- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Anti-Bot protection "Trojan.Win32.Password-Unencry...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anti-Bot protection "Trojan.Win32.Password-Unencrypted.A"
Hi,
yesterday, during automatic scheduled update, a protection named "Trojan.Win32.Password-Unencrypted.A" was installed blocking all http connection.
As a workaround I change the protection from "prevent" to "detect".
Now, I can't find the protection in my database nor in the wiki, what's happened? How can I know if hte protection was retired?
kr,
Diego
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Searching the protection name in the Anti-BOT and changing form "protect" to "detect" before it was removed from the protection list.
Product: Anti-Bot
Protection ID: 00004C9C0
Protection Name: Trojan.Win32.Password-Unencrypted.A
Severity: Critical
Confidence Level: Medium
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Having this same issue today and was stumped when I couldnt find the protection at all. Guessing I just need to reinstall policy and it will be fixed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This impacted our network greatly as well. Will be opening a ticket to get a RCA. In the meantime, any details that can be shared here how this could have happened?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Searching the protection name in the Anti-BOT and changing form "protect" to "detect" before it was removed from the protection list.
Product: Anti-Bot
Protection ID: 00004C9C0
Protection Name: Trojan.Win32.Password-Unencrypted.A
Severity: Critical
Confidence Level: Medium
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can't because now the protection is not in the list, anyway as in the samples below, i searched for the protection and changed Prevent to detect:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The action taken was "Redirect", I'm happy to share screenshot privately, I have support case number if you want.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I get the same problem. How can we solve this?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you search and can find it, just change the Protection action from Prevent to Detect base on your Threat Prevention Profile.
Remember to install Threat Prevention policy to apply it.
It work for my customer at Monday.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi all,
After getting reports of issues with this protection it was removed from the Anti-Bot package, hence the fact you can't see it now when searching. Anyway it will not return in its current form.
HTH
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think it would be correct to flag it as a "retired" (similar as in the Microsoft's patches) and wrote something in the knowledgebase.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi All,
I had the same issue last Monday, May 20th, 2019. But when I'm looking into the Protection list. I can't find it anymore?
Did anyone confirm if the protection has been retired?
KR
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This protection is no longer part of the Anti-Bot dynamic package.
Omer Shliva | Team Leader, AB Research Protections and IPS/AB Customer Focus Team
