IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Endpoint Standard: Repmgr.exe is detected with TTP: detected_malware_app

Endpoint Standard: Repmgr.exe is detected with TTP: detected_malware_app

Environment

  • Carbon Black Cloud console: All versions
  • Endpoint Standard Sensor: All versions

Symptoms

  • Repmgr.exe is detected as an involved process with TTP: detected_malware_app
  • The alert triage page displays the message:
The file <application>.exe was first detected on a local disk.
 The device was on the corporate network using the public address xx.xx.xx.xx.
 The file is not signed. 
 The file was accessed by the application C:\program files\confer\repmgr.exe.

Cause


Since a process contains a primary & target application, in the process of malware scanning , repmgr.exe is the primary application and malware is the target application.

Resolution

Application detected as malware has to be evaluated as per the organization's security standards.

Was this article helpful? Yes No
67% helpful (2/3)
Article Information
Author:
Creation Date:
‎03-28-2021
Views:
15701