Question
Compromised site and fake tech support not blocked y fortigate
Hi all,
We often see some of our users reporting the fake tech support scam.
Exemple of a compromised site here : page2rss.com
While the scam is hosted on cloud, and url may change, it looks like there is always the same url pattern :
"randomfirstpart".cloudfront.net/xxxch75xx88/"
(example : https://d378glj94x3qmi.cloudfront.net/xxxch75xx88/index.html)
1. How can i block url patterns with xxxchxx88 ?
2. Why isnt my fortigate able to protect me against that threat ? (it's always the local antivirus that does the job)
ty
