Endpoint Protection

 View Only

  • 1.  Help I can't removed this Coinminer Activity 2 attack blocked

    Posted May 05, 2024 08:42 AM

    [SID: 30482] System Infected: Coinminer Activity 2 attack blocked. Traffic has been blocked for this application: C:\WINDOWS\SYSTEM32\SVCHOST.EXE

    Intensive Protection level: N/A

    I reverted from a backup from 2022 spent almost 20 hours getting this server back online, and today I see this again. I'm so frustrated with this.

    We have had endpoint for over 10 years.  My scans will not detect this, but this constantly shows up in the client logs this is the only way i detect it, and sometime a pop up when this is blocked  This does not show up in scans.   I highly doubt this was in my 2022 backup.



  • 2.  RE: Help I can't removed this Coinminer Activity 2 attack blocked

    Broadcom Employee
    Posted May 05, 2024 07:41 PM

    This is a Network traffic detection by Intrusion Prevention. It's not something on the physical server.



    ------------------------------
    John Owens
    Strategic Support Engineer | Enterprise Security Group
    Broadcom Software
    ------------------------------



  • 3.  RE: Help I can't removed this Coinminer Activity 2 attack blocked

    Posted May 06, 2024 06:54 AM

    Can you please elaborate.  This is the ONLY server on this same network showing this.  Users connected via citirx are seeing this Symantec popup via their terminal services. 

    Upon reading about this, I'm led to believe something is on this server causing this, but it's difficult to detect and remove. 

    No other computers on the network from what I can see are detecting this.  I can only see this in the client logs.




  • 4.  RE: Help I can't removed this Coinminer Activity 2 attack blocked

    Broadcom Employee
    Posted May 06, 2024 10:05 AM

    Please open a Support Case to assist you with this one.



    ------------------------------
    John Owens
    Strategic Support Engineer | Enterprise Security Group
    Broadcom Software
    ------------------------------



  • 5.  RE: Help I can't removed this Coinminer Activity 2 attack blocked

    Posted May 06, 2024 12:59 PM

    Ok John but based on what you mentioned before is this warning on the machine which the client log / security is showing this? 




  • 6.  RE: Help I can't removed this Coinminer Activity 2 attack blocked

    Broadcom Employee
    Posted May 06, 2024 01:02 PM

    The Intrusion Prevention technology detects network traffic to or from this device that matches the attack signature ID [SID: 30482].

    If you look at the full log you should be able to tell if it is Inbound or Outbound traffic.




    ------------------------------
    John Owens
    Strategic Support Engineer | Enterprise Security Group
    Broadcom Software
    ------------------------------



  • 7.  RE: Help I can't removed this Coinminer Activity 2 attack blocked

    Posted May 06, 2024 04:27 PM

    Here is a snapshot I dont' see incoming our outgoing but I'm assuming it's outgoing from my 192.168.1.4




  • 8.  RE: Help I can't removed this Coinminer Activity 2 attack blocked

    Broadcom Employee
    Posted May 06, 2024 04:33 PM

    Hello,

    From that screenshot, you can see it is Incoming from the following IPs.

    152.32.205.193
    101.36.108.175
    101.36.97.74

    Our Intrusion Prevention System (IPS) is a crucial component of our network security. It is designed to detect and prevent network traffic that matches known attack signatures. In this case, it has detected network traffic from the following IPs to your local system that matches the IPS Signature Attack ID.

    Are you familiar with those IPs?

    There is nothing directly on your system directly. It is the network traffic coming from these IPs to your local system.

    Thanks,



    ------------------------------
    John Owens
    Strategic Support Engineer | Enterprise Security Group
    Broadcom Software
    ------------------------------



  • 9.  RE: Help I can't removed this Coinminer Activity 2 attack blocked

    Posted May 06, 2024 04:39 PM

    no these IP's which are constantly changing I have no idea were they come form as we are on a 192.168.1 network here.

    152.32.205.193
    101.36.108.175
    101.36.97.74
     

    incoming from WAN? 




  • 10.  RE: Help I can't removed this Coinminer Activity 2 attack blocked

    Broadcom Employee
    Posted May 06, 2024 04:41 PM

    You would have to look up those IPs to see what they are. Maybe from your ISP?

    In any case, SEP is doing its job of blocking these attempted attacks.



    ------------------------------
    John Owens
    Strategic Support Engineer | Enterprise Security Group
    Broadcom Software
    ------------------------------