Advice Request Infected website or False Positive from Fortinet?

Please provide comments and solutions that are helpful to the author of this topic.
Status
Not open for further replies.

128BPM

Level 2
Thread author
Verified
Feb 21, 2018
90
176
65
Utopia
Hi,

Every day I visit this page without problems, however this morning was blocked by Fortinet. Why?
Code:
http://www.amen-amen.net/RV1960/

I checked it with VT and the result is clean. But VT shows this file: c99f26061658e9461804e2deeed87823149ff0c7f847859b43c55a15255dca76

Is a little suspicious :cautious:


Screenshot_2018-11-15 Web Filter Violation.jpg
 
Last edited by a moderator:
  • Like
Reactions: oldschool
If Fortinet alerts, you should be concerned.

Primarily because Fortinet doesn't auto-classify, there are a couple of hundred engineers who sit around working on the classification. Also remember, FortiGuard, the TAC's primary feed also takes in from other sources ranging from FortiSandbox, IPS hits and other channels so it will often hit much sooner than other web classification services.
 
Status
Not open for further replies.