Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG 18.04 MR-4 more malware in emails missed even with Sandstorm now enabled!

After consulting the Sophos reseller we added the extra layer of protection of a Sophos Sandbox subscription.

I now have two additional MALWARE E-MAILS that ended up in the quarentine queue that based on the XG settings should have been dropped. Piuremessage with old definitions identifies them as Mal/Generic-S, Mal/DrodRar-AIC and Mal/Generic-S, Mal/Inject-GM, CXmail/MalPE-B.

XG MTA with SAV DUAL SCAN engine, primary set to Sophos and DETECT ZERO DAY threats with SANDSTORM ENABLED does not detect the malware in these e-mails. In my understanding e-mails that is still being scanned for malware not yet given the all green from both SAV scanning and Sandstrom should not be in the quarantine queue.

Support is not really responding other than sending their default e-mails with instructions to upload the file, My answer again and again is that the fille requested is in the online case portal already uploaded there.

These two new emails are now uploaded also and the case record updated.

The case number is 03694098.

Fred



This thread was automatically locked due to age.
Parents
  • Another virus missed by XG SAV and Sandstorm.

    Detection by Puremessage behind the XG with outdated definitions:

    Event: Virus infection detected

    Location: 1035 Purchase Contract.rar

    Replaced with text: Yes

    Virus name(s): CXmail/MalPE-BP

    I have uploaded this one to the support portal case also

Reply
  • Another virus missed by XG SAV and Sandstorm.

    Detection by Puremessage behind the XG with outdated definitions:

    Event: Virus infection detected

    Location: 1035 Purchase Contract.rar

    Replaced with text: Yes

    Virus name(s): CXmail/MalPE-BP

    I have uploaded this one to the support portal case also

Children
No Data