Cleo VLTrader/Lexicom
Need Help Applying These Steps or Have Been Breached? Reach out to ReliBiz for Reliable IT Services www.ReliBiz.com
12/9/24 Vulnerability Mitigation Steps
The Steps for both VLTrader and Lexicom are Identical except for the file path.
WHEN MAKING ANY CHANGE YOU MUST RESTART THE LEXICOM/VLTRADER SERVICE. IF YOU CLEAR A BREACHED FILE, IT REMAIN IN MEMORY UNTIL YOU RESTART THE SERVICE.
Check Version
Open C:\LexiCom\LexiCom.exe or C:\VLTrader\VLTrader.exe
Click Help > About

Click Help > About
Ensure the Version is 5.8.0.21

Ensure the Version is 5.8.0.21 or better
Click Close
Update
If Your Version is 5.8.0.21+ Skip To “Change Autorun”
Click Tools and then Software Update

Click Tools and then Software Update
If the information in the Contact Section is not Correct or is Blank, Fill out the Information and then Click Reregister, (And then Check Registration, and then Register) If it’s filled out, skip to 3.

Fill our the contact information
Click Check for Update

After you've filled out the contact information and reregistered, Click Check for Update
Follow the Prompts. If you are currently upgrading from another 5.8.0.0 Revision see Appendix A Below for guidance. If you are upgrading from an earlier version, you will likely need to go through a separate installation process.
If you are currently upgrading from another 5.8.0.0 Revision Follow these steps. If you are upgrading from an earlier version, you will likely need to go through a separate installation process.
Click Save

Save the File
Accept the Terms and then Click Continue

Agree and Click COntinue
Click Okay

Click OK
Click Okay (again)

Click OK
After you have completed the install process, press the Windows + R Key, and type
services.msc
Start the Services Snapin
Look for Lexicom or VL Trader Right Click on it, and then Click Restart

Restart the Servce
Check the Version Again
Repeat this process until you See Version 5.8.0.21
IT IS VERY IMPORTANT THAT YOU REPEAT THIS UNTIL YOU SEE VERSION 5.8.0.21. MAJOR REVISIONS WILL NOT INSTALL THE LATEST 5.8 VERSION!
Change AutoRun Folder
Open Lexicom/VLTrader If it’s not already open
Click Configure and then Options

Open Options
Click the Other tab
Change the Autorun Directory to Autorun-DummyFolder\
THIS DIRECTORY MUST NOT EXIST!
Click in any Other White Space on the Tab
Click OK

Replace the Auto Run Directory with Non-Existing Directory, Click White Space and then OK.
Set Folders and Files to Read Only
Navigate to C:\Lexicom or C:\VLTrader
Right Click on Auto Run
Click Properties
Click the “Read-Only” Box Until it is a Check Mark

Click Okay

Set the Read Only Attribute
Navigate to C:\LexiCom\webserver\AjaxSwing\conf\templates\default-page or C:\VLTrader\webserver\AjaxSwing\conf\templates\default-page
Highlight body-footer,body-footerVL,Body-header,body-headerVL files. (Press and Hold CTRL while clicking files to select multiple files)
Right click on any of the files you have selected
Click the Read-Only Box Until it is Checked
Click Ok

Set the Read Only Attribute on all files starting with Body
Detecting a Breach
Navigate to C:\Lexicom\host or C:\VLTrader\host
If you see a guid string (i.e. 60282967-dc91-40ef-a34c-38e992509c2c.xml) This indicates a breach

This is an example of a breached system
Search all XML Files in this directory for the word “Powershell”, or “Bash”, and in some cases cmd. If you see these this indicates a breach,
IN A TEXT EDITOR ONLY DO NOT LAUNCH IN WEB BROWSER

This is an example of base64 injection
Then Navigate to
C:\LexiCom\webserver\AjaxSwing\conf\templates\default-page or
C:\VLTrader\webserver\AjaxSwing\conf\templates\default-page
IN A TEXT EDITOR OPEN THESE FILES. IN A TEXT EDITOR. (Notepad, Notepad++ etc)
Compare to the files that start with body to the examples below
