Hello,
Would have to see your rule but you can block traffic from teamveiwer.exe and teamviewer_service.exe
Those are the two that need to be blocked. It goes by exe name so it doesn't matter if hash changes or not (don't use the hash).
You could also try blocking peer to peer connection with below steps.
- Login to the Symantec Endpoint Protection Manager (SEPM)
- Click Policies
- Click Intrusion Prevention
- Right-click your IPS policy and click Edit
- Click Exceptions underneath Windows Settings
- Click Add...
- Click Signature Name two times to sort the IPS signatures in ascending order
- Select all signatures which start with: Audit: P2P
- Click Next
- Set Action to Block
- Set Log to Log the traffic
- Click OK
- Click OK
You should check this article for more details: How to block Peer to Peer Applications (P2P) using Symantec Endpoint Protection 12.1
http://www.symantec.com/docs/TECH122597
Hope that helps!!