Endpoint Protection

 View Only
Expand all | Collapse all

SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

  • 1.  SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jun 01, 2013 06:52 AM

    Dear Please,

    I am getting this message in my user pcs, i have seen this is only for windows xp computers. help me to solve this issue. how can i stop this kind of issues.

     

     

    "[SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application: C:\Program Files\Google\Chrome\Application\chrome.exe"

     

     

     

     



  • 2.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jun 01, 2013 07:32 AM

    This message mean that symantec Intrusion Prevention Component detected the attack of virus and blocked it.

    If you continuously get the message on that system then Check the thread to hide the option

    https://www-secure.symantec.com/connect/forums/constant-notification-traffic-has-been-blocked-application-svchostexe

    For the Safety you can Run the full scan on System

    Check it

    http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=25701

    Also Run the SymHelp tool and Submit the suspicious file to symantec

    https://www-secure.symantec.com/connect/articles/using-symantec-help-symhelp-tool-how-do-we-collect-suspicious-files-and-submit-same-symante

    https://www-secure.symantec.com/connect/articles/symantec-power-eraser-using-symantec-help-symhelp-tool



  • 3.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jun 01, 2013 08:26 AM

    This means that the IPS component is blocking a malicious attack.

    You need to find out what website the machine is attempting to browse to. Is this a user on your network?



  • 4.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jun 02, 2013 03:46 AM

    This is because the Symantec's IPS is blocking an intrusion attemt on your system. This alert can be caused when you visit any untrusted link. If you are getting this alert while browsing , then your system is safe uptill now. AS a precaution, you can delete your browser cookies to prevent repetation of this trigger.



  • 5.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Trusted Advisor
    Posted Jun 03, 2013 09:26 AM

    Hello,

    Check this: Web Attack: Exploit Toolkit Website 4

    http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=25701

    Do you have any Adobe Applications?

    It seems that some of the Applications installed on the machine are not updated with its vendor patches. Please make sure you have these application updated.

    Check this:

    http://www.securityfocus.com/bid/37331

    http://www.securityfocus.com/bid/37331/solution

    Would it be possible for you to check on the local machine if all the Products are up to date?

    Also, you can Run the SymHelp Utility to check if any suspicious files are found and if there are, submit the same to Symantec Security Response Team.

    Using Symantec Help (SymHelp) Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team.

    Hope that helps!!



  • 6.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Broadcom Employee
    Posted Jun 03, 2013 10:09 AM

    Hello,

    Follow the best practices:
     
    1) Install all the SEP features i.e. AV/AS, PTP & NTP.
     
    1) System should be updated with Service packs and windows patches.
     
    2) Make sure the machines are installed with the latest third party applications.
     
    3) Disable the Autorun Feature if not using SEP 12.1.
     
    Web Attack: Exploit Toolkit Website 4
     

    Severity: High

    This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

    Description

    This signature detects attempts to download exploits from a malicious toolkit which may compromise a computer through various vendor vulnerabilities.

    Additional Information

    Malicious toolkits contain various exploits bundled into a single package.Victim on visiting the malicious server hosting exploit toolkit is attacked with several different exploits exploiting different vulnerabilities one by one.Exploits may include MDAC,PDF,HCP etc.

    Refer this article: http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=25701

     



  • 7.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jul 22, 2013 05:57 AM
      |   view attached

    Dear pls help me,

    i ve probllem with a malware attack . when i opned my FB account and i want to play game call pool live tour when its loading to play at that time am getting message from norton " An intrusion attempted and blocked by norton"  this is from last three days only from that website remaining website its normal when am browsing. FB is trusted and the game is also trusted how it is possible to attack from a safe website >>

    What to do.......????????\

    here is the image of norton  contains attack details

    ......

    OS:

    windows 7,

    Help me plsss///....

    Thanks in Advns



  • 8.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jul 22, 2013 06:44 AM

    The threat is detected by IPS due to a continuous intrusion attempt. This detection triggers when a malicious Advertisement tries to load any malicious script. It is recommended, that you disable any pop-ups and play games over HTTPS service of Facebook to avoid any intrusion attempts.



  • 9.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jul 22, 2013 10:52 AM

    Thanks for your reply ,, but when i try disable Https service over facebook its saying that U need to enable https service to ensure security ...so what should i do.



  • 10.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jul 22, 2013 11:00 AM

    https is secure and recommended, why do you want to disable?



  • 11.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jul 23, 2013 12:28 AM

    hi Brian81 ,, thanks for ur reply...

    yes i know that but how to block popups from games in FB..???

    after alert msg getting from norton.. and i want to remove the threat from my pc.

    i ve scanned full pc three times nothing found ,.

    and i used malware bytes no use evrything is normal..

    norton power remover showing 0 risk items ..

     i tried  symantec help also nothing wrong with my pc..

    but when i want to play that game its loading and alert is asusual .....

    attempt blocked by norton ...

    i ve checked all progrms they are up to date..

    ..How to stop that attempt ....?????
     



  • 12.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Broadcom Employee
    Posted Jul 23, 2013 12:51 AM

    block the attacking computer 82.113.52.62



  • 13.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jul 23, 2013 02:06 AM

    Since the threat was already blocked by Norton, so your system is secure. It is advisable to move on HTTPS, or you can selectively block the IP.



  • 14.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jul 23, 2013 02:36 AM

    ok. i got it but how to do that tell me pls bcoz am new to this ...

    how to block that IP address



  • 15.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Broadcom Employee
    Posted Jul 23, 2013 02:50 AM

    you have desktop firewall, create a rule to block the IP.



  • 16.  RE: SID: 25701] Web Attack: Exploit Toolkit Website 4 detected. Traffic has been blocked from this application

    Posted Jul 23, 2013 04:46 AM

    i tried and its not working still getting message from norton "attempt blocked bt norton"

    now what??