Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

JonathanTorian_FTNT

Protection against CryptoWall 4.0

Hi FortiGuard Fuse Members,

I have a customer who recently reached out to me to inquire about the latest variant of CryptoWall (4.0).  I know we recently released an article around our detection with CryptoWall 3.0, but is there any updated information regarding CryptoWall 4.0?

Here is some literature I found on the subject:

http://www.fixedbyvonnie.com/2015/11/cryptolocker-new-and-improved-cryptowall-4-0/#.VkOTPfmrR1s

http://blog.varonis.com/beware-cryptowall-4-0-is-on-the-loose/

My customer is currently protected by a FortiGate (not inspecting SSL), FortiMail and FortiSandbox.  Is there any reassurance I can give him on our abilities to detect and mitigate this threat?

Thanks!

1 Solution
jrockett_FTNT

They can set app control to monitor and block I2P (Similar to Tor) traffic which is used by the malware as an overlay network.

JR

View solution in original post

1 REPLY 1
jrockett_FTNT

They can set app control to monitor and block I2P (Similar to Tor) traffic which is used by the malware as an overlay network.

JR