Topic: Amavis does not detect virus/trojan horse
==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.3.1 MARIADB edition.
- Deployed with iRedMail Easy or the downloadable installer? downloadable installer
- Linux/BSD distribution name and version: CentOS 7
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? No
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
One of my customer complains about the fact that he received trojan horses in his e-mail.
His desktop antivirus has found the trojan horse.
/var/log/maillog says this about one of the e-mails:
Sep 1 20:30:51 mail02 amavis[26531]: (26531-10) Passed CLEAN {RelayedInbound}, [212.76.85.90]:59518 [31.166.126.163] <w.ibrahim@al-bustan.net> -> <client-email>, Queue-ID: 4BgwcR09jVzMvf2W, Message-ID: <CE8596ACA3E54B7FBE73DF53DB39F611.MAI@sw16.saharanet.com>, mail_id: RyLsHW1-pZTd, Hits: 0.103, size: 251574, queued_as: 4BgwcW11SGzMsRZT, 1961 ms, Tests: [HTML_MESSAGE=0.001,MIME_HTML_ONLY=0.1,SPF_HELO_NONE=0.001,SPF_NONE=0.001]
Sep 1 20:30:51 mail02 amavis[26531]: (26531-10) Passed CLEAN, <w.ibrahim@al-bustan.net> -> <client-email>, Hits: 0.103, tag=2, tag2=6.2, kill=6.9, queued_as: 4BgwcW11SGzMsRZT, L/0/0/0
Running clamscan manual over the file (clamscan --scan-mail=yes --phishing-sigs=yes --phishing-scan-urls=yes --heuristic-alerts=yes <file>), this is the output:
/var/vmail/vmail1/domain/path-to/Maildir/.Trash/cur/1598985051.M249203P702.mailserverFQDN,S=248925,W=252182:2,Sac: Doc.Downloader.Emotet-9621083-0 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 8793853
Engine version: 0.102.4
Scanned directories: 0
Scanned files: 1
Infected files: 1
Data scanned: 0.01 MB
Data read: 0.23 MB (ratio 0.05:1)
Time: 20.838 sec (0 m 20 s)
Why does amavis not take care of this threat?
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.