Does Avast detect the hacked 3CX dlls?

It’s all in the subject line.

Thanks.

https://www.virustotal.com/gui/file/dde03348075512796241389dfea5560c20a3d2a2eac95c894e7bbed5e85a0acc?nocache=1

https://www.bleepingcomputer.com/news/security/hackers-compromise-3cx-desktop-app-in-a-supply-chain-attack/

When the MSI or update is installed, it will extract malicious ffmpeg.dll [VirusTotal] and the d3dcompiler_47.dll [VirusTotal] DLL files, which are used to perform the next stage of the attack.
https://www.virustotal.com/gui/file/7986bbaee8940da11ce089383521ab420c443ab7b15ed42aed91fd31ce833896?nocache=1

https://www.virustotal.com/gui/file/11be1803e2e307b647a8a7e02d128335c448ff741bf06bf52b332e0bbf423b03?nocache=1

Thanks for that info, Pondus, very informative as always.
Happy Easter to you as well.
And for all: “Never put all your eggs in one and the same basket”.

Additionally after the supply chain attack a newer version was launched.

Install this latest version, which apparently is not flagged by any av-vendor:
https://www.virustotal.com/gui/url/f933a56503f1ad8fe9ca16db4af721b25fb85b5f5fe1a0f88cb8b6d7e73d10e6?nocache=1

Communicating file flagged: 2023-03-31
1/ 60 Windows Installer 3CXPhoneforWindows.msi

Read from them for the windows installer, from their forums I read:
Re: https://www.3cx.com/community/threads/new-desktop-app-build-number-18-12-425-released.120123/

polonus

Thank you both. We’re running the “legacy” desktop app, which appears to be unaffected by this issue.