False positive V16 Softphone Link marked as Malware by Defender

Evolute IT

3CX MVP
Gold Partner
Advanced Certified
Joined
Feb 6, 2018
Messages
11,199
Reaction score
7,010
Hi,

We had a user transfer their 3CX Welcome Email to us for some questions.

Email got caught in the O365 Defender quarantine. Links were scanned and the MSI file for v16 was marked as malware for some reason.

IMG_3993.jpeg
 
@ConceptsWeb thanks for reporting this. Are they using a custom welcome email template?
Because if this is SP8 option " Note: Find the old (legacy) Windows app here. " is not included in the welcome email.
Now, as a Tenant admin, you can check quarantined messages and release them here:
https://security.microsoft.com/quarantine
 
@ConceptsWeb thanks for reporting this. Are they using a custom welcome email template?
Because if this is SP8 option " Note: Find the old (legacy) Windows app here. " is not included in the welcome email.
Now, as a Tenant admin, you can check quarantined messages and release them here:
https://security.microsoft.com/quarantine
System is still on U7. But is using the default email template. Upgrade is planned for end of month.

Also, we know for the quarantine, that's where the screenshot comes from.
 
System is still on U7. But is using the default email template. Upgrade is planned for end of month.

Also, we know for the quarantine, that's where the screenshot comes from.
Then this makes sense for the link to exist since its SP7.
May you report this to MS as a false alert?
 
Then this makes sense for the link to exist since its SP7.
May you report this to MS as a false alert?
Already done. I'm just letting you know that the v16 Windows clientMSI is considered malware by Microsoft, which might cause other issues for other people.
 
I didn't see this thread when I posted my thread on the same subject, which has now been closed.

However I will add, to this thread, that the system is of the latest version and does NOT contain the malicious v16 link. It is however most likely just a hangover of this although the DNSBL issue still stands.
 
Thanks for the reply. You can go ahead and follow the instructions above in this case.
 
  • Like
Reactions: JamieR
I didn't see this thread when I posted my thread on the same subject, which has now been closed.

However I will add, to this thread, that the system is of the latest version and does NOT contain the malicious v16 link. It is however most likely just a hangover of this although the DNSBL issue still stands.
As a side note though we will look into this further and once we have any feedback we will provide it.

Also apologies regarding your original thread being locked, this was done by mistake and the thread has now been unlocked.