This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Antivirus not catching infected .doc files?

Hi all.  We've suddenly begun getting deluged with emails containing infected MS Word .doc files that use, if memory serves, a W97 macro attack.  I have both Avira and Sophos antivirus engines running on our inbound email, but these things are sailing right through the Sophos firewall.  Can anyone suggest a way to intercept these while allowing uninfected .doc files through?  The attacks are old; it's not like they're using an attack that the antivirus has never heard of.
Dual UTM-525 in HA active/passive cluster running 9.315-2.

I see that we're not the only ones seeing this uptick: https://threatpost.com/microsoft-reports-massive-increase-in-macros-enabled-threats/110204


TIA,
Brian


This thread was automatically locked due to age.
Parents
  • Well it may be some kind of either problem with AV on the UTM, or config issue.  Have you been able to see anything in logging where it is allowed through?

    OPNSense 64-bit | Intel Xeon 4-core v3 1225 3.20Ghz
    16GB Memory | 500GB SSD HDD | ATT Fiber 1GB
    (Former Sophos UTM Veteran, Former XG Rookie)

Reply
  • Well it may be some kind of either problem with AV on the UTM, or config issue.  Have you been able to see anything in logging where it is allowed through?

    OPNSense 64-bit | Intel Xeon 4-core v3 1225 3.20Ghz
    16GB Memory | 500GB SSD HDD | ATT Fiber 1GB
    (Former Sophos UTM Veteran, Former XG Rookie)

Children
  • Yes; the log shows it passing right through without any kind of issue.

    Well it may be some kind of either problem with AV on the UTM, or config issue.  Have you been able to see anything in logging where it is allowed through?