Threat alerts from SentinelOne for desktop update initiated from desktop client

Status
Not open for further replies.

Brendan D

Silver Partner
Advanced Certified
Joined
Mar 22, 2023
Messages
15
Reaction score
12
Is anyone else seeing this issue with other A/V vendors?

Post Exploitation
  • Penetration framework or shellcode was detected
Evasion
  • Indirect command was executed
  • Code injection to other process memory space during the target process' initialization
\Device\HarddiskVolume4\Users\**USERNAME**\AppData\Local\Programs\3CXDesktopApp\3CXDesktopApp.exe
SHA1 e272715737b51c01dc2bed0f0aee2bf6feef25f1

I'm also getting the same trigger when attempting to redownload the app from the web client ( 3CXDesktopApp-18.12.416.msi ).
 
Hi skuers,

While that would sound ideal, there's hundreds if not thousands of AV solutions out there and we can't always reach out to them whenever an event occurs. We use the Electron framework for our app, perhaps they are blocking some if its functionality?

As you probably understand, we have no control over their software and the decisions it makes so it's not exactly our place to comment on it. I think in this case at least, it makes more sense if the SentinelOne customers contact their security software provider and see why this happens. Feel free to post your findings here if you get a reply.
Hi John
The problem I have with that answer is we the consumer get stuck in the middle because the AV Provider will also turn around to us and say "the software provider is building it wrong and its unsafe", create an exception, "trust" its safe and depending how its done create a security hole in the environment. I would ask for a middle ground where in this case SentinelOne are using a global database in MITRE so detailed information can be provided to the software developers and in turn the vulnerabilities can be reviewed, patched and deployed to the consumer. When we do create our support ticket with SentinelOne support what contact information can we give from 3CX end to facilitate the communication between the two development teams? Do you need more information from SentinelOne than just the MITRE Attack Database?
 
Hi skuers,

While that would sound ideal, there's hundreds if not thousands of AV solutions out there and we can't always reach out to them whenever an event occurs. We use the Electron framework for our app, perhaps they are blocking some if its functionality?

As you probably understand, we have no control over their software and the decisions it makes so it's not exactly our place to comment on it. I think in this case at least, it makes more sense if the SentinelOne customers contact their security software provider and see why this happens. Feel free to post your findings here if you get a reply.

It is important for 3CX to proactively investigate any potential security concerns raised by customers. It is absolutely possible that 3CX have introduced a vulnerability through this software update, and following a Zero Trust approach, it is best to assume a breach may have occurred until proven otherwise.

3CX should take responsibility for investigating any potential security incidents and not pass the responsibility onto their clients. In this case, it would be unwise to assume that the issue is a false detection without thoroughly investigating the situation.
 
We are experiencing the same issue with the Cortex XDR agent blocking 3CXDesktopApp.exe for 3CX 18.0 (Build 312)

We have opened a support case with Paloaltonetworks for further investigation.
 
  • Like
Reactions: wits2020
  • Like
Reactions: Evolute IT
Per Virustotal, nothing detects this as malware: https://www.virustotal.com/gui/file/5d99efa36f34aa6b43cd81e77544961c5c8d692c96059fef92c2df2624550734

That was last scanned 20 minutes before my post

This include S1 ML
View attachment 34847
So it's strange and I suspect the issue isn't the app itself but instead how the app updates itself or something similar.
The Static Detection Engine was not what flagged the threat. The Dynamic Behavioral AI engine was responsible, a writeup from SentinelOne's documentation below.

A Behavioral AI engine that uses machine learning techniques to detect process chains associated with malicious activities. This engine detects malicious activities in real-time, when processes execute.
 
We are also today receive the same detection using ESET. It appears only to one user several times and report back that he needs to restart the PC several times. Atm, we are following the issue.
Checking the hash through virus total no results come back.

Please see bellow

Hash
14075C5C8C373BE373E51DBEA7F6E5CD8087AB0A

Name: Win64/Agent.CFM
Detection Type: Trojan
Object type: File
Uniform Resource Identifier (URI): 3CXDesktopApp.exe(7192)

Detection Flags
Variant

Scan
Scanner
Advanced memory scanner
Detection engine version
26981 (20230329)
Current engine version
26981 (20230329)
 
  • Like
Reactions: wits2020
Also posting here so I can see updates. We are also seeing S1 flag and mitigate the client.
 
I am here for this also - Mine was detected by Crowdstrike and I have created a detailed post. We need some clear and concise answers please!
 
  • Like
Reactions: MH_INDUS
From the post-"This is a dynamic situation and updates will be provided here as they become available. CrowdStrike's Intelligence Team is in contact with 3CX. There is suspected nation-state involvement by the threat actor LABYRINTH CHOLLIMA."

 
I hope all the members in this thread who have whitelisted/excluded the app from their AV are aware that they have something serious to deal with - like NOW!
 
  • Like
Reactions: mferraby and crboyd
Seriously. Your EDR tells you that your phone client is behaving like a C2 talking to North Korea, and your response is to put it in the whitelist? Wow...
I hope all the members in this thread who have whitelisted/excluded the app from their AV are aware that they have something serious to deal with - like NOW!
 
Seriously. Your EDR tells you that your phone client is behaving like a C2 talking to North Korea, and your response is to put it in the whitelist? Wow...
(Some of this was actioned by MSP's on behalf of their customers - I can see a brown coloured storm approaching and I honestly feel for everyone involved)
 
Seriously. Your EDR tells you that your phone client is behaving like a C2 talking to North Korea, and your response is to put it in the whitelist? Wow...
I personally am not affected here, but to be fair to those that are, the executable is signed by the trusted vendor and the vendor has stated multiple times that you should bring it up with the AV vendor (indicating they believe it to be a false positive).

What does IT do when a business app is being flagged by AV and all indications are that it's a false positive?
 
I personally am not affected here, but to be fair to those that are, the executable is signed by the trusted vendor and the vendor has stated multiple times that you should bring it up with the AV vendor (indicating they believe it to be a false positive).

What does IT do when a business app is being flagged by AV and all indications are that it's a false positive?
I think it deserves to be investigated till there's no other option but decide it's false, I was instantly suspicious and did my research on the domain the device was trying to reach, it's suspicious at best.

1680114544043.png
 
  • Like
Reactions: mferraby
I personally am not affected here, but to be fair to those that are, the executable is signed by the trusted vendor and the vendor has stated multiple times that you should bring it up with the AV vendor (indicating they believe it to be a false positive).

What does IT do when a business app is being flagged by AV and all indications are that it's a false positive?
With multiple vendor flagging the desktop application and it being seen to connect to known suspicious command and control domains, I'd suggest further investigation is needed and certainly a response from 3CX before assuming a false positive. I'd originally whitelist this is our systems, these have been removed and the desktop app removed from all devices until we hear otherwise.
 
  • Like
Reactions: mferraby
With multiple vendor flagging the desktop application and it being seen to connect to known suspicious command and control domains, I'd suggest further investigation is needed and certainly a response from 3CX before assuming a false positive. I'd originally whitelist this is our systems, these have been removed and the desktop app removed from all devices until we hear otherwise.
Are you not worried that some damage could already have been done?
 
I think it deserves to be investigated till there's no other option but decide it's false, I was instantly suspicious and did my research on the domain the device was trying to reach, it's suspicious at best.

View attachment 34879
Crowdstrike first flagged it today. This thread opened a week ago from a flag from S1. S1 didn't provide this information per the posts in this thread.

With multiple vendor flagging the desktop application and it being seen to connect to known suspicious command and control domains, I'd suggest further investigation is needed and certainly a response from 3CX before assuming a false positive.
Replies from 3CX indicating this is a false positive:
https://www.3cx.com/community/threa...tiated-from-desktop-client.119806/post-558534
https://www.3cx.com/community/threa...tiated-from-desktop-client.119806/post-558539
 
Hello,

This is a fresh install of the application into a new windows laptop with SentinelOne install.
See attachment.
 

Attachments

  • Screenshot 2023-03-29 145634.png
    Screenshot 2023-03-29 145634.png
    53.7 KB · Views: 162
Status
Not open for further replies.