Endpoint Protection Small Business Edition

 View Only
Expand all | Collapse all

Endpoint Protection not detecting Malware with signature

Mick2009

Mick2009Mar 24, 2014 08:45 AM

Migration User

Migration UserMar 24, 2014 08:55 AM

  • 1.  Endpoint Protection not detecting Malware with signature

    Posted Mar 21, 2014 07:33 AM

    Last week, several of my users receved a targeted email which looked like it was sent by RIBA in the UK, and had only one spelling mistake (which gave it away).  The mail was forwarded on to me to check. The email had a word document that said the user had to run the macro attached to see what the document says. This macro creates a randomly named exe file, runs it, creates the registry key ADCBA753-DDBC-83D7-A662-3CA44878B697, adds it to the start up processes, and tries to connect to Ntemegreto.ru which at time of analyis connects to 88.198.11.14 via netbios. At no point did Synamtec Endpoint Protection detect this know infection, so i contacted the support as this was a major concern and got through to a technical support agent who after checking all of the possible things that could be stopping it from happening agreed that it was a problem escalated to the next level of support.

    They tried blaming vairous programs that were installed on the machine (such as wireshark) for the issue but after sending in even more data agreed that it was a problem and was very concerned about this but only offered tips on securing a network without an explination on the actual problem, so the agent suggested I send an email to them which I have not recevied any reply to at all.

    Obviously, this is unacceptable as the issue was initially reported over a week ago, and we are no closer to getting a resolution or any assurances that Symantec are even looking into the threat.  Please see below the email which was sent to Symantec.

     

    As discussed, I would like you to investigate why Endpoint Protection hasn’t picked up the the aforementioned malware. Please find below an outline of the current setup and explanation of what has happened thus far:

    Issue: The problem we are currently having is that Symantec Endpoint Protection is not detecting a piece of malware (

    Setup: Windows 7 Professional, running on a virtual machine hosted on Hyper-V, which was connected to the Synamtec Management Console to fully update with the newest defenitions. The virtual machine was then disconnected from the network and in a sealed environment to prevent the malware spreading.

    Process: The email was then opened, the Word (.docx) file was saved to the computer, and then the contained macro that contains the malware was allowed to run. The exe file that was created was then scanned, and at no point was the malware detected, even after a restart of the computer the malware was still no found. A full scan eventually detected the running process, but not until well after the initial infection was able to spread. It was eventually picked up as the Trojan.Zbot!gen19 infection, which Symantec are aware of (here: http://www.symantec.com/security_response/writeup.jsp?docid=2011-052508-4728-99 )

    The extra software you mentioned (Wireshark, Process Explorer, both legitimate programs) were added after the initial test to allow me to analyse the infection and had no effect on the running of Synamtec Endpoint Protection.

    I look forward to hearing from you, please let me know if you require further information regarding this case.

    Thanks



  • 2.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 21, 2014 07:37 AM

    You can submit submission file

    http://www.symantec.com/security_response/submitsamples.jsp

    Using Symantec Help (SymHelp) Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team

    https://www-secure.symantec.com/connect/articles/using-symantec-help-symhelp-tool-how-do-we-collect-suspicious-files-and-submit-same-symante



  • 3.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 21, 2014 07:42 AM

    They have already recived the scan log, risk, log, copy of the email, the word, file and the created .exe file.



  • 4.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 21, 2014 08:08 AM

    Hello,

    First you can submit submission file virus total site and check result

    https://www.virustotal.com/

    Here is some good articles

    Eliminating viruses and security risks

    Article:HOWTO27280 | Created: 2010-01-08 | Updated: 2010-01-15 | Article URL http://www.symantec.com/docs/HOWTO27280

    Best Practices for Troubleshooting Viruses on a Network

    Article:TECH122466 | Created: 2010-01-15 | Updated: 2014-01-10 | Article URL http://www.symantec.com/docs/TECH122466


  • 5.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 21, 2014 08:48 AM

    Had already done that during the the analysis phase



  • 6.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 21, 2014 09:17 AM

    What version of SEP are you running? Are you running IPS and firewall as well? See here:
     

    Security Response recommendations for Symantec Endpoint Protection settings



  • 7.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 21, 2014 10:00 AM

    Its version 12.3001.165 which was the current realease at the time, and the company is using an IPS and a firewall but that isn't the issue.



  • 8.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 21, 2014 04:38 PM

    Please clarify:

    Does your SEP 12.1.3001 client have all three features enabled?

    Virus/Spyware

    Proactive Threat Protection

    Network Threat Protection

    ...or is "the company is using an IPS and a firewall..." a third party solution?

    MJD



  • 9.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 21, 2014 05:26 PM

    Hi AK , 

    Please help us understand the issue.

    Whether SEP is detecting it ?

    At what circumstances ? 

    As far as I know SEP has the definitions for the infection that you mentioned , it can be a new varient.

    1). Please submit the files for analysis.

     

    2). Configuring these settings:

    It is possible to choose the desired Auto-Protect behavior by following these steps:

    1.Login to the Symantec Endpoint Protection Manager (SEPM)
    2.Click Policies > Virus and Spyware Protection
    3.Right-click your Virus and Spyware Protection policy and click Edit
    4.Click Auto-Protect > Advanced Scanning and Monitoring...
    5.Select the desired Auto-Protect behavior

     

    In the mean time please educate the users about the best practices, you would not like more computers to get infected. 

    Seems that you have already isolated the infected computer from the network , to be secure , you might want to block the remote IP adresses in your perimeter firewall untill any solutions works out for you .

    Please keep us posted.



  • 10.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 21, 2014 09:26 PM

    Did the PTP is enable or the SONAR? SONAR can help you in detecting malicious behavioral activities before affects the whole system. AV scannning engine is not enough to help you to protect with this kind of viruses. I suggest to install all features of SEP including the email protection.

     

    In case, that it can't be detected by SEP, you can submit the malicious file to Symantec then wait for its rapid release definitions.



  • 11.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 22, 2014 08:24 AM

    All of that has already been done and checked over by the member ofthe technical team hence why the case got escalated further up to the next level of technical support.



  • 12.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 22, 2014 08:42 AM

    Than all yo do it wprk with them at this point. We can give all the suggestions on how to tighten up security for the SEP client but it sounds like you're already passed all that.



  • 13.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 22, 2014 01:25 PM

    The whole problem is the upper security team giving no information what so ever on a very serious flaw in their product that could potentionally under mine a large multiple orginisations around the world and them not doing a thing at all about it.



  • 14.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 22, 2014 01:30 PM

    Do you have an SE you have escalate this case? As it stands now, this is unaaceptable



  • 15.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 23, 2014 03:53 AM

    Mr. Ak, I understand your frustration. Can you advise if within the Network Threat Protection (NTP), user interface and under Network Activity Tool (NAT)(*) did the connection to Ntemegreto.ru\88.198.11.14 was shown (connection details view) ? Also although not necessarily moot, do you have Symantec Network Access Control (SNAC) 12.1 enabled on the SEP 12.1 agent - and SEPM with Host Integrity (HI) policies? I say because the added registry entry can be remediated with SNAC 12.1 and a custom HI policy - amongsts others for incident response. Also if you have Intrusion Prevention (with the latest at the time of the incident) and with or without the NTP firewall enabled, a Security Response, Signature ID (SID) for the IDS/IPS should have caught this - and blocked as making an outbound connection from the SEP 12.1 agent. Please advise to this thread. I cannot speak for Symantec response to you, but we are trying to help you here as SME's Thank you sir.

    * http://www.symantec.com/business/support/index?page=content&id=TECH92950 (“Using Symantec Endpoint Protection 11's Network Activity Tool to Identify Suspicious Processes”)(Although version 11, this is the same in the 12.1 SEP agent)



  • 16.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 05:41 AM

    Sonar is currently enabled that didn't stop it either, luckly it was first opened inside a sealed machine so the it couldn't spead and could be analysied which is how the desination and the registary key entery was found, if it had managed to get out we have netbios blocked at the router firewall but this would of been negated once the infected machine left the network ie the user took their laptop home.



  • 17.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 07:50 AM

    Hi Mr Ak,

    Undetected files should be submitted to Symantec Security Response for examination, after the computer upon which they are found has been isolated.  Some good articles:  

     

    Best Practices for Troubleshooting Viruses on a Network
    http://www.symantec.com/docs/TECH122466

     

    Scanning a file with a competitor's antivirus program detects a virus, but scanning with Symantec Endpoint Protection does not
    http://www.symantec.com/docs/TECH98929

     

    How to Use the Web Submission Process to Submit Suspicious Files
    http://www.symantec.com/docs/TECH102419

     

    It is not recommended to run more than one AV scanner at a time.  If more than one program is attempting to access, scan, and perform actions on a file, then malfunctions can result.

    Should you run more than one antivirus program at the same time?
    http://www.symantec.com/docs/TECH104806
     

    And one final clarification: there's no problem running Wireshark with SEP.

    A brief guide to capturing packet data in Wireshark
    http://www.symantec.com/docs/TECH105811

    Hope this helps!

    Mick

     



  • 18.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 08:01 AM

    Hi Mick, the file was sent in during the troubleshooting phase with the member of the tech support team I was talking too along with diagnostics logs. While scanning wth Synamtec there wasn't any other antivirus running as in the live enviroment. It was a higher up technical member than the one I was communtcating with that was questioning why wireshark was installled as well as sys explorer.



  • 19.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 08:14 AM

    Please add your submission number to this thread- I will take a look.



  • 20.  RE: Endpoint Protection not detecting Malware with signature



  • 21.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 08:45 AM

    That's a URL, not a suspicious file.  &: )

     



  • 22.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 08:55 AM

    The case number is 06207455



  • 23.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 08:58 AM

    Thanks - What is the tracking number of the suspicious file submitted to Symantec for examination?



  • 24.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 09:58 AM

    Hi AK, 

    Please make it clear if the file is getting detected by SEP.

    Is there any specific scan which is detecting it ?

    What does the scan log says ? quarentiened or logged or repaired ?

    whether users accessed the file or made any modifications ?

    What happens when you scan the specific file ?

     

    If SEP is not detecting the virus , please help us in identifying the file by submitting it to the 

    https://submit.symantec.com/websubmit/basic.cgi

    Following which you will receive a tracking number which you can share with us or Ask the Symantec suppiort to track the details.

    Thank You

     



  • 25.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 10:05 AM

    I don't know the tracking number as it was the support member that submitted it



  • 26.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 10:34 AM

    Tech Support cannot submit files on behalf of a customer.  Suspicious files that are uploaded to cases, emailed to Symantec, etc are deleted immediately and not examined.  Using the web submission portal is the one and only way to get a suspicious sample to Security Response for examination.

    How to Use the Web Submission Process to Submit Suspicious Files
    http://www.symantec.com/docs/TECH102419

     

    If possible, do please submit any suspicious files from your case now.

    Many thanks!

    Mick  
     



  • 27.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 11:38 AM

    He copied a zip file of the malicious exe file in a zip file so I assumed that he had done it. I've now submitted the file and the tracking number is 38353135.



  • 28.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 11:59 AM

    following this , you will receive a closure e-mail. Which might contain the definition information.

    Once you receive the definition version , download the Rapid Release definitions and update the local SEP client. running a full system scan will try to repair or remove the threat.

     

    The question is  " If SEP was having the definitions before is it going to make any differance  ? "

    just clicked ? Will be interested to know the result. 



  • 29.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 12:52 PM

    For the Rapid release use the below mentioned URL :

    http://www.symantec.com/security_response/definitions/download/detail.jsp?gid=rr



  • 30.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 24, 2014 01:15 PM

    Many thanks, Mr. Ak.  I have asked Security Response to examine #38353135 as a priority.  I will update this thread when their analysis is complete.



  • 31.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 25, 2014 02:52 AM

    Good news- Security Response have completed their analysis.  The submission is confirmed to be Trojan.Mdropper.  It extracts another file, WkPmyhVE.exe, which is a Trojan.Zbot variant.

    Protection against both is included in Rapid Release definitions (sequence 152441, March 24 2014 rev 35 or higher).  These are available now: ftp://ftp.symantec.com/public/english_us_canada/antivirus_definitions/norton_antivirus/rapidrelease/

    With thanks and best regards,

    Mick

     



  • 32.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 25, 2014 09:24 PM

    Hi,

    I think your problem is related on this blog..

    Zero-Day Vulnerability Discovered in Microsoft Word

    https://www-secure.symantec.com/connect/blogs/zero-day-vulnerability-discovered-microsoft-word.

     

    On the blog, microsoft already have a fix on the issue..

     

     

    Regards,

    JM

     

     



  • 33.  RE: Endpoint Protection not detecting Malware with signature

    Posted Mar 26, 2014 02:29 AM

    Hi Mr. Ak.

    Just a status check?  The thread is still marked "needs solution."

    All the best,

    Mick