Updater 'Compromised'- Malwarebytes report
Had the following Malwarebytes 'RTP detection' event
-Log Details-
Protection Event Date: 24/03/2021
Protection Event Time: 10:46
Log File: 3786e8ba-8c8e-11eb-b180-30f9edd870a1.json
-Software Information-
Version: 4.3.0.98
Components Version: 1.0.1217
Update Package Version: 1.0.38623
Licence: Premium
-System Information-
OS: Windows 10 (Build 19041.867)
CPU: x64
File System: NTFS
User: System
-Blocked Website Details-
Malicious Website: 1
, C:\Program Files (x86)\Acronis\Agent\bin\updater.exe, Blocked, -1, -1, 0.0.0, ,
-Website Data-
Category: Compromised
Domain:
IP Address: 91.241.19.60
Port: 6888
Type: Inbound
File: C:\Program Files (x86)\Acronis\Agent\bin\updater.exe
Reported to Acronis with zero response - thoughts anyone?


- Accedi per poter commentare

Sorry Steve probably being thick, but repair install of Acronis or Windows? Malwarebytes report did say that website had been blocked so no need for further action, and neither Malwarebytes nor Bitdefender has flagged up any issues since.
- Accedi per poter commentare

C:\Program Files (x86)\Acronis\Agent\bin\updater.exe referenced in the report is ATI so any repair would be of Acronis, not Windows.
- Accedi per poter commentare

Thanks will do.
- Accedi per poter commentare

The repair install went through without incident, no error reports.
- Accedi per poter commentare

I'm getting these from Malwareytes too. Different IP addresses trying port 6888 to get to Acronis Updater. Seems they are trying to exploit the updater. Maybe there is a flaw in it??
IP addresses blocked: 185.81.68.253; 176.111.174.89; 94.102.61.39; 178.162.199.161; 94.102.61.39
These are all listed and malicious addresses on various sites.
Does Acronis updater have an exploitable flaw??
- Accedi per poter commentare

Mark Evans wrote:I'm getting these from Malwareytes too. Different IP addresses trying port 6888 to get to Acronis Updater. Seems they are trying to exploit the updater. Maybe there is a flaw in it??
IP addresses blocked: 185.81.68.253; 176.111.174.89; 94.102.61.39; 178.162.199.161; 94.102.61.39
These are all listed and malicious addresses on various sites.
Does Acronis updater have an exploitable flaw??
Hello Mark!
Please refer to this thread where the topic in on discussion: https://forum.acronis.com/forum/acronis-cyber-protect-home-office-forum…
At the moment we are waiting news from the team.
As soon as I have them I will update the thread.
Thanks.
- Accedi per poter commentare

Jose, the initial report of this problem was over two years ago so a response from Acronis is long overdue!
- Accedi per poter commentare

DrMopp wrote:Jose, the initial report of this problem was over two years ago so a response from Acronis is long overdue!
Hello!
I have requested more details to the team.
As soon as I have them I will update the threads.
Thanks in advance!
- Accedi per poter commentare