Riskware/NetFilter

description-logoAnalysis



Riskware/NetFilter is a highly generic detection for a set of Riskware samples. Most of these samples are unwanted application and may carry undesirable components during installation. Since this is a generic detection, malware that are detected as Riskware/NetFilter may have varying behaviour.

  • Below are some samples of illustration we observed during the tests of several samples:

    • Figure 1: Installer.


    • Figure 2: Installer.


    • Figure 3: Installer.


    • Figure 4: Application.


    • Figure 5: Installer.


    • Figure 6: Installer.




recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
FortiClient
FortiAPS
FortiAPU
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2024-04-17 92.03457
2024-04-15 92.03397
2024-04-13 92.03352
2024-04-12 92.03311
2024-04-12 92.03307
2024-04-11 92.03270
2024-04-08 92.03191
2024-04-07 92.03163
2024-04-06 92.03141
2024-04-06 92.03135