SOLUTION MODULES | PATTERN BRANCH | RELEASE DATE | DETECTION/POLICY/RULES |
---|---|---|---|
PREDICTIVE LEARNING (TRENDX) | In-the-Cloud | In-the-Cloud | TROJ.Win32.TRX.XXPE50FFF032 |
FILE DETECTION (VSAPI/SMART SCAN) AND ADVANCED THREAT SCAN ENGINE (ATSE) | 15.433.00 | 15/10/2019 | Ransom.Win32.BITPAYMER.TGACAM TROJ_GEN.R011C0WGA19 TROJ_GEN.R007C0PAG20 TROJ_GEN.R03FC0DFH19 TROJ_GEN.R011C0PFO19 TROJ_GEN.R011C0PFI19 TROJ_GEN.R011C0RFF19 Ransom.Win32.ICRYPT.AG TROJ_GEN.R011C0RFE19 TROJ_GEN.R011C0WF719 TROJ_GEN.R011C0WF219 Backdoor.Win32.DRIDEX.THEBCAI |
BEHAVIORAL MONITORING (AEGIS) | RAN4052T, MALWARE BEHAVIOR BLOCKING | ||
SANDBOX SOLUTION | VAN_RANSOMWARE.UMXX | ||
DEEP SECURITY | 1007596 - Identified Suspicious File Extension Rename Activity Over Network Share | ||
1007598 - Identified Suspicious Rename Activity Over Network Share | |||
TIPPINGPOINT | 36513 TCP FBitPaymer Ransomware - Payload Transfer Detection |
Actions to Take:
Make sure that your product software is patched and up to date. Please refer to these KB articles:
- SECURITY BULLETIN: Directory Traversal Vulnerability in Trend Micro Apex One, OfficeScan and Worry-Free Business Security
- SECURITY BULLETIN: Multiple Critical Vulnerabilities in Trend Micro Apex One and OfficeScan
Trend Micro Endpoint Product using best practice should be able to detect and clean this malware. Refer to the KB article, Best practices in configuring OfficeScan (OSCE) for malware protection, for more information.
For machines that are isolated or without agents installed, you can use ATTK online Clean Tool to clean the infected machine.