This is a big problem. clamav detects a virus, but the email is send thru. Also there is no way to block a archive that could not be unpacked.
Here is the log (i changed some names and ipadresses for privacy reasons):
Mar 17 16:35:28 pmg postfix/smtpd[109597]: connect from mout.kundenserver.de[212.227.17.24]
Mar 17 16:35:28 pmg postfix/smtpd[109597]: NOQUEUE: client=mout.kundenserver.de[212.227.17.24]
Mar 17 16:35:28 pmg pmg-smtp-filter[109598]: 14B56623355402F876: new mail message-id=<kcis.53709C30E7FA43B786E8135D89DA46BD@mymail>#012
Mar 17 16:35:28 pmg pmg-smtp-filter[109598]: 14B56623355402F876: virus detected: Heuristics.Encrypted.Zip (clamav)
Mar 17 16:35:28 pmg pmg-smtp-filter[109598]: 14B56623355402F876: found archive 'AWLAmmonitore speciale BIMU-1.eml' (message/rfc822)
Mar 17 16:35:28 pmg pmg-smtp-filter[109598]: 14B56623355402F876: unpack failed - child '110656' failed: 512
Mar 17 16:35:28 pmg pmg-smtp-filter[109598]: 14B56623355402F876: unpack archive 'AWLAmmonitore speciale BIMU-1.eml' done (44 ms)
Mar 17 16:35:31 pmg pmg-smtp-filter[109598]: 14B56623355402F876: SA score=4/5 time=3.213 bayes=undefined autolearn=no autolearn_force=no hits=ClamAVHeuristics(3),AWL(-0.070),HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),KAM_LAZY_DOMAIN_SECURITY(1),KAM_NUMSUBJECT(0.5),MIME_HTML_ONLY(0.1),RCVD_IN_MSPIKE_H2(-0.001),SPF_HELO_NONE(0.001),SPF_NONE(0.001),T_SCC_BODY_TEXT_LINE(-0.01),XPRIO(0.167)
Mar 17 16:35:31 pmg postfix/smtpd[109052]: connect from localhost[127.0.0.1]
Mar 17 16:35:31 pmg postfix/smtpd[109052]: 85DB014B5F: client=localhost[127.0.0.1], orig_client=mout.kundenserver.de[212.227.17.24]
Mar 17 16:35:31 pmg postfix/cleanup[109053]: 85DB014B5F: message-id=<kcis.53709C30E7FA43B786E8135D89DA46BD@mymail>
Mar 17 16:35:31 pmg postfix/qmgr[108144]: 85DB014B5F: from=<myemail@sender.de>, size=55632, nrcpt=1 (queue active)
Mar 17 16:35:31 pmg postfix/smtpd[109052]: disconnect from localhost[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5
Mar 17 16:35:31 pmg pmg-smtp-filter[109598]: 14B56623355402F876: accept mail to <myemail@receiver.de> (85DB014B5F) (rule: rule_possibleSpam (Level 2))
Mar 17 16:35:31 pmg pmg-smtp-filter[109598]: 14B56623355402F876: processing time: 3.358 seconds (3.213, 0.027, 0)
Mar 17 16:35:31 pmg postfix/smtpd[109597]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (14B56623355402F876); from=<myemail@sender.de> to=<myemail@receiver.de> proto=ESMTP helo=<mout.kundenserver.de>
Mar 17 16:35:31 pmg postfix/smtp[109054]: 85DB014B5F: to=<myemail@receiver.de>, relay=0.0.0.10[0.0.0.10]:25, delay=0.04, delays=0.01/0/0/0.03, dsn=2.0.0, status=sent (250 Message accepted for delivery)
Mar 17 16:35:31 pmg postfix/qmgr[108144]: 85DB014B5F: removed
Mar 17 16:35:31 pmg postfix/smtpd[109597]: disconnect from mout.kundenserver.de[212.227.17.24] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
Here is the log (i changed some names and ipadresses for privacy reasons):
Mar 17 16:35:28 pmg postfix/smtpd[109597]: connect from mout.kundenserver.de[212.227.17.24]
Mar 17 16:35:28 pmg postfix/smtpd[109597]: NOQUEUE: client=mout.kundenserver.de[212.227.17.24]
Mar 17 16:35:28 pmg pmg-smtp-filter[109598]: 14B56623355402F876: new mail message-id=<kcis.53709C30E7FA43B786E8135D89DA46BD@mymail>#012
Mar 17 16:35:28 pmg pmg-smtp-filter[109598]: 14B56623355402F876: virus detected: Heuristics.Encrypted.Zip (clamav)
Mar 17 16:35:28 pmg pmg-smtp-filter[109598]: 14B56623355402F876: found archive 'AWLAmmonitore speciale BIMU-1.eml' (message/rfc822)
Mar 17 16:35:28 pmg pmg-smtp-filter[109598]: 14B56623355402F876: unpack failed - child '110656' failed: 512
Mar 17 16:35:28 pmg pmg-smtp-filter[109598]: 14B56623355402F876: unpack archive 'AWLAmmonitore speciale BIMU-1.eml' done (44 ms)
Mar 17 16:35:31 pmg pmg-smtp-filter[109598]: 14B56623355402F876: SA score=4/5 time=3.213 bayes=undefined autolearn=no autolearn_force=no hits=ClamAVHeuristics(3),AWL(-0.070),HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),KAM_LAZY_DOMAIN_SECURITY(1),KAM_NUMSUBJECT(0.5),MIME_HTML_ONLY(0.1),RCVD_IN_MSPIKE_H2(-0.001),SPF_HELO_NONE(0.001),SPF_NONE(0.001),T_SCC_BODY_TEXT_LINE(-0.01),XPRIO(0.167)
Mar 17 16:35:31 pmg postfix/smtpd[109052]: connect from localhost[127.0.0.1]
Mar 17 16:35:31 pmg postfix/smtpd[109052]: 85DB014B5F: client=localhost[127.0.0.1], orig_client=mout.kundenserver.de[212.227.17.24]
Mar 17 16:35:31 pmg postfix/cleanup[109053]: 85DB014B5F: message-id=<kcis.53709C30E7FA43B786E8135D89DA46BD@mymail>
Mar 17 16:35:31 pmg postfix/qmgr[108144]: 85DB014B5F: from=<myemail@sender.de>, size=55632, nrcpt=1 (queue active)
Mar 17 16:35:31 pmg postfix/smtpd[109052]: disconnect from localhost[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5
Mar 17 16:35:31 pmg pmg-smtp-filter[109598]: 14B56623355402F876: accept mail to <myemail@receiver.de> (85DB014B5F) (rule: rule_possibleSpam (Level 2))
Mar 17 16:35:31 pmg pmg-smtp-filter[109598]: 14B56623355402F876: processing time: 3.358 seconds (3.213, 0.027, 0)
Mar 17 16:35:31 pmg postfix/smtpd[109597]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (14B56623355402F876); from=<myemail@sender.de> to=<myemail@receiver.de> proto=ESMTP helo=<mout.kundenserver.de>
Mar 17 16:35:31 pmg postfix/smtp[109054]: 85DB014B5F: to=<myemail@receiver.de>, relay=0.0.0.10[0.0.0.10]:25, delay=0.04, delays=0.01/0/0/0.03, dsn=2.0.0, status=sent (250 Message accepted for delivery)
Mar 17 16:35:31 pmg postfix/qmgr[108144]: 85DB014B5F: removed
Mar 17 16:35:31 pmg postfix/smtpd[109597]: disconnect from mout.kundenserver.de[212.227.17.24] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5