All Apps and Add-ons

Alert Manager Enterprise - Malware Detection vsw.exe

daniel333
Builder

All, 

Our SentinelOne EDR started detecting Alert Manager Enterprise's vsw.exe as Malware https://www.virustotal.com/gui/file/1cb09276e415c198137a87ba17fd05d0425d0c6f1f8c5afef81bac4fede84f6a....

Anyone else run into this before I start digging into this? Is there a proper course of action Splunkbase would like if this ends up being positive? 

thanks

-Daniel

Labels (1)

mborner
Explorer

The binary is used for verifying the signature of the license key. We have already contacted all vendors listed on VirusTotal. Only the Windows version is affected.

If you do not utilize Windows, you can safely remove the binary. Furthermore, if you are a customer of SentinelOne or another vendor, kindly contact them to flag the binary as safe.

0 Karma

Austinkline
Engager

We're also seeing similar results in our Organization. Got flagged for the same binary yesterday. No mention of the binaries or their usage in the AME documentation, but it is used for license validation in the product. You can see the python script here where they are referenced and license validation occurs. 

alert_manager_enterprise\lib\ame\utilities\LicenseValidatorUtility.py

I'm not entirely sure where else the binaries are being referenced at this time but without access to the source code of the binaries (vsl & vsw) we are choosing to take it on face value that they are potentially malicious and acting accordingly. I uploaded vsl to VirusTotal as well but it appears to be coming back clean, for now. 

We are working to determine if we want to remove only vsw.exe from our app deployment or remove the app entirely.  I have reached out to the developers via the contact information on their website and will report back what they have to say about it.

This is disheartening because I'm a long time fan of the Alert Manager, and now Alert Manger Enterprise application. I'll continue to monitor this thread for suggested recommendations as the situation evolves. 

 

Tags (3)
0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...
OSZAR »