This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Mail scanner does not detect incoming Malware.

I recieved a phishing email with an attachment, the mail was classed as spam and quarantined.

I released the mail from quarantine and once I was sure it was a phising email I forwarded it to the security department at the organisation it perported to come from.

I immeadiately got a bounce from my UTM that the mail had a malware attachment !!

"Your message to the following recipients was quarantined:

<phishing@hmrc.gsi.gov.uk>, quarantine reason: Malware (Troj/DocDl-HKN)

Please contact your IT administrator for further assistance."


This means that the scanner missed it on the way in !
I have no whitelisting to prevent any antivirus scanning and use dual scan.

UTM v9.411-3

This would appear as a rather severe bug

Jeff


This thread was automatically locked due to age.
Parents
  • Hi,

    what you haven't told us is your incoming mail setup.

    Do you use imap because the UTM doesn't scan imap currently only smtp and pop3.

    The malware would have been caught on the wayout by the smtp scanning.

    Please put ina feature request for imap scanning.

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Sorry,

    Came in via SMTP Proxy

    Was marked as spam, when I released it and forwarded I got the message.

     

    Log:

    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:50:51 firewall exim-in[7784]: 2017-02-15 13:50:51 H=(hmrcg0v.co.uk) [146.20.65.136]:54525 Warning: jimbojones.com profile excludes greylisting: Skipping greylisting for this message
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:50:51 firewall exim-in[7784]: 2017-02-15 13:50:51 H=(hmrcg0v.co.uk) [146.20.65.136]:54525 Warning: jimbojones.com profile excludes SANDBOX scan
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:50:52 firewall exim-in[7784]: 2017-02-15 13:50:52 [146.20.65.136] F=<service-jimbo=jimbojones.com@hmrcg0v.co.uk> R=<jimbo@jimbojones.com> Verifying recipient address with callout
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:51:13 firewall exim-in[7784]: 2017-02-15 13:51:13 1cdzyu-00021Y-1J DKIM: d=hmrcg0v.co.uk s=key c=relaxed/relaxed a=rsa-sha1 [invalid - public key record (currently?) unavailable]
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:51:14 firewall exim-in[7784]: 2017-02-15 13:51:14 1cdzyu-00021Y-1J <= service-jimbo=jimbojones.com@hmrcg0v.co.uk H=(hmrcg0v.co.uk) [146.20.65.136]:54525 P=esmtp S=146907 id=0.0.0.0.1D287917DA14CAC.1AC5FEA0@hmrcg0v.co.uk
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:51:14 firewall exim-in[7784]: 2017-02-15 13:51:14 SMTP connection from (hmrcg0v.co.uk) [146.20.65.136]:54525 closed by QUIT
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:51:20 firewall smtpd[7932]: SCANNER[7932]: 1cdzzM-00023w-Dv <= service-jimbo=jimbojones.com@hmrcg0v.co.uk R=1cdzyu-00021Y-1J P=INPUT S=145531
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:51:20 firewall smtpd[7932]: SCANNER[7932]: id="1001" severity="info" sys="SecureMail" sub="smtp" name="email quarantined" srcip="146.20.65.136" from="service-jimbo=jimbojones.com@hmrcg0v.co.uk" to="jimbo@jimbojones.com" subject="HMRC Secure Communication" queueid="1cdzzM-00023w-Dv" size="145531" reason="as" extra=""
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-23:03:00 firewall exim-out[8786]: 2017-02-15 23:03:00 1cdzzM-00023w-Dv => jimbo@jimbojones.com P=<service-jimbo=jimbojones.com@hmrcg0v.co.uk> R=static_route_hostlist T=static_smtp H=My.LAN.IP.2 [My.LAN.IP.2]:25 C="250 2.0.0 Ok: queued as 929496086CE0"

Reply
  • Sorry,

    Came in via SMTP Proxy

    Was marked as spam, when I released it and forwarded I got the message.

     

    Log:

    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:50:51 firewall exim-in[7784]: 2017-02-15 13:50:51 H=(hmrcg0v.co.uk) [146.20.65.136]:54525 Warning: jimbojones.com profile excludes greylisting: Skipping greylisting for this message
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:50:51 firewall exim-in[7784]: 2017-02-15 13:50:51 H=(hmrcg0v.co.uk) [146.20.65.136]:54525 Warning: jimbojones.com profile excludes SANDBOX scan
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:50:52 firewall exim-in[7784]: 2017-02-15 13:50:52 [146.20.65.136] F=<service-jimbo=jimbojones.com@hmrcg0v.co.uk> R=<jimbo@jimbojones.com> Verifying recipient address with callout
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:51:13 firewall exim-in[7784]: 2017-02-15 13:51:13 1cdzyu-00021Y-1J DKIM: d=hmrcg0v.co.uk s=key c=relaxed/relaxed a=rsa-sha1 [invalid - public key record (currently?) unavailable]
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:51:14 firewall exim-in[7784]: 2017-02-15 13:51:14 1cdzyu-00021Y-1J <= service-jimbo=jimbojones.com@hmrcg0v.co.uk H=(hmrcg0v.co.uk) [146.20.65.136]:54525 P=esmtp S=146907 id=0.0.0.0.1D287917DA14CAC.1AC5FEA0@hmrcg0v.co.uk
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:51:14 firewall exim-in[7784]: 2017-02-15 13:51:14 SMTP connection from (hmrcg0v.co.uk) [146.20.65.136]:54525 closed by QUIT
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:51:20 firewall smtpd[7932]: SCANNER[7932]: 1cdzzM-00023w-Dv <= service-jimbo=jimbojones.com@hmrcg0v.co.uk R=1cdzyu-00021Y-1J P=INPUT S=145531
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-13:51:20 firewall smtpd[7932]: SCANNER[7932]: id="1001" severity="info" sys="SecureMail" sub="smtp" name="email quarantined" srcip="146.20.65.136" from="service-jimbo=jimbojones.com@hmrcg0v.co.uk" to="jimbo@jimbojones.com" subject="HMRC Secure Communication" queueid="1cdzzM-00023w-Dv" size="145531" reason="as" extra=""
    /var/log/smtp/2017/02/smtp-2017-02-15.log.gz:2017:02:15-23:03:00 firewall exim-out[8786]: 2017-02-15 23:03:00 1cdzzM-00023w-Dv => jimbo@jimbojones.com P=<service-jimbo=jimbojones.com@hmrcg0v.co.uk> R=static_route_hostlist T=static_smtp H=My.LAN.IP.2 [My.LAN.IP.2]:25 C="250 2.0.0 Ok: queued as 929496086CE0"

Children