Endpoint Protection

 View Only
  • 1.  [SID: 28803] System Infected: Infostealer.Chabibase Activity 2 attack blocked.

    Posted Mar 16, 2016 10:38 PM

    [SID: 28803] System Infected: Infostealer.Chabibase Activity 2 attack blocked. Traffic has been blocked for this application:

     

    This is the Even description from NTP log. Anyone came across this Malware infection.



  • 2.  RE: [SID: 28803] System Infected: Infostealer.Chabibase Activity 2 attack blocked.

    Posted Mar 17, 2016 11:38 AM

    What executable is showing, if any? Did this user attempt to access a malicious URL. You need to view this log in the SEPM for further detail.



  • 3.  RE: [SID: 28803] System Infected: Infostealer.Chabibase Activity 2 attack blocked.

    Posted Mar 18, 2016 07:29 AM

    Hi hackgeek,

    I recomend investigating the computer which generated this IPS event.  It is likely infected with malware.

    Infostealer.Chabibase
    https://www.symantec.com/security_response/writeup.jsp?docid=2015-033114-4138-99

    This may help:

    Using Today's SymDiag to Combat Today's Threats
    https://www-secure.symantec.com/connect/articles/using-todays-symhelp-combat-todays-threats

    Please do keep this thread up-to-date with your progress!

    With thanks and bets regards,

    Mick