Endpoint Protection

 View Only
Expand all | Collapse all

Cryptodefense ? Can SEP detect and stop it?

  • 1.  Cryptodefense ? Can SEP detect and stop it?

    Posted Mar 20, 2014 03:19 PM

    Running SEP 12.1.4

    Am I safe? Can SEP detect and clean this? I did a search but didn't find anything. I imagine Symantec probably references this virus with another name.

    Any recommendations on how we should combat this virus?



  • 2.  RE: Cryptodefense ? Can SEP detect and stop it?

    Posted Mar 20, 2014 03:23 PM

    CrytopLocker is detected by Symantec, 

    https://www-secure.symantec.com/connect/forums/cryptolocker-are-we-safe

    Have you checked in virustotal? Did that encrypt any of your files?

     



  • 3.  RE: Cryptodefense ? Can SEP detect and stop it?

    Posted Mar 20, 2014 03:37 PM

    I don't know if this is CrytoLocker or a new variant. 

    I've seen that link you shared and was wondering if it is the same issue.

     

    The virus I have is definitely calling itself "cryptodefense" 

    SEP doesn;t seem to have found anythign yet.

     

    http://www.bleepingcomputer.com/virus-removal/cryptodefense-ransomware-information



  • 4.  RE: Cryptodefense ? Can SEP detect and stop it?

    Posted Mar 20, 2014 03:40 PM

    Yeah I saw that :) they both do the same thing, encrypt and ask money. if you have a sample submit to symantec please

    https://submit.symantec.com/websubmit/retail.cgi

    tried malware bytes?



  • 5.  RE: Cryptodefense ? Can SEP detect and stop it?

    Posted Mar 20, 2014 08:58 PM

    SEP has multiple sigantures for the AV componentas well as multiple signatures for the IPS component so it can catch many variants. Ensure both are up to date.

    If this is a new variant than you will need to submit it for analysis.



  • 6.  RE: Cryptodefense ? Can SEP detect and stop it?

    Posted Mar 20, 2014 11:48 PM

    See some goot articles

    Killing Conficker: How to Eradicate W32.Downadup for Good

    https://www-secure.symantec.com/connect/articles/killing-conficker-how-eradicate-w32downadup-good

    The Day After: Necessary Steps after a Virus Outbreak

    https://www-secure.symantec.com/connect/articles/day-after-necessary-steps-after-virus-outbreak



  • 7.  RE: Cryptodefense ? Can SEP detect and stop it?

    Posted Mar 21, 2014 06:37 AM

    Hi M-NYC,

    It's impossible to confirm without knowing what exact MD5 that article is about.  From the description, though, it sounds like that article is talking about what Symantec calls Trojan.Nymaim.B.

    Trojan.Nymaim.B
    http://www.symantec.com/security_response/writeup.jsp?docid=2014-012318-0146-99

    AV and IPS protection (System Infected: Trojan.Ransomlock.AJ) will stop known variants of this threat.

    Definitely ensure you have IPS protection in place ("Two Reasons why IPS is a "Must Have" for your Network,") and a regular backup schedule.

    Hope this helps!

     

     

     



  • 8.  RE: Cryptodefense ? Can SEP detect and stop it?

    Posted Mar 24, 2014 06:55 AM

    Hi M-NYC,

    Just wondering if your query has been answered?  This thread is still marked "needs solution."

    All the best,

    Mick



  • 9.  RE: Cryptodefense ? Can SEP detect and stop it?

    Posted Mar 31, 2014 11:23 AM

    This official blog post by Symantc Security Response may be of interest:

    CryptoDefense, the CryptoLocker Imitator, Makes Over $34,000 in One Month

    https://www-secure.symantec.com/connect/blogs/cryptodefense-cryptolocker-imitator-makes-over-34000-one-month

    Protection
    Although not related, such were the similarities seen between CrytoDefense and Cryptolocker that Symantec initially detected this threat as Trojan.Cryptolocker along with numerous other detections. Symantec detects CryptoDefense under the following detection names:

    Antivirus detections

    Heuristic detections

    Reputation detections

    Intrusion prevention signatures



  • 10.  RE: Cryptodefense ? Can SEP detect and stop it?

    Posted Mar 31, 2014 11:37 AM

    @ Mick2009, team Symantec, excellent analysis here. Concur on the fact that you must definitely ensure you have IPS protection in place ("Two Reasons why IPS is a "Must Have" for your Network,") Much appreciated!!!!!



  • 11.  RE: Cryptodefense ? Can SEP detect and stop it?

    Posted Apr 22, 2014 09:52 PM

    Hi All,

    To prevent cryptolocker, my point of view is ,In order for Symantec to detect the cryptolocker, we might need the help from symantec to do forensic to the infected host because it is beyond our knowledge, also the variant and infectection vector is very different, some of them till now still no idea of it infection vector.

     

    Thanks