Jump to content

Intenta

Members
  • Posts

    5
  • Joined

  • Last visited

About Intenta

  • Rank
    Newbie
    Newbie

Profile Information

  • Location
    Germany
  1. Some vendors updated their signature databases and no longer flag the file "epi.exe" as malicious. The download of All-In-One installers through the ESET Protect UI is finally working for us now (without configuring any exceptions). Thanks!
  2. Thanks for your eager efforts @itman. However I fear you might possibly cause further confusion to fellow readers of this topic, hehe. No offense intended. After some further analysis of my own regarding the "epi.exe" with the sha256 hash of 950a48235da3dde7f4376cebcceb85353ab2feff03646ff72f9718b9cf5c30a7 seems to be a confirmable false-positive. I'd like if ESET posted an official statement or tries to build a new bootstrapper which doesn't get falsely flagged as potentially malicious. Similar to their old one from Aug 2020 (hxxp://repository.eset.com/v1/com/eset/tools/installers/bootstrapper_era/v2/2.0.47.0/epi.exe - sha256: d821eb22cbe802d4077a6f57bf8b9ed1a6fc93bdc1605e50426b09f41ca7ec7b).
  3. Actually this could help with the process of deciding weather it might be safe to whitelist the file at all. Additionally I'd prefer the file being digitally signed. I'm sure most IT professionals have been following the news regarding SolarWinds. Someone can never be too cautious these days, although the VT result looks indeed like an false positive only and potential threat actors wouldn't be so sloppy to get caught by VT in the first place.
  4. It's being blocked by our Unified Threat Management solution which uses vendor specific anti-malware measures to be precisely. It's possibly checking file hashes against VirusTotal or whatever. That's not the important point right now. Just that I understand your proposed solution correctly: you want me to to whitelist the download of the "epi.exe", which isn't digitally signed, and ignore the VirusTotal results of other AntiVir products?
  5. Same issues here. Turns out that the file under hxxp://repository.eset.com/v1/com/eset/tools/installers/bootstrapper_era/v4/4.0.12.0/epi.exe is being declared malicious by various AntiMalware solutions: https://www.virustotal.com/gui/file/950a48235da3dde7f4376cebcceb85353ab2feff03646ff72f9718b9cf5c30a7/detection
×
×
  • Create New...