This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Logs do not specify blocked filetypes. Where do downloads blocked by filetype appear in the logs?

I performed the eicar test where I attempt to download the Eicar virus testfile. The block page shows that the file eicar.com was blocked by filetype. However, the webfilter log shows that the website was blocked, but does not specify that it was due to a fileype being blocked. HTTPS decryption is working properly, but I noticed it was different this time:

Usually the webfilter blocks the eicar testfile from downloading and the block page says it blocked "websites categorized as Malware".

This time the webfilter did not detect the eicar test site as a malware site but instead blocked the ".com" filetype from downloading and did not actually detect the eicar testfile as a virus. the other .ZIP files were blocked due to web category Malware, and not extracted and scanned by the antivirus.

Nowhere i

But the logs are frustrating, with many users complaining that the block page/log is not specific enough to let a system admin know enough about what the exact details of the block are caused by.  

I looked through the logs (ATP, Zero-day protection, web filter), and there is no log anywhere that related to blocked filetypes.

I'ts even more strange since Sophos categorizes the Eicar testfile website as Information technology, Acceptable.

I created a Policy check exclusion for eicar.com in the Web Filter Exceptions, and now the AV component is able to successfully scan the .ZIP archives and detect them as malware. The eicar test files are now appearing in the Zero-Day protection logs as they should. If I remove the .COM filetype from the list of blocked filetypes, then it should also appear. This was just a configuration issue. But still, the log should say weather a download was blocked by filetype, since the eicar testfile site is categorized as acceptable, the log entry does not give any details to why it was blocked.



This thread was automatically locked due to age.
Parents
  • Hello,

    Greeting!

    I have reviewed the same in my local setup and observing the same behavior. I request you to raise the support case to get this confirmed and share us the case ID to progress it.

    Mayur Makvana
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question please use the 'Verify Answer' button.

  • I can't really get to the bottom of this. In the log in the post above, the site was categorized as "Information Technology" but now it is categorized as "Spyware and Malware" and I was wondering if it was just some sort of fluke: maybe Sophos mis-categorizing the site temporarily, or if I overrrided the website category, but I did not change anything besides playing around with the exceptions (HTTPS decryption/Malware/Zeroday/Policy)

    It's not a huge deal, but I can't seem to reproduce what it was doing before, where it blocked the download by the filetype (.COM)

    I don't know exactly how the firewall proccess web filtering in what order, whether it do a filetype check after it passes the web category lookup or the other way around. Exactly in what order it is done, there is a chart somewhere that shows the exact flow. I should study it.

    Aha, yes I found it.

Reply
  • I can't really get to the bottom of this. In the log in the post above, the site was categorized as "Information Technology" but now it is categorized as "Spyware and Malware" and I was wondering if it was just some sort of fluke: maybe Sophos mis-categorizing the site temporarily, or if I overrrided the website category, but I did not change anything besides playing around with the exceptions (HTTPS decryption/Malware/Zeroday/Policy)

    It's not a huge deal, but I can't seem to reproduce what it was doing before, where it blocked the download by the filetype (.COM)

    I don't know exactly how the firewall proccess web filtering in what order, whether it do a filetype check after it passes the web category lookup or the other way around. Exactly in what order it is done, there is a chart somewhere that shows the exact flow. I should study it.

    Aha, yes I found it.

Children
No Data