Jump to content

Recommended Posts

Posted

We have had issues with Groupcall since June 2021 when Sophos anti-virus decided to delete important Xporter files (which Groupcall acknowledged and liaised with Sophos to rectify). Although it still worked to provide the data export after we reinstalled it, our installation never really recovered. The software is extremely ‘chatty’ producing hundreds of logs in event viewer, (many hundreds of entries at a time) mostly with no description. It also uses ‘random’ file extensions for its update process which flags our server protection system (things like .cry and .xxx have been observed and if you are in I.T. I don’t need to tell you how disconcerting this is)… To their credit Groupcall had offered to remote in to our server and investigate, but this is complicated due to how locked down our system is, finding suitable times and allowing them permissions to change files.

 

Therefore Groupcall software was recently removed from our servers due to these ongoing issues.

 

Before this happened I spoke directly with Groupcall support to determine which data feeds this would impact and was told there were only 2 partners we share data with and those data feeds went to CPOMS and 2 Simple (for Purple Mash).

 

We moved those two data feeds over to Wonde as we currently use that to provide all of our other data export requirements and we view this change as a positive step for streamlining our procedures and reducing our GDPR exposure footprint. I believe Groupcall are fully GDPR compliant, but we would still like to simplify our data streams.

 

However, the LEA have just been in contact to ask why they haven't been receiving a data export from us... Now, I do seem to remember setting up a something like a B2B scheduled task and possibly something in Xporter about Meritec Jobs, but it was quite a few years ago. If these were a data export to the LEA then I guess they've been deleted and this is the issue.

 

So it would appear they will be asking us to reinstall Groupcall software and I'd really rather not. Although I have a feeling this is a statutory requirement and they aren't going to be very flexible....

 

Before I start going head to head with the LEA, does anyone have this kind of job set up and can it be done with Wonde?

Posted

I generally recommend every school to already have an account with Groupcall and Wonde, irrelevant what MIS you're using and you're pretty much covered.

 

From what you describe, I'd be inclined to have SIMS, Groupcall and Wonde on a new VM.

  • Thanks 1
Posted

Thanks, yeah the move to a separate VM for SIMS in in the pipeline, just seems like a waste of time to have to reinstall it for one export, then have to move it all over later on...

 

Somehow it appears the LEA have never heard of Wonde and Groupcall are their "preferred and contracted way of extracting the data".

 

CPOMS said the same and initially were unimpressed with the idea of us moving to Wonde, seems like Groupcall really cornered the market at one point!

Posted

They didn't really corner the market as such due to being ourstanding or anything - they were pretty much the only third party transfer tool around 10 years ago.

 

We've dumped groupcall and everything is in Wonde now.

 

The fact your LEA have not heard of Wonde demonstrates that they are strategically operating 10 years in the past...

Posted

Precisely...

 

However, CPOMS were not best pleased we wished to move our data extraction to Wonde either.... something about contractually obliged partner, deeper integration, high level support, our Groupcall import code is far superior and is always being improved, close relationship, we are in daily communication with Groupcall's support and leadership teams if issues were to ever arise with the integration.... blah, blah, blah....

 

Anyway, I installed the software... does anyone know why Groupcall needs a SIMS user (I mean I know why) and Wonde although it has a 'user' there is no password for it so I'm not sure how it does the extraction....?

 

I thought the next issue might have been resolved with an uninstall/reinstall but in June 2021 when Sophos anti-virus decided to delete important Xporter files (which Groupcall acknowledged and liaised with Sophos to rectify), it still worked after a 'repair' but it's so chatty and there is no description in the event log...

 

"The description for Event ID 1 from source Groupcall Xporter (4734141e42cb4632ba8f88188b9ae3ac) cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer"

 

"The description for Event ID 2 from source Groupcall Xporter (4734141e42cb4632ba8f88188b9ae3ac) cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer"

 

"The description for Event ID 256 from source Groupcall Xporter (4734141e42cb4632ba8f88188b9ae3ac) cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer"

 

My server event log was full within a few minutes (I mean thousands of events) and although some do have 'extra' information included, why hook it into the 'event log' (nothing else seems to be so verbose and anyway I'm sure it's got it's own log....?).

 

The worst part is the my server is emailing me saying that is has found files with the extension of .ecc and.kkk - well known cryptolocker virus extensions.... I have also had in the past...

 

Groupcall_Cry.jpg

 

Supposedly these are random file extensions but come on guys!!! And yes, I know... as their support said 'whitelist all the Groupcall things'... but I want to reduce the amount of directories that don't get virus checked not increase it! :doh:

 

I suppose I'm going to jinx it now, but Wonde has had zero issues....

Posted
Two alerts I got over the weekend...

 

[ATTACH=CONFIG]69243[/ATTACH]

 

Do you think the Groupcall coders are secretly just having a laugh...?

 

It's been that way for years sadfully (example from 2018) - http://www.edugeek.net/forums/security/196320-groupcall-crypto-vulnerability-something-else.html#post1678329 - and basically confirmed as you said, that only way to avoid it would be bypassing the entire temp folder which isn't recommended.

 

The only other way I could think of doing it (while still a bodge, but less of a security risk) is scripting a Bypass rule to add to the FSRM service for that minute that the GroupCall process runs (assuming that alert is from around that 1am window it used to run?), and then removing it again after. So it's only activated on the temp folder for that minute or two it needs to process the file

 

Steve

  • Thanks 1
Posted

Thanks! Well spotted!

 

Yes, I had been told so was aware they were 'randomly generated' and we've been using it for a few years (surprised it wasn't a link to of mine where I was complaining about it though - as I am getting grumpier in my old age) so I think I had just 'sucked it up' and lived with it.

 

That's twice in recent succession I've had those file types though, so not as 'random' as advertised...

  • 2 weeks later...
Posted

Yet, another 'random' file extension from Groupcall... and yes, I know that the fact it's random means it can actually be anything (even real words or well known Cryptolocker virus extensions) but this is the only software we have that gives me a heart attack on a regular basis!

 

FUN.jpg

 

"This is an article that provides specific details on .fun files virus infection.

 

After the detection of several Jigsaw ransomware iterations this month other three versions of the ransomware has been spotted in active attack campaigns. They are all associated with the extension .fun and as typical data locker ransomware all aim to blackmail victims into paying a ransom for decryption of valuable data."

 

"What is the Fun virus?

Fun virus is a variant of Jigsaw ransomware that encrypts files, adds the .fun file extension to the end of the file name, and downloads a ransom note on Windows Desktop and in every folder it encrypted files in."

 

What is Jigsaw ransomware?

Jigsaw is ransomware that uses the AES algorithm to encrypt various files stored on computers.

 

After encryption, this ransomware displays a window with a message listing the encrypted files and stating that victims can only restore them by paying a ransom. In addition, every sixty minutes, .Fun deletes a certain number of files, thus, putting victims under pressure to pay, since delays result in permanent deletion of more files

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...