Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MikeRigsby
New Contributor

Virus/Worm detected: JS/Moat.2081C96D!tr hits on FortiGate 200D FW: v5.2.2, build642

We are getting alerts from various network PCs alerting to Virus/Worm detected: JS/Moat.2081C96D!tr with Destination IPs directing to various website hosts, like Digital Ocean or GoDaddy.

 

MOAT.js is a legitimate javascript API but the email alerts are so cryptic that it's tough to tell if these alerts are legitimate activity, like the local Java installation attempting to update, or if they're actually a Worm attempting to communicate out.

 

Has anyone else seen these alerts and perhaps have more information on "Virus/Worm detected: JS/Moat.2081C96D!tr" since there isn't much of anything in any virus definition database online discussing details of it.

1 Solution
DCTI
New Contributor II

Also seeing this.  ESET does not pick this up after doing an on-demand scan.

View solution in original post

6 REPLIES 6
DCTI
New Contributor II

Also seeing this.  ESET does not pick this up after doing an on-demand scan.

MikeRigsby

Yeah, same here. We're running ESET and all scans come back clean, which is why I'm wondering if this is a false positive from our Fortigate.

akaur786

We are runnignj fortigate 310 B FW  v5.0,build0271 We are also having same issue.Atleast 5 users got blocked from web today and When i ran Reports in Fortianalyser for them below threat name are listed:

 

JS/Moat.2081C96D!tr 3

JS/Moat.A9BA34BC!tr 3

JS/Redirector.CN!tr

Dripci

I have the same issue, a number of various websites that were ok untill 2 days ago are now blocked by fortigate because of the same reason: JS/Moat.A9BA34BC!tr.

The interesting fact is, when i did a first search on google like a couple of hours ago on this Moat js, the first and single result was donald trumps' website :)). Now his website is outranked by this thread. I find that very suspicious.

Anyhow, could it be a false positive ?

MikeRigsby

Something worth checking at your locations.

 

I think this might be related to the "Suppress sponsor offers when installing or updating java" checkbox not being checked in the Control Panel applet.

 

I noticed that one thing the three systems I've gotten this from so far had in common is that I had forgotten to check that checkbox on them.

 

So my thought it that the Fortigate is, rightly so, stopping the Ask.com and/Amazon Browser plug-in crapware from getting through and that's the alert it sends.

stayready40

I have also been getting an excessive amount of these alerts starting 4 weeks ago. I put in a ticket with fortinet to have them confirm if this was a false positive and that got me know real answers.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors