Topic: Why does email with virus get delivered?
==== Required information ====
- iRedMail version: 0.8.6
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Linux/BSD distribution name and version: Centos 6
- Related log if you're reporting an issue: /var/log/maillog
Emails with attachments containing viruses seem to be coming without being blocked. I found this in the logs:
Mar 26 20:53:55 ip-hidden postfix/smtpd[3375]: connect from unknown[4.31.76.74]
Mar 26 20:53:55 ip-hidden postfix/smtpd[3375]: C043BDB2632: client=unknown[4.31.76.74]
Mar 26 20:53:56 ip-hidden postfix/cleanup[3406]: C043BDB2632: message-id=<001e01cf4934cf1253c4c800000a@SIT-RDP-EST-01>
Mar 26 20:53:57 ip-hidden postfix/qmgr[21871]: C043BDB2632: from=<dontreply303@asklawyers.com>, size=109901, nrcpt=2 (queue active)
Mar 26 20:53:57 ip-hidden postfix/smtpd[3375]: disconnect from unknown[4.31.76.74]
Mar 26 20:53:58 ip-hidden postfix/smtpd[3429]: connect from localhost[127.0.0.1]
Mar 26 20:53:58 ip-hidden postfix/smtpd[3429]: 5E544DB266A: client=localhost[127.0.0.1]
Mar 26 20:53:58 ip-hidden postfix/cleanup[3406]: 5E544DB266A: message-id=<001e01cf4934cf1253c4c800000a@SIT-RDP-EST-01>
Mar 26 20:53:58 ip-hidden postfix/smtpd[3430]: connect from localhost[127.0.0.1]
Mar 26 20:53:58 ip-hidden postfix/smtpd[3429]: disconnect from localhost[127.0.0.1]
Mar 26 20:53:58 ip-hidden postfix/qmgr[21871]: 5E544DB266A: from=<dontreply303@asklawyers.com>, size=110517, nrcpt=1 (queue active)
Mar 26 20:53:58 ip-hidden postfix/smtpd[3430]: 603B9DB266B: client=localhost[127.0.0.1]
Mar 26 20:53:58 ip-hidden postfix/cleanup[3406]: 603B9DB266B: message-id=<001e01cf4934cf1253c4c800000a@SIT-RDP-EST-01>
Mar 26 20:53:58 ip-hidden amavis[3102]: (03102-03) Passed BANNED (.exe,.exe-ms,Court_Notice.exe) {RelayedTaggedOutbound}, LOCAL [4.31.76.74]:5970 [4.31.76.74] <dontreply303@asklawyers.com> -> <xxxxx@yyyyy.com>, Message-ID: <001e01cf4934cf1253c4c800000a@SIT-RDP-EST-01>, mail_id: 24cyMsygNso9, Hits: 3.419, size: 109901, queued_as: 5E544DB266A, 1268 ms
Mar 26 20:53:58 ip-hidden postfix/qmgr[21871]: 603B9DB266B: from=<dontreply303@asklawyers.com>, size=110509, nrcpt=1 (queue active)
Mar 26 20:53:58 ip-hidden postfix/smtpd[3430]: disconnect from localhost[127.0.0.1]
Mar 26 20:53:58 ip-hidden postfix/smtp[3410]: C043BDB2632: to=<xxxxx@yyyyy.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=2.9, delays=1.6/0.02/0/1.3, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 5E544DB266A)
Mar 26 20:53:58 ip-hidden amavis[1190]: (01190-19) Passed BANNED (.exe,.exe-ms,Court_Notice.exe) {RelayedTaggedOutbound}, LOCAL [4.31.76.74]:5970 [4.31.76.74] <dontreply303@asklawyers.com> -> <xxxxx@yyyyy.com>, Message-ID: <001e01cf4934cf1253c4c800000a@SIT-RDP-EST-01>, mail_id: gZf768fkYbnt, Hits: 3.419, size: 109901, queued_as: 603B9DB266B, 1259 ms
Mar 26 20:53:58 ip-hidden postfix/smtp[3411]: C043BDB2632: to=<xxxxx@yyyyy.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=2.9, delays=1.6/0.03/0/1.3, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 603B9DB266B)
Mar 26 20:53:58 ip-hidden postfix/qmgr[21871]: C043BDB2632: removed
Mar 26 20:53:58 ip-hidden postfix/pipe[3431]: 5E544DB266A: to=<xxxxx@yyyyy.com>, relay=dovecot, delay=0.04, delays=0.01/0.01/0/0.03, dsn=2.0.0, status=sent (delivered via dovecot service)
Mar 26 20:53:58 ip-hidden postfix/qmgr[21871]: 5E544DB266A: removed
As you can see the email has an attachment with an executable in it and Amavis says Passed BANNED. Is there a way of getting better protection or configuring Amavis to block those emails?
FYI: certain things might appear twice as there is a forward for the destination mailbox active
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.