This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Invoice Malware & Doc files

We have been seeing, over several customers, that Puremessage has been putting a lot of messages into quarantine that really should be deleted.

The messages are fake invoices with a *.doc attachement which according to a quick search contains a macro virus.

An example being http://sanesecurity.blogspot.co.uk/2015/03/linsen-parts-uk-ltd-invoice-from-linsen.html

The problem with this is that a user still gets notified of the item and can still download it.

Our Pure message is set at 90 to delete messages and these seem to score 82-84 or so.

We have filtered some buy using athe subject, but others are craftier with a subject that keeps changing.

Any ideas or recommendations how to stop these other than reducing the delete threshold ?

:56308


This thread was automatically locked due to age.
Parents
  • after submitting the file yesterday I noticed a multitude of

    Server: SATURN_EMAIL_02

    ============================================================

    Incident information:

    Event: Virus infection detected

    Location: BHX8728621.doc

    Replaced with text: Yes

    Virus name(s): Troj/DocDl-QH

    being generated now.  Plus I cannot upload the file to virustotal anymore as endpoint detects as a virus. 

    I very much doubt I am the only recipient of a 0 day virus (especially as virustotal already had other vendors recognising the file as a virus).

    Not happy with sophos at all with this.  DRIDEX and variants are not new.

    :57562
Reply
  • after submitting the file yesterday I noticed a multitude of

    Server: SATURN_EMAIL_02

    ============================================================

    Incident information:

    Event: Virus infection detected

    Location: BHX8728621.doc

    Replaced with text: Yes

    Virus name(s): Troj/DocDl-QH

    being generated now.  Plus I cannot upload the file to virustotal anymore as endpoint detects as a virus. 

    I very much doubt I am the only recipient of a 0 day virus (especially as virustotal already had other vendors recognising the file as a virus).

    Not happy with sophos at all with this.  DRIDEX and variants are not new.

    :57562
Children
No Data