Threat alerts from SentinelOne for desktop update initiated from desktop client

Status
Not open for further replies.

Brendan D

Silver Partner
Advanced Certified
Joined
Mar 22, 2023
Messages
15
Reaction score
12
Is anyone else seeing this issue with other A/V vendors?

Post Exploitation
  • Penetration framework or shellcode was detected
Evasion
  • Indirect command was executed
  • Code injection to other process memory space during the target process' initialization
\Device\HarddiskVolume4\Users\**USERNAME**\AppData\Local\Programs\3CXDesktopApp\3CXDesktopApp.exe
SHA1 e272715737b51c01dc2bed0f0aee2bf6feef25f1

I'm also getting the same trigger when attempting to redownload the app from the web client ( 3CXDesktopApp-18.12.416.msi ).
 
Are you not worried that some damage could already have been done?
Yes, that's certainly a possibility
Crowdstrike first flagged it today. This thread opened a week ago from a flag from S1. S1 didn't provide this information per the posts in this thread.


Replies from 3CX indicating this is a false positive:
https://www.3cx.com/community/threa...tiated-from-desktop-client.119806/post-558534
https://www.3cx.com/community/threa...tiated-from-desktop-client.119806/post-558539
Multiple trusted security vendors are flagging this, I've seen SentinalOne, CrowdStrike and Todyl just this morning.

"Todyl is actively tracking a malicious actor campaign targeting users of the 3CX softphone telephony platform, currently attributed to the LABYRINTH CHOLLIMA group operating out of the Democratic People’s Republic of Korea"

A 3CX support rep doesn't have an insight into the development process of the 3CX desktop application. The installation application is correctly signed, yes this could be a false positive but it may also be a compromised developer account too. Until its understood and there's a official company response from 3CX we'll be reverting our clients to the web app.
 
That is incorrect. 3cx has NOT indicated it is a false positive.
How do you read either of the 2 linked posts and not see 3CX indicating its a AV problem? They say to contact the AV vendor because
there's hundreds if not thousands of AV solutions out there and we can't always reach out to them whenever an event occurs. We use the Electron framework for our app, perhaps they are blocking some if its functionality?
That doesn't say "we think it's a false positive" to you?

Multiple trusted security vendors are flagging this, I've seen SentinalOne, CrowdStrike and Todyl just this morning.

"Todyl is actively tracking a malicious actor campaign targeting users of the 3CX softphone telephony platform, currently attributed to the LABYRINTH CHOLLIMA group operating out of the Democratic People’s Republic of Korea"

A 3CX support rep doesn't have an insight into the development process of the 3CX desktop application. The installation application is correctly signed, yes this could be a false positive but it may also be a compromised developer account too. Until its understood and there's a official company response from 3CX we'll be reverting our clients to the web app.
Obviously there's a problem here, no one is arguing that. But my post you quoted was replying to someone else who "blamed" everyone who initially whitelisted it after hearing from 3CX that they think it's a false flag for not investigating it themselves further. All I said was "I understand why they whitelisted it".
 
Hi skuers,

While that would sound ideal, there's hundreds if not thousands of AV solutions out there and we can't always reach out to them whenever an event occurs. We use the Electron framework for our app, perhaps they are blocking some if its functionality?

As you probably understand, we have no control over their software and the decisions it makes so it's not exactly our place to comment on it. I think in this case at least, it makes more sense if the SentinelOne customers contact their security software provider and see why this happens. Feel free to post your findings here if you get a reply.
Sure, but you can reach out to the major ones, especially when it suddenly decides your program is acting like malware.
 
@SweetAction

You can't be serious? You are putting words in their mouth. The single 3cx rep that has replied on this thread hasn't said one way or another what they think is going on. All they are saying is they don't know what the AV companies are saying and doing but if your AV company says there is an issue reach out to them. This situation is likely above their pay grade to begin with. I don't know how you read anything they said and draw the conclusion that 3cx is saying it is a false positive.
 
We need an official statement from 3CX - are we having a false positive ? it seems not !

Please google : 3cx falcon reddit
 
@SweetAction

You can't be serious? You are putting words in their mouth. The single 3cx rep that has replied on this thread hasn't said one way or another what they think is going on. All they are saying is they don't know what the AV companies are saying and doing but if your AV company says there is an issue reach out to them. This situation is likely above their pay grade to begin with. I don't know how you read anything they said and draw the conclusion that 3cx is saying it is a false positive.
We just have to disagree here. The way I read John's posts and the way you do clearly are different.
 
Just want to add that our crowdstrike was blowing up with one system having the "Triggering Indicator" being a DNS request of "azureonlinestorage.com". This domain seems to not be associated with Microsoft as far as we can tell and seems very suspicious.
The nameserver is from "thcservers.com" which is a web hosting provider.
The detection mentions:
NOTE: Highly suspicious domain, likely actor controlled.
This has been raised for immediate action and should be investigated urgently.
From what we can see, the detections seem to be after an update from UPDATE.EXE --> "3CXDESKTOPAPP.EXE
 
Likewise, in light of this new information we have raised a P1 ticket with SentinelOne and will post feedback.
Use the Webclient until further notice to continue operation.
 
Just to chime in here that I am in the "the 3CX response to this has been bad" camp.
 
Also chiming in to say 3CX's response has been unacceptable to this. We need an official update and statement from them now.
 
If we are already on 18 Update 7 Build 312, can we let S1 quarantine and leave it alone until we get an answer from 3CX or S1?
 
Why is there no response from 3CX yet? This is insane!

Maybe they were in on it?
 
We are proactivly uninstalling 3CX Desktop across our locations right now while waiting for an update from 3CX. The lack of communication right now is incredibly dissapointing.
 
  • Like
Reactions: EBrooke
It is normal that if they activated their incident management program, communications with interested parties is limited to authorized people. If they are in an investigation process, the communications will be carried out on a scheduled basis and through authorized channels and persons.

I understand that due to media pressure they should make an official statement in the next few hours.
 
  • Like
Reactions: EBrooke
[...]

Maybe they were in on it?
This is far from a reasonable accusation and less than helpful.

It is normal that if they activated their incident management program, communications with interested parties is limited to authorized people. If they are in an investigation process, the communications will be carried out on a scheduled basis and through authorized channels and persons.

I understand that due to media pressure they should make an official statement in the next few hours.
I absolutely agree that 3CX PR should not be spewing forth information right now, but complete radio silence on the matter is a misstep given how many people are frantically investigating their environments for signs of compromise right now.
 
  • Like
Reactions: EBrooke
"A 3CX spokesperson didn't reply to a request for comment when BleepingComputer reached out earlier today."

We need more information from 3CX.
 
  • Like
Reactions: EBrooke
SentinelOne has replied to our Support Ticket. See Information below for others to read.

SentinelOne observed malicious activity originating from a known-good application (3CX Desktop App). Further, we’ve identified the usage of this application in your environment. SentinelOne has already globally blocklisted known-malicious files, and the Windows agent natively detects this behavior. To provide further protection in the event of additional indicators of compromise (IoC) identification, we recommend the following:

  • Remove any suppressions and exclusions relating to 3CX
  • Conduct threat hunting on known malicious hashes
    • bfecb8ce89a312d2ef4afc64a63847ae11c6f69e - Installer
    • 3b88cda62cdd918b62ef5aa8c5a73a46f176d18b - First stage DLL
    • cad1120d91b812acafef7175f949dd1b09c6c21a - Second stage DLL
  • Work with 3CX to obtain the latest, patched version

The SentinelOne Windows agent will natively detect this malicious behavior on supported versions. You can find additional information in our post here.

https://www.sentinelone.com/blog/sm...3cx-software-in-software-supply-chain-attack/
 
Status
Not open for further replies.

Forum statistics

Threads
111,999
Messages
590,216
Members
164,937
Latest member
RevHealth