Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
david_ekstrom
New Contributor II

Fortinet report blocked - from malicious sender?

Anyone ever see a Fortinet daily report get blocked due to malicious URL?  I get daily reports from our fortigates and this one was blocked.  This is what mimecast shows in the log.  Strange is that same report, on the same day went to our helpdesk with no issue and from a totally different IP.  I looked back a couple days and saw the same thing a few days ago.  Did an SPF check and that 89[.]248 address is not in Fortinet's SPF record.

 

URL
89[.]248[.]163[.]161
Category
Malware
Message Section
Body
Log Type
User Click

Action
Block
Policy
Default Inbound URL Protect Definition
Admin Override
N/A
User Override
None
User Awareness
N/A

Scan Result
 Malicious
Scan Details
URL Reputation Scan
Type:
Malware
Original URL:
ORIGINAL:[https://]89[.]248[.]163[.]161 (Blocked as MALWARE)

From
noreply@forticloud.com
To
david.ekstrom@mfbonline.com
Subject
FG201ETK19906260_360 Degree Activities Report_daily_2023-07-04_2023-07-05_root_1688555134808
Route
Inbound
Sending IP
208[.]91[.]113[.]148
Date/Time
Wed, 05 Jul 2023 - 08:07:18
2 REPLIES 2
Anthony_E
Community Manager
Community Manager

Hello David,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Debbie_FTNT
Staff
Staff

Hey David,

I double-checked, but I was not able to confirm if the IP range in question belongs to Fortinet/FortiCloud or not. The report name does look legitimate, but the source IP is suspicious indeed. Have you submitted the report to any virus scanners for checking?

If this happens regularly, you could consider a ticket with Fortinet Support to verify if the IP is expected or not (if yes, then it should not be classed as malicious, if not, then it bears further investigating what that report actually is).

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors