Endpoint Protection

 View Only
Expand all | Collapse all

W32/DistTrack

Migration User

Migration UserAug 15, 2012 08:13 PM

Migration User

Migration UserAug 15, 2012 09:47 PM

Migration User

Migration UserAug 16, 2012 07:47 AM

  • 1.  W32/DistTrack

    Posted Aug 15, 2012 07:42 PM

    Mcafee recently released an emergency dat for W32/DistTrack, has Symantec addressed this?



  • 2.  RE: W32/DistTrack

    Posted Aug 15, 2012 07:57 PM

    I would like this information as well.  I see nothing on security response about this.



  • 3.  RE: W32/DistTrack

    Posted Aug 15, 2012 08:13 PM

    Bump



  • 4.  RE: W32/DistTrack

    Posted Aug 15, 2012 08:32 PM

    Does anyone have any further information on this threat type as there is nothing in the NAI files for this at present.

     

    Cheers

     

    Fal



  • 5.  RE: W32/DistTrack

    Posted Aug 15, 2012 08:35 PM


  • 6.  RE: W32/DistTrack

    Posted Aug 15, 2012 08:39 PM

    The problem is the naming convention is different so Symantec may have something for it, just under a different name.



  • 7.  RE: W32/DistTrack

    Posted Aug 15, 2012 08:44 PM

    Brian, that's what the "Also Known As" in the write-up is for.



  • 8.  RE: W32/DistTrack

    Posted Aug 15, 2012 08:56 PM

    hi,

    Yesterday Symantec has added detection for a new worm that collects system information and steals user credentials.

    https://www-secure.symantec.com/connect/forums/w32gauss



  • 9.  RE: W32/DistTrack

    Posted Aug 15, 2012 09:47 PM

    I strongly believe that is not the same.



  • 10.  RE: W32/DistTrack

    Posted Aug 16, 2012 04:30 AM
    I suspect that this virus yesterday attack on Saudi Aramco. Deos any one know what this virus name in Symantec virus data base ?. Thanks in advance.


  • 11.  RE: W32/DistTrack

    Posted Aug 16, 2012 04:35 AM
    This virus wipe out complete hard disk within 5 minute. Can you please check what this virus name in symantec.


  • 12.  RE: W32/DistTrack

    Posted Aug 16, 2012 06:32 AM

     

    Symantec Security Response has posted a public writeup on W32.DistTrack:

    http://www.symantec.com/security_response/writeup.jsp?docid=2012-081608-0202-99&om_rssid=sr-mixed30days



  • 13.  RE: W32/DistTrack

    Posted Aug 16, 2012 06:44 AM

    The right way to proceed is to submit a sample. Since the naming conventions are different you cannot know what this is unless it is something huge like downadup etc.

    How to Use the Web Submission Process to Submit Suspicious Files

    http://www.symantec.com/business/support/index?page=content&id=TECH102419

     

    Submit the sample and symantec will give you the details.

    You can also use

    http://www.threatexpert.com/submit.aspx

     



  • 14.  RE: W32/DistTrack
    Best Answer

    Broadcom Employee
    Posted Aug 16, 2012 07:39 AM

    Hi,

    Symantec Security Response has analyzed the related sample(s) and detection is added as W32.DistTrack.  Rapid Release definitions sequence#: 136853 & above will include the detection.

    Symantec Security Response has posted a public writeup on W32.DistTrack:

    http://www.symantec.com/security_response/writeup.jsp?docid=2012-081608-0202-99&om_rssid=sr-mixed30days

    The write-up will be updated as necessary.



  • 15.  RE: W32/DistTrack

    Posted Aug 16, 2012 07:47 AM
    even Downadup got alias of Kido and Conficker :)


  • 16.  RE: W32/DistTrack

    Posted Aug 16, 2012 12:59 PM

    A blog has been published by Symantec Security Response on this targeted attack.

    http://www.symantec.com/connect/blogs/shamoon-attacks

     



  • 17.  RE: W32/DistTrack

    Posted Aug 16, 2012 01:02 PM
    Hello Folks, 
    
    The offical Symantec writeup for this threat can be found here.
    
    http://www.symantec.com/security_response/writeup.jsp?docid=2012-081608-0202-99&om_rssid=sr-mixed30days

     

    Blog on the natuer of the targted attack can be found here

    http://www.symantec.com/connect/blogs/shamoon-attacks

     

     



  • 18.  RE: W32/DistTrack

    Posted Aug 17, 2012 12:32 PM

    "Thumbs up" to teh advice, above.

    Note that this threat spreads by network shares.  It is a crucial best practice that access to network shares be locked down / password protected and access limited to those who need it.   



  • 19.  RE: W32/DistTrack

    Posted Aug 22, 2012 02:18 PM

    Thank you, Symantec for a quick turnaround on this.