Riskware/Agent

description-logoAnalysis


Riskware/Agent is a very generic detection for a set of executables that harbors high risk behaviors.
These are mostly composed of Installers, BHO's, Stand Alone applications, or Utilities itself that could be used to deliver unwanted components into an unsuspecting users.
Some of these applications are big files above 100MB and some are delivered in foreign languages.
Below are some of the sample effects:


    • Figure 1: BHO Installation.


    • Figure 2: Remote utility.


    • Figure 3: Another BHO.


    • Figure 4: Downloader Installation.


recommended-action-logoRecommended Action

  • Make sure that your FortiGate/FortiClient system is using the latest AV database.
  • Quarantine/delete files that are detected and replace infected files with clean backup copies.

Telemetry logoTelemetry

Detection Availability

FortiGate black-background-switch-icon
FortiClient black-background-switch-icon
FortiAPS black-background-switch-icon
FortiAPU black-background-switch-icon
FortiMail black-background-switch-icon
FortiSandbox black-background-switch-icon
FortiWeb black-background-switch-icon
Web Application Firewall black-background-switch-icon
FortiIsolator black-background-switch-icon
FortiDeceptor black-background-switch-icon
FortiEDR black-background-switch-icon

Version Updates

Date Version Detail
2023-11-27 91.09205
2023-11-27 91.09204
2023-11-27 91.09201
2023-11-27 91.09200
2023-11-27 91.09197
2023-11-27 91.09194
2023-11-27 91.09192
2023-11-26 91.09190
2023-11-26 91.09181
2023-11-26 91.09170