- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: infected with techunity.tc.b
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
infected with techunity.tc.b
I have in infected devices on the Checkpoint 790 Appliance saying the router is infected with the techunity.tc.b
I found it because I am having issue with an RDP brute force attach originating from the external ip of the same checkpoint.
I do have RDP NAT but to another server with IP restrictions.
I turned off the RDP NAT and it still happens originating from the router.
Any suggestions would be great.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not sure why you posted this in the DevSecOps group.
Also “the router is infected” what precise information did you see?
Screenshots (redacting sensitive data) would be helpful, as would the precise firmware version and build.
Some details about the malware in question: https://threatpoint.checkpoint.com/ThreatPortal/threat?threatType=malware&threatId=32312779
General remediation steps: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not sure why you posted this in the DevSecOps group.
Also “the router is infected” what precise information did you see?
Screenshots (redacting sensitive data) would be helpful, as would the precise firmware version and build.
Some details about the malware in question: https://threatpoint.checkpoint.com/ThreatPortal/threat?threatType=malware&threatId=32312779
General remediation steps: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry about that will Close the question.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I moved it to the correct place, all good.