Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"

Jump to solution

Hi,

yesterday, during automatic scheduled update, a protection named "Trojan.Win32.Password-Unencrypted.A" was installed blocking all http connection.

As a workaround I change the protection from "prevent" to "detect".

Now, I can't find the protection in my database nor in the wiki, what's happened? How can I know if hte protection was retired?

kr,

Diego

1 Solution

Accepted Solutions
Highlighted

Searching the protection name in the Anti-BOT and changing form "protect" to "detect" before it was removed from the protection list.

Product: Anti-Bot
Protection ID: 00004C9C0
Protection Name: Trojan.Win32.Password-Unencrypted.A
Severity: Critical
Confidence Level: Medium

 

View solution in original post

0 Kudos
13 Replies
Highlighted
Employee+
Employee+
 
0 Kudos
Highlighted
Ivory

Having this same issue today and was stumped when I couldnt find the protection at all.  Guessing I just need to reinstall policy and it will be fixed.

0 Kudos
Highlighted
Iron

This impacted our network greatly as well. Will be opening a ticket to get a RCA. In the meantime, any details that can be shared here how this could have happened?

0 Kudos
Highlighted

Searching the protection name in the Anti-BOT and changing form "protect" to "detect" before it was removed from the protection list.

Product: Anti-Bot
Protection ID: 00004C9C0
Protection Name: Trojan.Win32.Password-Unencrypted.A
Severity: Critical
Confidence Level: Medium

 

View solution in original post

0 Kudos
Highlighted
Employee+
Employee+
 
0 Kudos

I can't because now the protection is not in the list, anyway as in the samples below, i searched for the protection and changed Prevent to detect:

bot.jpg

0 Kudos
Highlighted
Iron

The action taken was "Redirect", I'm happy to share screenshot privately, I have support case number if you want.

Highlighted
Ivory

I get the same problem. How can we solve this?

0 Kudos
Highlighted
Silver

If you search and can find it, just change the Protection action from Prevent to Detect base on your Threat Prevention Profile.

Remember to install Threat Prevention policy to apply it.

It work for my customer at Monday.

1.png

0 Kudos
Highlighted
Employee+
Employee+

Hi all,

After getting reports of issues with this protection it was removed from the Anti-Bot package, hence the fact you can't see it now when searching. Anyway it will not return in its current form.

 

HTH

Highlighted
All,
I showed the solution in my first post (change the protection to "detect"), I rather wondered why it was not present in the Anti-BOT wiki on this link https://threatwiki.checkpoint.com/threatwiki/public.htm

I think it would be correct to flag it as a "retired" (similar as in the Microsoft's patches) and wrote something in the knowledgebase.
 
Consider that the impact on our company has been remarkable ...
0 Kudos
Highlighted
Ivory

Hi All,

I had the same issue last Monday, May 20th, 2019. But when I'm looking into the Protection list. I can't find it anymore?

Did anyone confirm if the protection has been retired?

KR

 

0 Kudos
Highlighted
Employee+
Employee+

This protection is no longer part of the Anti-Bot dynamic package.

 

Omer Shliva | Team Leader, AB Research Protections and IPS/AB Customer Focus Team

0 Kudos