Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Muhammad_Umer
New Contributor

Virus/Worm Riskware/CoinHive

Dear Team

I am facing issue regarding to virus which is sending me logs with below given details

1)

Message meets Alert condition

 

Virus/Worm detected: Riskware/CoinHive Protocol: HTTP Source IP: xxxxxxxxx

Destination IP: xxxxxxxxxx Email Address From: Email Address To: VIRUS REFERENCE URL: [link]http://www.fortinet.com/ve?vn=Riskware%2FCoinHive[/link] date=2018-10-05 time=10:49:04 devname=xxxxxxx devid=xxxxxxxx logid=xxxxxxxx type=utm subtype=virus eventtype=infected level=warning vd=root msg="File is infected." action=blocked service="HTTP" sessionid=4850262 srcip=xxxxxxxx dstip=xxxxxxxx srcport=62481 dstport=80 srcintf="internal" dstintf="wan1" policyid=3 proto=6 direction=incoming quarskip=No-skip virus="Riskware/CoinHive" dtype="Virus" ref="http://www.fortinet.com/ve?vn=Riskware%2FCoinHive" virusid=4294967295 url=xxxxxxxxxxx profile="AV Policy For KHI" user="" analyticssubmit=false crscore=50 crlevel=critical

 

2) 

Message meets Alert condition Virus/Worm detected: Riskware/CoinHive Protocol: HTTP Source IP: xxxxxxxx Destination IP: xxxxxxxxxx Email Address From: Email Address To: VIRUS REFERENCE URL: [link]http://www.fortinet.com/ve?vn=Riskware%2FCoinHive[/link] date=2018-10-05 time=10:45:12 devname=xxxxxxxxxxx devid=xxxxxxxxxxx logid=xxxxxxxx type=utm subtype=virus eventtype=infected level=warning vd=root msg="File is infected." action=blocked service="HTTP" sessionid=4839154 srcip=xxxxxxxxx dstip=xxxxxxxxxx srcport=54251 dstport=80 srcintf="internal" dstintf="wan1" policyid=3 proto=6 direction=incoming filename="css" quarskip=No-skip virus="Riskware/CoinHive" dtype="Virus" ref="http://www.fortinet.com/ve?vn=Riskware%2FCoinHive" virusid=4294967295 url="http://fonts.googleapis.com/css?family=Open+Sans:400,300,600,700" profile="AV Policy For KHI" user="" agent="Chrome/69.0.3497.100" analyticssubmit=false crscore=50 crlevel=critical

 

Number of emails are being generated all related to Riskware/CoinHive, even if i open url http://www.espncricinfo.com/ it gives an email alert.

 

Please guide me in this issue.

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors