Executable file (virus, attached) slipping through

ron

Member
Oct 31, 2006
38
0
6
Hi ;)

attached is an infected file that managed to pass the gateway and was detected/qurantined by smsmse 6.5. over the past few days, there have been a few incidents like this one. can you spot the difference between this file and other executables that are usualy blocked at the gateway level?
 

Attachments

  • SYQb8854011_instructions.zip
    9.6 KB · Views: 5
thanks for reporting, I submitted the file to the clamav maintainers for analysis.
 
Hi Tom,

more and more viruses are passing through the gateway (which is healthy and up to date).
I am not sure at all that this is a CLAM issue - even if the files weren't viruses - they are still executables inside an un-encrypted zip file, and should have been blocked ('Dangerous Content' rules are at their default)...
 

Attachments

  • SYQb8c927f2_Forwarded Message.zip
    8.7 KB · Views: 6
  • SYQba0a3461_instructions.zip
    9.6 KB · Views: 4
  • SYQbb4a8eb1_statement.zip
    8.2 KB · Views: 3
  • SYQbc01d282_report.zip
    8.3 KB · Views: 3
  • SYQbc419351_dhl_viewer.zip
    8.9 KB · Views: 3
Last edited:
I just sent all file through our testenvironment, all viruses gets detected by Avira SAV, but only three by ClamAV. so make sure your clamav is updating (check via web interface) and consider the second AV scanning engine.

Dangerous Content (default rule):
this rule does not block exe files inside zip
 
no.
 
Why do you filter ransomware only during office hours?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!