<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic New German Wiper Blocked By SandBlast Agent Zero Day Prevention in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/New-German-Wiper-Blocked-By-SandBlast-Agent-Zero-Day-Prevention/m-p/59656#M3271</link>
    <description>&lt;P&gt;A thread on &lt;A title="german wiper" href="https://www.bleepingcomputer.com/forums/t/701735/germanwiper-ransomware-with-random-extensions-08kja-avco3-oqn1b/#entry4839002" target="_blank" rel="noopener"&gt;bleeping computer&lt;/A&gt;&amp;nbsp;describes an outburst of a new Wiper Malware. This wiper mimics Ransomware behavior but instead of encrypting the files it fills them with zeros (Nulls).&lt;/P&gt;
&lt;P&gt;Our SandBlast Agent Anti-Ransomware zero day prevention detects and remidiate this attack without a need to update or signature usage.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The files are encrypted in our honeypot&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EncryptedFilesnig1a.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2073i990999CCBAFE05A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="EncryptedFilesnig1a.png" alt="EncryptedFilesnig1a.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;File is indeed filled with Nulls and not possible to decrypt&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EncryptedFileWithNulls.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2074iAB81A45F32101D11/image-size/large?v=v2&amp;amp;px=999" role="button" title="EncryptedFileWithNulls.png" alt="EncryptedFileWithNulls.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;SandBlast Agent Anti-Ransomware detects the ransomware process encrypting the files&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EncryptionDetectedBySBAAntiRansomware.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2075i73C9FA0EA4D98629/image-size/large?v=v2&amp;amp;px=999" role="button" title="EncryptionDetectedBySBAAntiRansomware.png" alt="EncryptionDetectedBySBAAntiRansomware.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;SandBlast Agent restores the files&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EncryptedFileRestored.png" style="width: 598px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2076i2FDE029E604D77E0/image-size/large?v=v2&amp;amp;px=999" role="button" title="EncryptedFileRestored.png" alt="EncryptedFileRestored.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The infection is based on powershell script, I will move next to test this versus our File-Less infection prevention and update.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Gadi&lt;/P&gt;
&lt;DIV id="tinyMceEditorclipboard_image_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Mon, 05 Aug 2019 14:38:06 GMT</pubDate>
    <dc:creator>Gad_Naveh</dc:creator>
    <dc:date>2019-08-05T14:38:06Z</dc:date>
    <item>
      <title>New German Wiper Blocked By SandBlast Agent Zero Day Prevention</title>
      <link>https://community.checkpoint.com/t5/Endpoint/New-German-Wiper-Blocked-By-SandBlast-Agent-Zero-Day-Prevention/m-p/59656#M3271</link>
      <description>&lt;P&gt;A thread on &lt;A title="german wiper" href="https://www.bleepingcomputer.com/forums/t/701735/germanwiper-ransomware-with-random-extensions-08kja-avco3-oqn1b/#entry4839002" target="_blank" rel="noopener"&gt;bleeping computer&lt;/A&gt;&amp;nbsp;describes an outburst of a new Wiper Malware. This wiper mimics Ransomware behavior but instead of encrypting the files it fills them with zeros (Nulls).&lt;/P&gt;
&lt;P&gt;Our SandBlast Agent Anti-Ransomware zero day prevention detects and remidiate this attack without a need to update or signature usage.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The files are encrypted in our honeypot&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EncryptedFilesnig1a.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2073i990999CCBAFE05A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="EncryptedFilesnig1a.png" alt="EncryptedFilesnig1a.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;File is indeed filled with Nulls and not possible to decrypt&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EncryptedFileWithNulls.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2074iAB81A45F32101D11/image-size/large?v=v2&amp;amp;px=999" role="button" title="EncryptedFileWithNulls.png" alt="EncryptedFileWithNulls.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;SandBlast Agent Anti-Ransomware detects the ransomware process encrypting the files&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EncryptionDetectedBySBAAntiRansomware.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2075i73C9FA0EA4D98629/image-size/large?v=v2&amp;amp;px=999" role="button" title="EncryptionDetectedBySBAAntiRansomware.png" alt="EncryptionDetectedBySBAAntiRansomware.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;SandBlast Agent restores the files&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EncryptedFileRestored.png" style="width: 598px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2076i2FDE029E604D77E0/image-size/large?v=v2&amp;amp;px=999" role="button" title="EncryptedFileRestored.png" alt="EncryptedFileRestored.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The infection is based on powershell script, I will move next to test this versus our File-Less infection prevention and update.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Gadi&lt;/P&gt;
&lt;DIV id="tinyMceEditorclipboard_image_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 05 Aug 2019 14:38:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/New-German-Wiper-Blocked-By-SandBlast-Agent-Zero-Day-Prevention/m-p/59656#M3271</guid>
      <dc:creator>Gad_Naveh</dc:creator>
      <dc:date>2019-08-05T14:38:06Z</dc:date>
    </item>
  </channel>
</rss>

