- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Check the correctness of Threat Prevention
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check the correctness of Threat Prevention
Dear Guy!
Currently on our Threat Prevention interface there are some logs related to Check Point scanning traffic and found some machines infected with Ramnit Bot.
However, under the desktop we used Trend Micro and deep scan but could not find this bot. Is Check Point showing it correctly?
How can we find this Bot and clean with it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- open the relevant packet captures in the traffic logs (most of the time there is a packet capture)
with this capture you can find more info related to this Ramnit.
Also reflect the information with this article:
https://community.checkpoint.com/t5/Threat-Intelligence-Reports/sLoad-Delivering-Ramnit/ba-p/175
I suspect false positive because Ramnit is from 2011 and came back years after in a modified version
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Open a SR# with CP TAC to get help for this !
