Skip to main content

Auto updater blocked by anti-virus software because the Acronis server source IP is "compromised"

Thread needs solution

I've been using Acornis True Image for a few years with no problems.

Yesterday I got an alert from Malwarebytes (a reputable antivirus software) saying that the Acronis updater was blocked due to the inbound connection source being "compromised".

This is the log from the antivirus software:

-Log Details-
Protection Event Date: 4/17/23
Protection Event Time: 10:39 PM
Log File: [redacted].json

-Software Information-
Version: 4.5.26.259
Components Version: 1.0.1976
Update Package Version: 1.0.68158
License: Premium

-System Information-
OS: Windows 10 (Build [redacted])
CPU: x64
File System: NTFS
User: System

-Blocked Website Details-
Malicious Website: 1
, C:\Program Files (x86)\Acronis\Agent\bin\updater.exe, Blocked, -1, -1, 0.0.0, ,

-Website Data-
Category: Compromised
Domain:
IP Address: 94.102.61.39
Port: 6888
Type: Inbound
File: C:\Program Files (x86)\Acronis\Agent\bin\updater.exe


(end)

 

And this is another 3rd party threat detection service that corroborates the "compromised" status of the IP Address that Acronis is using:

(this forum won't let me post hyperlinks so please interpret my workaround by replaced DOT COM with you know what)

abuseipdb[DOT COM]/check/94.102.61.39

 

0 Users found this helpful
frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 2
Comments: 1727

Hello!

I would suggest you to exclude the agent folders/executables in the A.Virus: https://kb.acronis.com/content/36429 .

Could you also tell me what Acronis product are you using because under your email we can't find any registered.

Thanks!

I would suggest you to exclude the agent folders/executables in the A.Virus: https://kb.acronis.com/content/36429 .

The antivirus isn't blocking Acronis from doing backups (backups are working fine), it's blocking the connection attempt from the server/IP address that the Acronis auto-updater is attempting to use.

Your advice is very dangerous as it would make my machine vulnerable to a server IP address that's been corroborated by multiple 3rd parties as compromised.

Here's another 3rd party corroborating that the Acronis server IP has been compromised:

virustotal[DOT COM]/gui/ip-address/94.102.61.39

Could you also tell me what Acronis product are you using

I'm using Acronis True Image for Western Digital.

Jose, re-running the Virus Total scan of 94.102.61.39 reports that 5 security vendors are flagging this address as being malicious which should be a concern to Acronis to address!

VirusTotal scan results link here.

I wonder if a part of the issue here are the results returned when doing a Who Is lookup for this IP address which shows as below:

Whois: Final results obtained from whois.ripe.net.
Results:
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '94.102.61.0 - 94.102.61.255'

% Abuse contact for '94.102.61.0 - 94.102.61.255' is 'request@aispera.com'

inetnum: 94.102.61.0 - 94.102.61.255
netname: AISPERA
descr: Criminal IP Collector AiSpera
remarks: +-----------------------------------------------
remarks: | Criminal IP collects port information for only security/research purposes.
remarks: | It only reads the response data from basic port requests,
remarks: | and never utilizes vulnerability scanning or other exploit scripts.
remarks: |
remarks: | Our internet-wide, non-intrusive port scanning does not target specific IP addresses.
remarks: | It differs from malicious acts such as DDoS attacks
remarks: | in that it simply surveys by knocking on the door(port).
remarks: | We will permanently whitelist your IP address upon request.
remarks: | For any inquiries, please contact request@aispera.com
remarks: +-----------------------------------------------
country: NL
geoloc: 52.370216 4.895168
org: ORG-AS965-RIPE
admin-c: CI1923-RIPE
tech-c: CI1923-RIPE
status: ASSIGNED PA
mnt-by: IPV
mnt-lower: IPV
mnt-routes: IPV
created: 2019-02-04T13:27:35Z
last-modified: 2022-03-21T16:30:08Z
source: RIPE

organisation: ORG-AS965-RIPE
org-name: AI Spera
org-type: OTHER
address: 7 Yeonmujang 5(o)ga-gil, Seongsu 2(i)-ga 3(sam)-dong, Seongdong-gu
address: Seoul, South Korea
abuse-c: CI1923-RIPE
mnt-ref: IPV
mnt-by: IPV
mnt-by: IPV
created: 2022-03-21T16:25:27Z
last-modified: 2022-03-21T16:25:27Z
source: RIPE # Filtered

role: Criminal IP
address: 7 Yeonmujang 5(o)ga-gil, Seongsu 2(i)-ga 3(sam)-dong, Seongdong-gu
address: Seoul, South Korea
abuse-mailbox: request@aispera.com
nic-hdl: CI1923-RIPE
mnt-by: IPV
created: 2022-03-21T16:22:01Z
last-modified: 2022-03-21T16:25:19Z
source: RIPE # Filtered

% Information related to '94.102.61.0/24AS202425'

route: 94.102.61.0/24
origin: AS202425
remarks: +-----------------------------------------------
remarks: | Criminal IP collects port information for only security/research purposes.
remarks: | It only reads the response data from basic port requests,
remarks: | and never utilizes vulnerability scanning or other exploit scripts.
remarks: |
remarks: | Our internet-wide, non-intrusive port scanning does not target specific IP addresses.
remarks: | It differs from malicious acts such as DDoS attacks
remarks: | in that it simply surveys by knocking on the door(port).
remarks: | We will permanently whitelist your IP address upon request.
remarks: | For any inquiries, please contact request@aispera.com
remarks: +-----------------------------------------------
mnt-by: IPV
created: 2019-02-08T16:10:59Z
last-modified: 2022-03-21T16:30:39Z
source: RIPE

Perhaps a further question that Acronis should answer is why is the updater tool for Cyber Protect contacting a port scanning service and what ports are being scanned and why?

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 2
Comments: 1727

Hello everybody!

I reported this behavior to the team. As soon as I have the answers I will let you know.

Cheers!

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 2
Comments: 1727

Private User wrote:

What' the update on this? It's been weeks

Hello!

So far the team didn't provided any updates.

I will request them again and check if there are any news.

Thanks in advance! 

Having the same issue (blocked by antivirus) and (only) having standard W11 antivirus enabled.

Taking backups is not a problem.

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Posts: 2
Comments: 1727

Peter Bossier wrote:

Having the same issue (blocked by antivirus) and (only) having standard W11 antivirus enabled.

Taking backups is not a problem.

Hello!

This topic refers to the program Malwarebytes not to Windows Defender. This is not related.

Please check this KB: https://kb.acronis.com/content/62144

If the issue persists after, I suggest raising a ticket at  https://kb.acronis.com/content/8153

Best regards.