Skip to main content
ebuild
New Member
March 19, 2016
Solved

Best appraoch to test Antivirus Profile; Locky malware case

  • March 19, 2016
  • 1 reply
  • 7468 views

In our Fortigate 100D we enabled IMPA and POP3 profiles, but need to make sure the antivirus is working as expected, for that how one can run an attack test ?

    Best answer by netmin

    To just test the AV profile setup for general functionality, the standard EICAR anti-virus test files could be used: http://www.eicar.org/85-0-Download.html - they should be detected/blocked by every AV software, so you might need to temporarily disable your local AV client, when trying to send an email containing it.

     

    btw, here's another interesting site: http://metal.fortiguard.com/

    1 reply

    ede_pfau
    SuperUser
    SuperUser
    March 20, 2016

    AFAIK there is no check for 'locky' in AV. The signature is included in Application Control, 'Botnet' category.

     

    And no, I don't know of any reliable source / web site where you could catch a locky trojan -

    netmin
    netminAnswer
    New Member
    March 20, 2016

    To just test the AV profile setup for general functionality, the standard EICAR anti-virus test files could be used: http://www.eicar.org/85-0-Download.html - they should be detected/blocked by every AV software, so you might need to temporarily disable your local AV client, when trying to send an email containing it.

     

    btw, here's another interesting site: http://metal.fortiguard.com/