Anyone have information on New Trojan called: Adylkuzz
(Trojan.Adylkuzz is a Trojan horse that downloads a cryptocurrency miner onto the compromised computer)
Mostly affects old Windows.
Also I got an update from Checkpoint experts as below:
"Check Point protection currently detects: Adlkuzz (Trojan.Win32.Adylkuzz.a, Trojan.Win32.Adylkuzz.b, Trojan.Win32.Adylkuzz.c, Trojan.Win32.Adylkuzz.d) which utilizes SMB vulnerabilities to spread via Eternalblue and Doublepular; then ultimately mines Minero cryptocurrency on a compromised host"
But I have updated IPS Database and ThreatPrevention (AV/AB/AS all
were currently updated)
Unable to find those Trojan listed for protection.
Anyone can suggest.
Now we can see the signatures for Trojan - Adylkuzz in Anti-Bot. We can now action these to "Prevent"
(Trojan.Win32.Adylkuzz.A, Trojan.Win32.Adylkuzz.B, Trojan.Win32.Adylkuzz.C, Trojan.Win32.Adylkuzz.D, (Trojan.Win32.Adylkuzz.E, Trojan.Win32.Adylkuzz.F)
Retrieving data ...