Jump to content

Exploit reported but no item in exclude exploit list


Recommended Posts

Hi,

After installing LSI/Avago/Broadcom MegaRaid Storage Manager and running it  Malwarebytes  3.3 (3.3.1.2183) reports an exploit.

The MegaRaid is a java application and it connects to service running locally with the IP 192.168.232.1.

The explot it detected as "Java malicious inbound socket".

The exclution wizard doesn't show anything:

.5a14bf00033a1_exlusionwizard.thumb.PNG.f7e8e1a22218213525c87f4e90553093.PNG

 

I've tried to exclude the MegaRaid Softwares folder and executables (exclude1.png) and turned of two java exploit settings.

exclude1.thumb.PNG.01ee1e4ed09e37c6741f67ebe593cea0.PNGexclude2.PNG.3752bbdfdee6252144ac6042362ad764.PNG

 

But the MegaRaid software isn't able to locate the service.

megaraid.thumb.PNG.15a66b499eb7ad3fde19211a4f0c6282.PNG

 

Here is the logged explot:

Malwarebytes
www.malwarebytes.com

-Log Details-
Protection Event Date: 11/22/17
Protection Event Time: 12:28 AM
Log File: 9db03b3d-cf13-11e7-8b00-3085a9406ff6.json
Administrator: Yes

-Software Information-
Version: 3.3.1.2183
Components Version: 1.0.236
Update Package Version: 1.0.3316
License: Premium

-System Information-
OS: Windows 10 (Build 17035.1000)
CPU: x64
File System: NTFS
User: System

-Exploit Details-
File: 0
(No malicious items detected)

Exploit: 1
Malware.Exploit.Agent.Generic, , Blocked, [0], [392684],0.0.0

-Exploit Data-
Affected Application: Java
Protection Layer: Application Behavior Protection
Protection Technique: Java malicious inbound socket detected
File Name:
URL:

 

(end)

Link to post
Share on other sites

Hello @MartiniGM,

EDIT:

It looks like I was able to reproduce this issue. We are looking into what is triggering it, but for the time being, go ahead and follow this workaround: 

  1. Turn off just the inbound/outbound settings under Java Protection. (see attached screenshot)
  2. Reboot the machine
  3. Open MegaRAID Storage Manager, should load up correctly. 

 

Capture.thumb.PNG.827635313e11fefb85663e2a09383084.PNG

 

Thank you

Edited by vbarytskyy
Link to post
Share on other sites

  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.