1

Topic: Block Ransomware

How I can block or remove ransomware emails that contain ZIP file with the executable or JS that encrypt all client pc files?

Thank you

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: Block Ransomware

It's defined in Amavisd config file, setting '$banned_filename_re' or '$banned_namepath_re'.

3

Re: Block Ransomware

Can you exlain me with more details?
I don't want to block all ZIP file, only that contain executable files.

I've also read this
https://extremeshok.com/6873/iredmail-a … assin-3-x/
can be a valid help for preventing infected mails? Which of two method do you suggest?

There is some guidelines?
Thank you

4

Re: Block Ransomware

johjoh wrote:

Can you exlain me with more details?
I don't want to block all ZIP file, only that contain executable files.

There're some samples in the config file, so you should be able to simply copy/paste with some modification to match your need.

5

Re: Block Ransomware

here is a guide you've asked about https://sureshotsoftware.com/guides/decrypt-btcware/