ESET denies it was compromised as Israeli orgs targeted with 'ESET-branded' wipers

Discussion in 'other anti-malware software' started by ronjor, Oct 18, 2024 at 8:39 AM.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    170,840
    Location:
    Texas
    Connor Jones Fri 18 Oct 2024
     
  2. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,642
    Location:
    U.S.A.
    Last edited: Oct 18, 2024 at 10:23 AM
  3. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,555
    Interesting for sure. Wonder if we will get the full story at some point.
     
  4. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,374
    Location:
    Ontario, Canada
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,642
    Location:
    U.S.A.
  6. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,642
    Location:
    U.S.A.
    Further details here: https://www.bleepingcomputer.com/ne...breached-to-send-data-wipers-to-israeli-orgs/ .

    Of note;
    Bottom line - Eset corp. servers were not breached.
     
  7. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,897
    Location:
    Slovenia, EU
  8. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,642
    Location:
    U.S.A.
    Which link you referring to? The bleepingcomputer.com link?

    What is strange is if I try to access the malicious download site: https://backend.store.eset.co[.]il/pub/2eb524d79ce77d5857abe1fe4399a58d/ESETUnleashed_081024.zip, I get a Cloudflare blocked access alert. Problem is I am not using Cloudflare DNS or DoH servers. Alert must be originating from Eset Israeli eStore web site.
     
    Last edited: Oct 18, 2024 at 4:16 PM
  9. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,897
    Location:
    Slovenia, EU
    First upload was for bleepingcomputer link.
    Accessing this thread now triggered two uploads on my system, one for a link and another for whole thread page

    upload_2024-10-18_22-37-4.png

    upload_2024-10-18_22-37-33.png
     
  10. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,642
    Location:
    U.S.A.
    Strange. I am not receiving any Eset Virus Lab uploads on bleepingcomputer link or when reviewing web page details. I am using ESSP 17.2.8.
     
  11. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,897
    Location:
    Slovenia, EU
    I still get files uploaded each time I visit this thread or bleepingcomputer link. I use Eset Nod32 AV 17.2.8.

    This are my settings:

    upload_2024-10-19_9-33-17.png
     
  12. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,642
    Location:
    U.S.A.
    Note that your "Automatic submission of detected samples" is set to "Do not submit." As such, I would think there should be no submissions to Eset Virus Lab occurring. There might also be an issue with browser you are using causing this activity. I am using Firefox. I am also running Firefox in Eset Secure all browsers mode.

    -EDIT- What I did notice is when I access the bleepingcomputer.com article w/Secure all browsers disabled, I observe tsmxx.eset.com network activity. This usually occurs when Eset detects suspicious network activity with whatever detected being auto submitted to LiveGrid for analysis. Note that this is separate and different monitoring activity than submissions to Eset Virus Lab.

    Also, did you disable NOD32 HTTPS scanning? That could be related to this Virus Lab submission issue.

    If this issue is not browser related, I would say that either there's an issue with your NOD32 installation or there's a bug in NOD32. For starters, you could reinstall NOD32 and see if this activity persists. If it does, post in the Eset forum about these Eset Virus Lab submissions.
     
    Last edited: Oct 19, 2024 at 10:58 AM
  13. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,897
    Location:
    Slovenia, EU
    I have only disabled option Submission of detected samples. I have left option Submission of suspicious samples enabled for some types of files. If I disable sending of those too, nothing is sent to ESET. Since they classify those files as suspicious that is IMO expected behaviour.
    Since I don't find this behaviour as "issue", I won't try to "fix" it. If ESET finds those files suspicious they can upload it to their servers if they want. They can also upload it as many times as they want :)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.