Messaging Gateway

 View Only
  • 1.  SMG missed the Malware attachment Email.

    Posted Nov 11, 2015 12:01 AM

    We used Symantec messaging Gateway Appliances with version 10.xx, One of our user recivied One Email with attachment (.ZIP) and and got infected with Malware.

     

    kindly help me to find out this issue.



  • 2.  RE: SMG missed the Malware attachment Email.

    Posted Nov 11, 2015 11:15 AM

    Open an incident, but they need the sample.

    In the meantime block these kind of files, eg exe, js, etc

    In addition, add an additional malware-scanner



  • 3.  RE: SMG missed the Malware attachment Email.

    Broadcom Employee
    Posted Nov 11, 2015 12:19 PM

    If the Messaging Gateway missed the threat, and the Endpoint client also missed the threat, we need a sample submitted so we can detect it in the future.

    Please submit the sample here: https://submit.symantec.com/websubmit/basic.cgi



  • 4.  RE: SMG missed the Malware attachment Email.

    Posted Jan 05, 2016 09:49 PM

    Hi,

    in SMG, it is enabled by default? or we need to add additional rule to block this kind of email?

    any help will be appreciate, thanks!



  • 5.  RE: SMG missed the Malware attachment Email.

    Broadcom Employee
    Posted Jan 06, 2016 10:24 AM

    The 'Virus: Clean message" rule is the default for malware, so unless anything was changed that should still be in effect.



  • 6.  RE: SMG missed the Malware attachment Email.

    Posted Jan 07, 2016 03:12 AM

    Hi Davis,

    Thank for your response,

    I am able to find this Virus: Clean message (default)" under Malware Policy, it is enabled and apply to default policy group.

    but when tested, the virus email still go through

     

     



  • 7.  RE: SMG missed the Malware attachment Email.

    Posted Jan 07, 2016 04:11 AM

    Does this message belong to SMG?

    This message has been processed by Symantec AntiVirus.

    Invoice Copy.ace was infected with the malicious virus Infostealer.Limitail and has been deleted because the file cannot be cleaned

     



  • 8.  RE: SMG missed the Malware attachment Email.

    Broadcom Employee
    Posted Jan 07, 2016 10:46 AM

    No, that clearly states Symantec AntiVirus, which is a very old product