Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ebuild
New Contributor

Best appraoch to test Antivirus Profile; Locky malware case

In our Fortigate 100D we enabled IMPA and POP3 profiles, but need to make sure the antivirus is working as expected, for that how one can run an attack test ?

2 Solutions
ede_pfau
SuperUser
SuperUser

AFAIK there is no check for 'locky' in AV. The signature is included in Application Control, 'Botnet' category.

 

And no, I don't know of any reliable source / web site where you could catch a locky trojan -


Ede

"Kernel panic: Aiee, killing interrupt handler!"

View solution in original post

Ede"Kernel panic: Aiee, killing interrupt handler!"
netmin

To just test the AV profile setup for general functionality, the standard EICAR anti-virus test files could be used: http://www.eicar.org/85-0-Download.html - they should be detected/blocked by every AV software, so you might need to temporarily disable your local AV client, when trying to send an email containing it.

 

btw, here's another interesting site: http://metal.fortiguard.com/

View solution in original post

2 REPLIES 2
ede_pfau
SuperUser
SuperUser

AFAIK there is no check for 'locky' in AV. The signature is included in Application Control, 'Botnet' category.

 

And no, I don't know of any reliable source / web site where you could catch a locky trojan -


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
netmin

To just test the AV profile setup for general functionality, the standard EICAR anti-virus test files could be used: http://www.eicar.org/85-0-Download.html - they should be detected/blocked by every AV software, so you might need to temporarily disable your local AV client, when trying to send an email containing it.

 

btw, here's another interesting site: http://metal.fortiguard.com/

Labels
Top Kudoed Authors