<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Absolute Software CTES - Multiple alerts - Variant Lazy in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5295828#M8863</link>
    <description>&lt;DIV class="lia-quilt-row lia-quilt-row-message-header-bottom"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-18 lia-quilt-column-left lia-quilt-column-message-header-bottom-left"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-left"&gt;
&lt;DIV class="lia-message-author-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV id="bodyDisplay" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV id="bodyDisplay" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;Had multiple machines alerting for Absolute Software CTES files:&lt;/P&gt;
&lt;P data-unlink="true"&gt;Names:&amp;nbsp;&lt;SPAN class="text"&gt;CtGeoPrvPackage.zip&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class="text"&gt;GEO_Windows-GEO-1.0.13.6&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SHA256: dcadf2ca20756544ac8a007a1da94e6f932770558128658280a5ece2828791da&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="text"&gt;Name: abwfscnEx.dll&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="text"&gt;SHA256:&amp;nbsp;b3c1247951b553e062a3038d886562d5c80ff96abed729fb73524f3341a18931&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="text"&gt;All of this comming from the path:&amp;nbsp;C:\ProgramData\CTES\&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="text"&gt;Detectión:&amp;nbsp;Gen:Variant.Lazy&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I'm pretty sure this is a false positive but I've had a look and cant find any information anywhere yet cause I think its quite recent, just wanted to check in and see if anyone else has experienced the same?&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 02 Jun 2025 14:41:33 GMT</pubDate>
    <dc:creator>kelvin ortega</dc:creator>
    <dc:date>2025-06-02T14:41:33Z</dc:date>
    <item>
      <title>Absolute Software CTES - Multiple alerts - Variant Lazy</title>
      <link>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5295828#M8863</link>
      <description>&lt;DIV class="lia-quilt-row lia-quilt-row-message-header-bottom"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-18 lia-quilt-column-left lia-quilt-column-message-header-bottom-left"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-left"&gt;
&lt;DIV class="lia-message-author-avatar"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV id="bodyDisplay" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-main"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-main-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV id="bodyDisplay" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;Had multiple machines alerting for Absolute Software CTES files:&lt;/P&gt;
&lt;P data-unlink="true"&gt;Names:&amp;nbsp;&lt;SPAN class="text"&gt;CtGeoPrvPackage.zip&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class="text"&gt;GEO_Windows-GEO-1.0.13.6&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SHA256: dcadf2ca20756544ac8a007a1da94e6f932770558128658280a5ece2828791da&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="text"&gt;Name: abwfscnEx.dll&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="text"&gt;SHA256:&amp;nbsp;b3c1247951b553e062a3038d886562d5c80ff96abed729fb73524f3341a18931&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="text"&gt;All of this comming from the path:&amp;nbsp;C:\ProgramData\CTES\&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&lt;SPAN class="text"&gt;Detectión:&amp;nbsp;Gen:Variant.Lazy&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I'm pretty sure this is a false positive but I've had a look and cant find any information anywhere yet cause I think its quite recent, just wanted to check in and see if anyone else has experienced the same?&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 02 Jun 2025 14:41:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5295828#M8863</guid>
      <dc:creator>kelvin ortega</dc:creator>
      <dc:date>2025-06-02T14:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: Absolute Software CTES - Multiple alerts - Variant Lazy</title>
      <link>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5295901#M8864</link>
      <description>&lt;P&gt;Hi Kevin,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;What engine is detecting this FP?&amp;nbsp; Just navigate to the Event page then pivot to Device Trajectory and look under right side for the event details which engine complaints about this. &lt;BR /&gt;&lt;BR /&gt;Then you can either exclude the files but &lt;STRONG&gt;preferably&lt;/STRONG&gt; open TAC case and let us handle the detection directly. If it is true FP we will fix the disposition on our end.&lt;BR /&gt;&lt;BR /&gt;FYI: the two SHA256 seem to be non malicious based on my quick search.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;1: dcadf2ca20756544ac8a007a1da94e6f932770558128658280a5ece2828791da&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;VirusTotal Detections:6/66&lt;BR /&gt;ClamAV: Not Detected&lt;BR /&gt;TETRA: Not Detected&lt;BR /&gt;Sophos: Not Detected&lt;BR /&gt;McAfee: Not Detected&lt;BR /&gt;File Name: CtGeoPrvPackage.zip&lt;BR /&gt;File Size: 2,945 KB&lt;BR /&gt;File Type: ZIP&lt;BR /&gt;File Magic: Zip archive data, at least v2.0 to extract, compression method=deflate&lt;BR /&gt;First Seen: 2025-06-02 03:53:26 UTC&lt;BR /&gt;Last Scanned: 2025-06-02 17:30:43 UTC&lt;BR /&gt;&lt;STRONG&gt;threatgrid.com Threat Score: 66&lt;/STRONG&gt;&lt;BR /&gt;Sample ID: 71425efb187c075c6a77fdfb6d46b495&lt;BR /&gt;File Size: 4,961 KB&lt;BR /&gt;File Magic: PE32 executable (console) Intel 80386, for MS Windows&lt;BR /&gt;Last Analyzed: 2025-06-02 17:36:03 UTC&lt;BR /&gt;threatgrid.eu No report returned.&lt;BR /&gt;threatgrid.ca No report returned.&lt;BR /&gt;threatgrid.com.au No report returned.&lt;BR /&gt;Talos Intel No report returned.&lt;BR /&gt;AMP Cloud NA Disposition: Unknown&lt;BR /&gt;EU Disposition: Unknown&lt;BR /&gt;APJC Disposition: Unknown&lt;BR /&gt;&lt;STRONG&gt;Threat Metascore: 43 ~ File appears to be benign &amp;lt;&amp;lt; ----------&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2: b3c1247951b553e062a3038d886562d5c80ff96abed729fb73524f3341a18931&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;VirusTotal Detections: 0/72&lt;BR /&gt;ClamAV: Not Detected&lt;BR /&gt;TETRA: Not Detected&lt;BR /&gt;Sophos: Not Detected&lt;BR /&gt;McAfee: Not Detected&lt;BR /&gt;File Name: ProviderHost&lt;BR /&gt;File Size: 863 KB&lt;BR /&gt;File Type: Win32 EXE&lt;BR /&gt;File Magic: PE32 executable (console) Intel 80386, for MS Windows&lt;BR /&gt;Absolute Software Corp. Expires: 10:15 PM 12/19/2027&lt;BR /&gt;SSL.com EV Code Signing Intermediate CA RSA R3 Expires: 05:44 PM 03/22/2034&lt;BR /&gt;SSL.com EV Root Certification Authority RSA R2 Expires: 06:14 PM 05/30/2042&lt;BR /&gt;Product Name: ProviderHost&lt;BR /&gt;Product Version: 1.0.0.3619&lt;BR /&gt;First Seen: 2025-03-05 09:29:44 UTC&lt;BR /&gt;Last Scanned: 2025-05-12 14:11:17 UTC&lt;BR /&gt;&lt;STRONG&gt;threatgrid.com Threat Score: 25&lt;/STRONG&gt;&lt;BR /&gt;Sample ID: 5d3b4990ceacd70262f40ea92c866c2c&lt;BR /&gt;File Size: 863 KB&lt;BR /&gt;File Magic: PE32 executable (console) Intel 80386, for MS Windows&lt;BR /&gt;Last Analyzed: 2025-06-02 15:01:12 UTC&lt;BR /&gt;threatgrid.eu Threat Score: 24&lt;BR /&gt;Sample ID: 1e94b3660e74ff8c76d7fde59ece2684&lt;BR /&gt;File Size: 863 KB&lt;BR /&gt;File Magic: PE32 executable (console) Intel 80386, for MS Windows&lt;BR /&gt;Last Analyzed: 2025-05-19 07:07:06 UTC&lt;BR /&gt;threatgrid.ca No report returned.&lt;BR /&gt;threatgrid.com.au No report returned.&lt;BR /&gt;Talos Intel No report returned.&lt;BR /&gt;AMP Cloud NA Disposition: Unknown&lt;BR /&gt;EU Disposition: Unknown&lt;BR /&gt;APJC Disposition: Unknown&lt;BR /&gt;&lt;STRONG&gt;Threat Metascore: 25 ~ File appears to be benign &amp;lt;&amp;lt; ----------&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 19:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5295901#M8864</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2025-06-02T19:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Absolute Software CTES - Multiple alerts - Variant Lazy</title>
      <link>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5295914#M8865</link>
      <description>&lt;P&gt;Hi Roman&lt;/P&gt;
&lt;P&gt;This events are Detected by the Tetra engines.&lt;/P&gt;
&lt;P&gt;I've already opened a TAC case, awaiting a response.&lt;/P&gt;
&lt;P&gt;Thank you for your comments, I will wait for the TAC's resolution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 18:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5295914#M8865</guid>
      <dc:creator>kelvin ortega</dc:creator>
      <dc:date>2025-06-02T18:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Absolute Software CTES - Multiple alerts - Variant Lazy</title>
      <link>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5295923#M8866</link>
      <description>&lt;P&gt;Sounds good If this is Tetra engine then it will be handled by our Internal Talos Team. TAC will just need the samples if you didn't provide them yet. &lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 19:18:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5295923#M8866</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2025-06-02T19:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Absolute Software CTES - Multiple alerts - Variant Lazy</title>
      <link>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5299781#M8870</link>
      <description>&lt;P&gt;Did you ever figure out anything with this? Seems to me, that Cisco is catching the fact these outdated CTES agents have a CVE. However I am not finding how to update the CTES.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 21:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5299781#M8870</guid>
      <dc:creator>Francis Skibicki III</dc:creator>
      <dc:date>2025-06-16T21:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Absolute Software CTES - Multiple alerts - Variant Lazy</title>
      <link>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5305471#M8898</link>
      <description>&lt;P&gt;Hi Francis, Cisco passed the sample to TALOS and they confirmed it's a Falpos, and the signature was updated. However, some Absolute files are still pending, because now I'm seeing detections for NTAgent.exe. If it continues the same, I'll file another case to have the signature updated.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 19:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5305471#M8898</guid>
      <dc:creator>kelvin ortega</dc:creator>
      <dc:date>2025-07-03T19:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Absolute Software CTES - Multiple alerts - Variant Lazy</title>
      <link>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5306567#M8899</link>
      <description>&lt;P&gt;Yes I have been seeing the same. Thanks for the update, I have just been Whitelisting for now.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 15:24:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/absolute-software-ctes-multiple-alerts-variant-lazy/m-p/5306567#M8899</guid>
      <dc:creator>Francis Skibicki III</dc:creator>
      <dc:date>2025-07-07T15:24:42Z</dc:date>
    </item>
  </channel>
</rss>

