Updater 'Compromised'- Malwarebytes report
Had the following Malwarebytes 'RTP detection' event
-Log Details-
Protection Event Date: 24/03/2021
Protection Event Time: 10:46
Log File: 3786e8ba-8c8e-11eb-b180-30f9edd870a1.json
-Software Information-
Version: 4.3.0.98
Components Version: 1.0.1217
Update Package Version: 1.0.38623
Licence: Premium
-System Information-
OS: Windows 10 (Build 19041.867)
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, C:\Program Files (x86)\Acronis\Agent\bin\updater.exe, Blocked, -1, -1, 0.0.0, ,
-Website Data-
Category: Compromised
Domain:
IP Address: 91.241.19.60
Port: 6888
Type: Inbound
File: C:\Program Files (x86)\Acronis\Agent\bin\updater.exe
Reported to Acronis with zero response - thoughts anyone?


- Anmelden, um Kommentare verfassen zu können

Sorry Steve probably being thick, but repair install of Acronis or Windows? Malwarebytes report did say that website had been blocked so no need for further action, and neither Malwarebytes nor Bitdefender has flagged up any issues since.
- Anmelden, um Kommentare verfassen zu können

C:\Program Files (x86)\Acronis\Agent\bin\updater.exe referenced in the report is ATI so any repair would be of Acronis, not Windows.
- Anmelden, um Kommentare verfassen zu können

Thanks will do.
- Anmelden, um Kommentare verfassen zu können

The repair install went through without incident, no error reports.
- Anmelden, um Kommentare verfassen zu können

I'm getting these from Malwareytes too. Different IP addresses trying port 6888 to get to Acronis Updater. Seems they are trying to exploit the updater. Maybe there is a flaw in it??
IP addresses blocked: 185.81.68.253; 176.111.174.89; 94.102.61.39; 178.162.199.161; 94.102.61.39
These are all listed and malicious addresses on various sites.
Does Acronis updater have an exploitable flaw??
- Anmelden, um Kommentare verfassen zu können

Mark Evans wrote:I'm getting these from Malwareytes too. Different IP addresses trying port 6888 to get to Acronis Updater. Seems they are trying to exploit the updater. Maybe there is a flaw in it??
IP addresses blocked: 185.81.68.253; 176.111.174.89; 94.102.61.39; 178.162.199.161; 94.102.61.39
These are all listed and malicious addresses on various sites.
Does Acronis updater have an exploitable flaw??
Hello Mark!
Please refer to this thread where the topic in on discussion: https://forum.acronis.com/forum/acronis-cyber-protect-home-office-forum…
At the moment we are waiting news from the team.
As soon as I have them I will update the thread.
Thanks.
- Anmelden, um Kommentare verfassen zu können

Jose, the initial report of this problem was over two years ago so a response from Acronis is long overdue!
- Anmelden, um Kommentare verfassen zu können

DrMopp wrote:Jose, the initial report of this problem was over two years ago so a response from Acronis is long overdue!
Hello!
I have requested more details to the team.
As soon as I have them I will update the threads.
Thanks in advance!
- Anmelden, um Kommentare verfassen zu können