Riskware/Agent

description-logoAnalysis


Riskware/Agent is a very generic detection for a set of executables that harbors high risk behaviors.
These are mostly composed of Installers, BHO's, Stand Alone applications, or Utilities itself that could be used to deliver unwanted components into an unsuspecting users.
Some of these applications are big files above 100MB and some are delivered in foreign languages.
Below are some of the sample effects:


    • Figure 1: BHO Installation.


    • Figure 2: Remote utility.


    • Figure 3: Another BHO.


    • Figure 4: Downloader Installation.


recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate
FortiClient
FortiAPS
FortiAPU
FortiMail
FortiSandbox
FortiWeb
Web Application Firewall
FortiIsolator
FortiDeceptor
FortiEDR

Version Updates

Date Version Detail
2024-04-19 92.03517
2024-04-19 92.03514
2024-04-19 92.03506
2024-04-19 92.03504
2024-04-18 92.03501
2024-04-18 92.03500
2024-04-18 92.03497
2024-04-18 92.03495
2024-04-18 92.03494
2024-04-18 92.03491