BIP 12.2.1.4 desktop flagged with Malicious with high threat score
Summary:
Software packaging team has restricted BIP 12.2.1.4 desktop installation due to high threat score. Need a workaround so that we can continue to use BIP desktop for creating or extending BIP reports in Oracle Fusion Cloud.
Content (please ensure you mask any confidential information):
Here is excerpt of the log that is flagged as malicious when installing BIPublisherDesktop64.exe
Behavioral threat indicators
Malicious
2
Spawns a lot of processes
Source
Monitored Target
Relevance
8/10
MITRE ATT&CK
T1057
Details
Spawned process "BIPublisherDesktop64.exe" (UID: 00000000-00002732) Spawned process "ISBEW64.exe" with commandline "{EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{CE6AE24E-F0BD-4439-988D-44E8FEF13002}" (UID: 00000000-00001032) Spawned process"ISBEW64.exe" with commandline "{EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{A2BA5057-59DE-4654-9406-B7E6D8C81410}" (UID: 00000000-00009108) Spawned process "ISBEW64.exe" with commandline "{EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{30EDF42D-6FB6-4F21-980B-3971DE41405C}" (UID: 00000000-00004324) Spawned process "ISBEW64.exe" with commandline "{EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{D127FFA1-1BED-4DA8-AEA4-0D6E206E0ABC}" (UID: 00000000-00008628) Spawned process "ISBEW64.exe" with commandline "{EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{BC22945D-9801-48EC-9D5A-E000638F8FE3}" (UID: 00000000-00008724) Spawned process "ISBEW64.exe"with commandline "{EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{BD954CC4-6EBC-4DED-9398-DCEBF7977D23}" (UID: 00000000-00002900)Spawned process "ISBEW64.exe" with commandline "{EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{4156AD72-CB6E-4B01-955D-099F78382BFC}"(UID: 00000000-00004984) Spawned process "ISBEW64.exe" with commandline "{EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{573485B3-7