First of all ensure that your URL Filtering policies is blocking all "bad" categories such as Adware, high risk, critical, risk, malware, among others. This is not a silver bullet since URLs should be categorized as such. You can create a rule to drop all uncategorized traffic and set URL Filtering to do a fail close approach to the packets but most of the time this is cumbersome for end users.
Second: Your Firewall antivirus engine will not do anything if malware is being downloaded via HTTPS, you will need to configure Outbound HTTPS Inspection on your firewall.
Last, put that host in quarantine and perform a proper malware removal, it's not really a good practice to let your firewall handle all the incident handling, specially if the host is already compromise.
Hope it helps
____________
https://www.linkedin.com/in/federicomeiners/