent you a PM for the generated logs or a screenshot of the particular and you didn't get back to us,
we have reported this to Sentinel One to not lose time.
If you can provide more info on this, reply back on my private message, please.
 
OK I just worked out that if you go to the VirusTotal page you get an all clear:
https://www.virustotal.com/gui/file/eece002ac1ce6a1d6afd176be7d173682cbceafc2d53529e089ba87aabc87fe7

However if you go that page and you have signed in with a VirusTotal account (which is free) then you also get the "Crowdsourced YARA rules" section which is what I was looking at. It appears here:

n52JgSF.png
 
As we discussed at the PM and as you mentioned, this was marked on a user's PC by accident.
We are still waiting for confirmation from SentinelOne but checking on the Details on Virus Total, it shows that
there is no issue at all.
Thank you for reporting.


1684734649131.png
 
  • Like
Reactions: Charles_3CX
Thank you.
 
  • Like
Reactions: NikosT_3CX
We have sent the AV vendor a follow-up email and are awaiting their reply, as soon as an update is received we will also reply here, in this post, with their feedback.
 
  • Like
Reactions: BoyanS_3CX
@BrendanPrice we are still waiting for feedback from the vendor regarding this. When we ll get it, we ll let you know immidiately.
 
This case seems to be a false positive. We reported the incident to SentilOne within 1 hour of this post and a second time 10 hours later. No other cases were reported to 3CX in the past 24 hours.

If the issue reoccurs please contact us.