cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post

Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

Hi,

yesterday, during automatic scheduled update, a protection named "Trojan.Win32.Password-Unencrypted.A" was installed blocking all http connection.

As a workaround I change the protection from "prevent" to "detect".

Now, I can't find the protection in my database nor in the wiki, what's happened? How can I know if hte protection was retired?

kr,

Diego

1 Solution

Accepted Solutions

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

Searching the protection name in the Anti-BOT and changing form "protect" to "detect" before it was removed from the protection list.

Product: Anti-Bot
Protection ID: 00004C9C0
Protection Name: Trojan.Win32.Password-Unencrypted.A
Severity: Critical
Confidence Level: Medium

 

0 Kudos
13 Replies
Employee+
Employee+

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution
 
0 Kudos
jgaikwad
Ivory

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

Having this same issue today and was stumped when I couldnt find the protection at all.  Guessing I just need to reinstall policy and it will be fixed.

0 Kudos
miguel
Iron

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

This impacted our network greatly as well. Will be opening a ticket to get a RCA. In the meantime, any details that can be shared here how this could have happened?

0 Kudos

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

Searching the protection name in the Anti-BOT and changing form "protect" to "detect" before it was removed from the protection list.

Product: Anti-Bot
Protection ID: 00004C9C0
Protection Name: Trojan.Win32.Password-Unencrypted.A
Severity: Critical
Confidence Level: Medium

 

0 Kudos
Employee+
Employee+

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution
 
0 Kudos
Highlighted

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

I can't because now the protection is not in the list, anyway as in the samples below, i searched for the protection and changed Prevent to detect:

bot.jpg

0 Kudos
miguel
Iron

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

The action taken was "Redirect", I'm happy to share screenshot privately, I have support case number if you want.

phuocle
Ivory

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

I get the same problem. How can we solve this?

0 Kudos
RickLin
Silver

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

If you search and can find it, just change the Protection action from Prevent to Detect base on your Threat Prevention Profile.

Remember to install Threat Prevention policy to apply it.

It work for my customer at Monday.

1.png

0 Kudos
Employee+
Employee+

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

Hi all,

After getting reports of issues with this protection it was removed from the Anti-Bot package, hence the fact you can't see it now when searching. Anyway it will not return in its current form.

 

HTH

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution
All,
I showed the solution in my first post (change the protection to "detect"), I rather wondered why it was not present in the Anti-BOT wiki on this link https://threatwiki.checkpoint.com/threatwiki/public.htm

I think it would be correct to flag it as a "retired" (similar as in the Microsoft's patches) and wrote something in the knowledgebase.
 
Consider that the impact on our company has been remarkable ...
0 Kudos
jboco
Ivory

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

Hi All,

I had the same issue last Monday, May 20th, 2019. But when I'm looking into the Protection list. I can't find it anymore?

Did anyone confirm if the protection has been retired?

KR

 

0 Kudos
Employee+
Employee+

Re: Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

This protection is no longer part of the Anti-Bot dynamic package.

 

Omer Shliva | Team Leader, AB Research Protections and IPS/AB Customer Focus Team

0 Kudos