FortiMail
FortiMail provides advanced, multi-layer protection against the full spectrum of email-borne threats
jandrysek
Staff
Staff
Article Id 336351
Description This article describes how to block email with a Bitcoin wallet in the email body.
Scope FortiMail.
Solution

Navigate to the Content Profile and in the Content Monitor and Filtering create a new Dictionary entry by selecting ‘+ New’.

 

Screenshot 2024-08-26 at 9.05.07.png

 

In the Content Monitor Profile window, select one of the currently created dictionaries or create a new one by selecting the '+' button.

 

Screenshot 2024-08-26 at 11.10.33.png

 

In the Dictionary Profile scroll down to Dictionary Entries and create a new entry. 

 

Screenshot 2024-08-26 at 11.15.48.png

 

To the Pattern cell paste the string:

 

 \b(bc(0([ac-hj-np-z02-9]{39}|[ac-hj-np-z02-9]{59})|1[ac-hj-np-z02-9]{8,87})|[13][a-km-zA-HJ-NP-Z1-9]{25,35})\b

 

And enable to search in the email body only.

 

Screenshot 2024-08-26 at 11.19.18.png

 

Select 'Create'. 

 

Now a Bitcoin wallet in the email body will be detected and the selected action in the Content Monitor Profile will be taken. If the default action is selected, the Content Profile action will be in charge.