We are getting alerts from various network PCs alerting to Virus/Worm detected: JS/Moat.2081C96D!tr with Destination IPs directing to various website hosts, like Digital Ocean or GoDaddy.
MOAT.js is a legitimate javascript API but the email alerts are so cryptic that it's tough to tell if these alerts are legitimate activity, like the local Java installation attempting to update, or if they're actually a Worm attempting to communicate out.
Has anyone else seen these alerts and perhaps have more information on "Virus/Worm detected: JS/Moat.2081C96D!tr" since there isn't much of anything in any virus definition database online discussing details of it.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Also seeing this. ESET does not pick this up after doing an on-demand scan.
Also seeing this. ESET does not pick this up after doing an on-demand scan.
Yeah, same here. We're running ESET and all scans come back clean, which is why I'm wondering if this is a false positive from our Fortigate.
We are runnignj fortigate 310 B FW v5.0,build0271 We are also having same issue.Atleast 5 users got blocked from web today and When i ran Reports in Fortianalyser for them below threat name are listed:
JS/Moat.2081C96D!tr 3
JS/Moat.A9BA34BC!tr 3
JS/Redirector.CN!tr
I have the same issue, a number of various websites that were ok untill 2 days ago are now blocked by fortigate because of the same reason: JS/Moat.A9BA34BC!tr.
The interesting fact is, when i did a first search on google like a couple of hours ago on this Moat js, the first and single result was donald trumps' website :)). Now his website is outranked by this thread. I find that very suspicious.
Anyhow, could it be a false positive ?
Something worth checking at your locations.
I think this might be related to the "Suppress sponsor offers when installing or updating java" checkbox not being checked in the Control Panel applet.
I noticed that one thing the three systems I've gotten this from so far had in common is that I had forgotten to check that checkbox on them.
So my thought it that the Fortigate is, rightly so, stopping the Ask.com and/Amazon Browser plug-in crapware from getting through and that's the alert it sends.
I have also been getting an excessive amount of these alerts starting 4 weeks ago. I put in a ticket with fortinet to have them confirm if this was a false positive and that got me know real answers.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.