Updater 'Compromised'- Malwarebytes report
Had the following Malwarebytes 'RTP detection' event
-Log Details-
Protection Event Date: 24/03/2021
Protection Event Time: 10:46
Log File: 3786e8ba-8c8e-11eb-b180-30f9edd870a1.json
-Software Information-
Version: 4.3.0.98
Components Version: 1.0.1217
Update Package Version: 1.0.38623
Licence: Premium
-System Information-
OS: Windows 10 (Build 19041.867)
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, C:\Program Files (x86)\Acronis\Agent\bin\updater.exe, Blocked, -1, -1, 0.0.0, ,
-Website Data-
Category: Compromised
Domain:
IP Address: 91.241.19.60
Port: 6888
Type: Inbound
File: C:\Program Files (x86)\Acronis\Agent\bin\updater.exe
Reported to Acronis with zero response - thoughts anyone?


- Log in to post comments

Sorry Steve probably being thick, but repair install of Acronis or Windows? Malwarebytes report did say that website had been blocked so no need for further action, and neither Malwarebytes nor Bitdefender has flagged up any issues since.
- Log in to post comments

C:\Program Files (x86)\Acronis\Agent\bin\updater.exe referenced in the report is ATI so any repair would be of Acronis, not Windows.
- Log in to post comments

Thanks will do.
- Log in to post comments

The repair install went through without incident, no error reports.
- Log in to post comments

I'm getting these from Malwareytes too. Different IP addresses trying port 6888 to get to Acronis Updater. Seems they are trying to exploit the updater. Maybe there is a flaw in it??
IP addresses blocked: 185.81.68.253; 176.111.174.89; 94.102.61.39; 178.162.199.161; 94.102.61.39
These are all listed and malicious addresses on various sites.
Does Acronis updater have an exploitable flaw??
- Log in to post comments

Mark Evans wrote:I'm getting these from Malwareytes too. Different IP addresses trying port 6888 to get to Acronis Updater. Seems they are trying to exploit the updater. Maybe there is a flaw in it??
IP addresses blocked: 185.81.68.253; 176.111.174.89; 94.102.61.39; 178.162.199.161; 94.102.61.39
These are all listed and malicious addresses on various sites.
Does Acronis updater have an exploitable flaw??
Hello Mark!
Please refer to this thread where the topic in on discussion: https://forum.acronis.com/forum/acronis-cyber-protect-home-office-forum…
At the moment we are waiting news from the team.
As soon as I have them I will update the thread.
Thanks.
- Log in to post comments

Jose, the initial report of this problem was over two years ago so a response from Acronis is long overdue!
- Log in to post comments

DrMopp wrote:Jose, the initial report of this problem was over two years ago so a response from Acronis is long overdue!
Hello!
I have requested more details to the team.
As soon as I have them I will update the threads.
Thanks in advance!
- Log in to post comments