Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
MarcuzShinz
Contributor

Check the correctness of Threat Prevention

Dear Guy!

Currently on our Threat Prevention interface there are some logs related to Check Point scanning traffic and found some machines infected with Ramnit Bot.

However, under the desktop we used Trend Micro and deep scan but could not find this bot. Is Check Point showing it correctly?

How can we find this Bot and clean with it.

 

2024-08-28_103331.png

0 Kudos
2 Replies
Lesley
Leader Leader
Leader

- open the relevant packet captures in the traffic logs (most of the time there is a packet capture)

with this capture you can find more info related to this Ramnit.

Also reflect the information with this article:

https://community.checkpoint.com/t5/Threat-Intelligence-Reports/sLoad-Delivering-Ramnit/ba-p/175

https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ramnithttps://www.trendmicro.com/vin...

I suspect false positive because Ramnit is from 2011 and came back years after in a modified version

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
G_W_Albrecht
Legend Legend
Legend

Open a SR# with CP TAC to get help for this !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events