- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-25-2013 01:34 PM
Hello all. I have a PA-5020 operating as our Layer 3 router between all of our VLAN's. For the past month or so the ACC on the Palo shows SMB: User Password Brute-force Attempt (ID:40004) as the #1 entry in Threat Prevention section. The attacker is our Antivirus (Kaspersky) Administration Server on VLAN 199 and the victim is a kiosk PC that isn't on our domain, just our network VLAN 202. There are about 10 other kiosks and they don't get any threats from the AV server. These kiosks are managed by another company and locked down pretty well. I've tried using netstat /oan and keep running it but never see the traffic (maybe the firewall on the kiosk terminates the traffic too quickly for me to see any SYN_WAIT, etc.). I do see a LOT of 445 connections off and on to other devices on our network, just none to that IP address.
I've scanned the server with the latest Kaspersky sigs and no malware is found. I'm stumped as to what this may be, should I start a packet capture and see if that yields any clues?
04-25-2013 01:48 PM
Well, if you feel this could be a false positive, and the FW is incorrectly recognizing traffic as Brute Force, you can create an IP exception rule in your vulnerability profile. You can to the profile, then go to Exceptions, find the vulnerability number, and edit it, to ignore the signature when it sees traffic destined for that PC in VLAN 202.
04-26-2013 12:26 AM
Suggest updating the AV DB and App and Threat DB to the latest version ,if the issue continues .
Open a support case providing following explained in the following document:
05-30-2013 09:03 AM
Thanks for the advise. Just wanted to follow up on this, it looked like Kaspersky server was still trying to run some job against this IP address thinking it was a domain computer holding the IP address. We made a dummy reservation in DHCP and forced the kiosk (non-domain) computer to get a new IP address and the threat stopped, it didn't follow the IP address.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!