Advice Request Infected website or False Positive from Fortinet?

Please provide comments and solutions that are helpful to the author of this topic.

Status
Not open for further replies.

128BPM

Level 2
Thread author
Verified
Feb 21, 2018
90
Hi,

Every day I visit this page without problems, however this morning was blocked by Fortinet. Why?
Code:
http://www.amen-amen.net/RV1960/

I checked it with VT and the result is clean. But VT shows this file: c99f26061658e9461804e2deeed87823149ff0c7f847859b43c55a15255dca76

Is a little suspicious :cautious:


Screenshot_2018-11-15 Web Filter Violation.jpg
 
Last edited by a moderator:
  • Like
Reactions: oldschool
F

ForgottenSeer 58943

If Fortinet alerts, you should be concerned.

Primarily because Fortinet doesn't auto-classify, there are a couple of hundred engineers who sit around working on the classification. Also remember, FortiGuard, the TAC's primary feed also takes in from other sources ranging from FortiSandbox, IPS hits and other channels so it will often hit much sooner than other web classification services.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top