Outbreak filters (OF/VOF) released viral emails

Hello,
yestearday 24.2.2015 around 9:00 CET we were on the top of viral email attack. In less than one hour OF on the Ironport started to react on this attack. That's great. But at midnight all emails from OF quarantine from this attack was released as a clean messages. Together with OF we have a  Sophos on the Ironport. Here's the log of one email:
24 Feb 2015 09:24:38 (GMT +00:00)
Message 286265 matched per-recipient policy DEFAULT for inbound mail policies.
24 Feb 2015 09:24:38 (GMT +00:00)
Message 286265 scanned by Anti-Spam engine CASE. Interim verdict: definitely negative.
24 Feb 2015 09:24:38 (GMT +00:00)
Message 286265 scanned by Anti-Spam engine: CASE. Final verdict: Negative
24 Feb 2015 09:24:38 (GMT +00:00)
Message 286265 scanned by Anti-Virus engine Sophos. Interim verdict: CLEAN
24 Feb 2015 09:24:38 (GMT +00:00)
Message 286265 scanned by Outbreak Filters. Verdict: Positive
24 Feb 2015 09:24:38 (GMT +00:00)
Message 286265 contains attachment '[email protected]'.
24 Feb 2015 09:24:38 (GMT +00:00)
Message 286265 Virus Threat Level=3
24 Feb 2015 09:24:38 (GMT +00:00)
Message 286265 contains attachment types zip
24 Feb 2015 09:24:38 (GMT +00:00)
Message 286265 quarantined to Outbreak by Outbreak Filters rule. OUTBREAK_0013689
24 Feb 2015 17:47:19 (GMT +00:00)
Message 286265 quarantined in Outbreak by Virus Outbreak Filters rule. OUTBREAK_0013699
24 Feb 2015 17:57:24 (GMT +00:00)
Message 286265 quarantined in Outbreak by Virus Outbreak Filters rule. OUTBREAK_0013689
24 Feb 2015 23:03:38 (GMT +00:00)
Message 286265 released from quarantine Outbreak after 49140 seconds. Reason: rescanned.
24 Feb 2015 23:03:38 (GMT +00:00)
Message 286265 released from all quarantines.
24 Feb 2015 23:03:38 (GMT +00:00)
Message 286265 matched per-recipient policy DEFAULT for inbound mail policies.
24 Feb 2015 23:03:38 (GMT +00:00)
Message 286265 scanned by Anti-Spam engine: CASE. Interim verdict: Negative
24 Feb 2015 23:03:38 (GMT +00:00)
Message 286265 scanned by Anti-Spam engine CASE. Interim verdict: definitely negative.
24 Feb 2015 23:03:38 (GMT +00:00)
Message 286265 scanned by Anti-Spam engine: CASE. Final verdict: Negative
24 Feb 2015 23:03:38 (GMT +00:00)
Message 286265 scanned by Anti-Virus engine Sophos. Interim verdict: CLEAN
24 Feb 2015 23:03:38 (GMT +00:00)
Message 286265 queued for delivery.
Yesterday at 12:00 CET I reported virus to the Sophos because the virus is not recognized by Sophos. I recieved this answer:
The file(s) submitted were malicious in nature and detection will be available on the Sophos Databank shortly.
From today morning I'm going thou Ironport configuration, forums, reading best practices but I can't find any useful information what's wrong. Why OF together with Sophos released viral emails. We have an Ironports for seven years and this is my first real problem with email scanning. In fact the mail should be stopped by VOF, antispam or antivirus. There's three engines which should react. I'm shocked. I hope that I have some misconfiguration on the Ironport. 
I would be happy for any idea. Thank you.
EDIT:
2x C170 with 8.5.6-092

Hello,
Sorry for the delay in my response, I sent that email before i went to bed last night.
As per your follow up.
The VOF rules can be 'checked' to a certain degree under the command
CLI > outbreakstatus
This will list a set of rules with sensory information such as unusual amounts of certain types of files, and such which can be triggered on VOF scanning.
But detailed information is kept as it's proprietary information.
Senderbase will not list the rules in full detail as if these rules were publicly available to be seen, spammers will take advantage of this and find ways around current rule sets being pushed out proactively.
The outlook add-in on your system for flagging these emails, when you do send a submission it will go to our database where our automated systems will re-classify emails based on the type of submission to the best of the automated processes abilities.
However if for some reason it cannot reclassify an email (possibly content if completely unknown) then a TAC case may be required to escalate it to the rule writing team further
But your submissions do get to us, and it is being used by the spam team from automated system to manual humans writing out rules.
Regards,
Matty

Similar Messages

  • Silent Spam Filtering - No NDR to Sender / No Notification to Recipient / No Option to Release Blocked Emails / No Support Document to request for Whitelisting of Sender

    Silent Spam Filtering used by iCloud is currently affecting us and our Customers. Our Customer, when sending us emails from their business domain (no presence on Global Spam Blacklists), is not able to reach us on our iCloud account and there is absolutely no sign of the email within the Inbox / Junk Folder and surprisingly no NDR to the Sender
    Symantec MessageLabs used for Outbound Mail Frittering by our customer confirms the emails to be delivered to MAC Servers, but not being forwarded to us or other end users using *@icloud.com account
    Delivery Report Extract:
    2014-10-15 03:56:39 PM SMTP Status: OK
    2014-10-15 03:56:44 PM Delivery attempt #1  (final)
    2014-10-15 03:56:44 PM Recipient server: 17.158.8.68 (mx1.mail.icloud.com)
    2014-10-15 03:56:44 PM Response: 250 2.5.0 Ok, envelope id [email protected]
    There should be a convenient way to request Apple Support Team, for addition of the Sender to an approved list or there should definitely be a Notification to the recipient of a Blocked Email address, which should help them to identify and release such emails, at will into their Inbox and not land up losing critical Customer Communications
    Cloud based Spam Filtering Solution Providers(Symantec, Microsoft and others to name a few) allows such options, as an email is now  a Business Essential Document and should be securely delivered to recipients

    This issue has become increasing prevalent over the last year and a half and has been covered by a number of reputable websites doing their own testing:
    http://www.macworld.com/article/2029570/silent-email-filtering-makes-icloud-an-u nreliable-option.html
    http://www.macworld.co.uk/news/mac/apple-censoring-icloud-emails-attachments-343 2561/
    http://www.mcelhearn.com/apples-silent-email-filtering-is-just-plain-wrong/
    No bounces are sent - messages are being accepted by Apple's mail servers and then filtered before they reach users inboxes. This is a pretty big deal.
    dgb

  • I have had a random e-mail telling me from Apple to confirm my Apple ID! I don't know whether this is one of those junk viral emails or its genuine. The reason I had the e-mail is that some tried to sign in using my ID.

    I had an e-mail from apple today regarding someone tried to sign into my apple ID account. They disabled my account for security reasons but I can still log into my Apple account!
    I was wondering if anyone else has bad this similar email, because this may be a viral email trying to obtain ones Apple information to use ones account fraudulently!

    Does this resemble the email you received?
    Read this post: Email verification sent by "[email protected]" Is it a scam?
    Identifying fraudulent "phishing" email
    Identifying legitimate emails from the iTunes Store
    The iTunes Store will never ask you to provide personal information or sensitive account information (such as passwords or credit card numbers) via email.

  • Send copy of released quarantined email

    Hi,
    Is it possible to send a copy of a released quarantined email to a specific mailbox/emailaddress? So, when the enduser releases an email which has been quarantined, a copy of that email needs to be send to a ham-mailbox. As administrator we can send these ham-messages to ironport using the outlook-snapins.
    Thanks in advance!
    Cor

    One of the settings configurable in your IronPort SPAM Quarantine setup is the check to enable the Reporting of released messages to IronPort for analysis. Is this what you are wanting to do or do you require BCC'ing those emails to another mailbox locally.
    Go to
    Monitor/Local Quarantines/IronPort SPAM Quarantine and Edit settings and enable "Notify IronPort Upon Message Release:"

  • The ePrint center can not release my email address what I deleted. So, I have to change another.

    The ePrint center can not release my email address what I deleted. So, I have to change another.
    How can I use the address again?
    Thanks.

    Hello GeorgeChang,
    You can not use the same custom ePrint email for your printer until it becomes unlocked in six months.  Sorry for the inconvenience.
    -------------How do I give Kudos? | How do I mark a post as Solved? --------------------------------------------------------

  • End user releasing own emails based on Policy/Content

    Hiya all,
    New to this forum and my first post so hello to all
    We recently installed a couple of C360 and an M series and they all are working well.
    We have also setup Profanity based filtering and as a result many swear words are being rejected.
    This is setup using dictionaries.
    But we are also getting a high number of false positives and as a result our Techsupport team is inundated with requests to release emails.
    I know with SPAM Quarantine there is End-User Quarantine Access but I don’t see this with Policy Quarantine.
    The end result I want is for end users to release their own emails blocked based on profanity.
    Is this possible?
    My apologies if this has been asked in the past.
    Ivan.
    :D :D

    Welcome aboard Ivan!
    The main reason there is a separation between ironport spam quarantine(isq) and policy quarantine(aka system quarantine) is that ISQ is mainly used in conjunction with the anti-spam verdict/results. While policy quarantine is used as a result of administrative/company policy(e.g. like a profanity dictionary filter in your case).
    Another difference between the two is ISQ is accessible by the end user. Policy quarantine is accessibly only by the admin of the machine.
    Here is a KB article that goes over their diffs.
    What is the difference between IronPort Spam Quarantine and System Quarantine?
    http://tinyurl.com/233qkq
    Now, there is a way to tweak it so that the content filter sends it over to the ISQ. Now keep in mind by doing this, you're mixing profanity filter verdicts with anti-spam results. It may be confusing for the end user unless you preprend the profanity stuff with "[Contains profanity]" at the beginning of the subject line.
    This Cisco IronPort support portal KB article goes over how to send content filter results over to the ISQ.
    Can a Content Filter divert messages to the IronPort Spam Quarantine?
    http://tinyurl.com/coebj3
    Good luck and let me know if that doesn't address your concern.

  • Visual Studio Online / Release Management Email Notifications

    We use Visual Studio Online and not a local TFS instance. Additionally we want to / ARE using the Release Management service.  But, we are having difficulties configuring the Email notifications within Release Management.    We have steps
    configured  for email notification on step approval.  BUT we are not getting any of these notifications and the Releases get stuck waiting during these steps.  And only if by sheer dumb luck the user logs into his/her Release Management window
    do they see that they have pending approvals...
    What do we need to do in order to get these approvals flowing?
    Thanks in advance!

    Hi,
    Thank you for reaching out to us. I am currently researching to gather more information with regards to your request. I shall revert back to you with an update at the earliest. Sincerely appreciate your patience.
    Regards,
    Nithin Rathnakar

  • Send of releases via email to vendors

    Hi Team...
    I have a issue, when we are sending the releases of a Schedule Agreement the output said that it was processed but when I go to the Txn SOST the output is not there.
    I compare the data of the vendors and the outputs meesages in MN12 and all looks the same.
    This is the process log I got for the message that is not being send
    Message
    Object 00550030850001010000000014
    Output type: For. Sch.-MX(EMAIL)
    Processing log for program ZM_SAPFM06P routine ENTRY_LPHE
    Message outputted under spool request number    133358
    And this is the log of the message that is correct:
    Object 00550005490001010000000017
    Output type: For. Sch.-MX(EMAIL)
    Processing log for program ZM_SAPFM06P routine ENTRY_LPHE
    Message object  created or sent
    As I mention, in the MN12 the 2 vendors show the same info like output medium =5, time=3, has the Comm strategy =CS01 (internet-letter).
    What else should I need to check??

    Problem solved.
    The issue was that the contract was very old, and when it was created the vendor master had not the email so when create the contract then email was empy.
    We maintain the vendor address into the SA manually and with that the email was sent.

  • Clicking on a viral email link has caused Safari to play up

    I received a link from my aunt through email this morning.  Not realising that it must have been viral I clicked on the link. 
    It opened up in safari and since then I could not quit out of safari, and the option is greyed out.  I choose instead to reset safari which means I can now use it, however I cannot quit out of safari and every time I try and shut down, my imac now says that I cannot shut down due to it being open?!!!!  . 
    Please help, I am concerned I now have a virus.
    I'm currently on Mountain Lion version 10.8.2, running safari 6.0.1
    Thanks...

    You do not have a virus.
    When you open Safari, is it still loading the same page? If so, force-quit Safari (press command-option-esc, then choose Safari and click the Force Quit button). Then, hold down the shift key and open Safari again. This will prevent it from loading whatever sites were open when it quit.
    If that doesn't help, let us know...

  • Work flow for release procedure Email

    How is the person responsible for releasing the purchase document to be notified by email or other methord.where is in SAP R/3 define  the person responsible for approval to be notified?where are we assign the workflow of purchase document.how is the email is send by the R/3 system to the particular person how is responsible for release the purchase document. Please explain in detail with t-code

    plz give to me some helpful advice.
    Edited by: GAURAV MITTAL on Nov 27, 2009 7:59 AM
    Edited by: GAURAV MITTAL on Nov 30, 2009 5:23 AM

  • I developed a number of message filters and now cannot receive emails. I deleted the filters and I still no emails. The account settings are right.

    The emails are at my server location but will not show up on my desktop machine. They show up on our other machines that also have filters. The desktop machine is XP and the netbooks are Windows 7. I am at a loss. Any help would be greatly appreciated.

    Here are the correct settings. They have never changed since iCloud debuted a year ago.
    Server information
    IMAP (Incoming Mail Server) information:
    Server name: imap.mail.me.com
    SSL Required: Yes
    Port: 993
    Username: [email protected] (use your @me.com address from your iCloud account)
    Password: Your iCloud password
    SMTP (outgoing mail server) information:
    Server name: smtp.mail.me.com
    SSL Required: Yes
    Port: 587
    SMTP Authentication Required: Yes
    Username: [email protected] (use your @me.com address from your iCloud account)
    Password: Your iCloud password
    Note: If you receive errors using SSL, try using TLS instead. SSL is required for both IMAP and SMTP connection with iCloud. POP is not supported by iCloud. 

  • When I try to create a new sync account using my email address, the response says it's alreay in use. I imagine this is a relic of my old foxmarks account. Is there a way to release that email account from the old version, or to reover the password?

    I've gotten an iPhone, and downloaded the Firefox browser to it, and I'd like to sync the browsers between my iMac and iPhone. When I enter my email to create a new sync account, I'm told that it's already in use, but there's no option to retrieve my password.
    Any idea how to get around this?

    Try the options at https://services.mozilla.com/ and see if you can't recover the password.

  • Purchase Order Release Strategy - Emails/SOST

    Hi,
    Please bear with me in terms of knowledge level on this subject, it's not normally my "area" but I'm trying to assist a colleague.
    When an order reaches a certain value, it requires authorisation by a senior member of staff, from Manager to Director, and finally Managing Director.  Probably not unusual.
    When a member of our Purchasing Team input an order that requires higher level authorisation, after it has been authorised it goes into the email queue in SOST.
    However, the sender is displayed as the person who authorised the order, not the person who raised the order.  In other words, we have Purchase Orders arriving in Vendors inboxes addressed from our MD!
    We don't want this.
    Can anyone point me in the direction of the config which may allow me to alter this?
    Many thanks.
    If this is in the wrong forum, I apologise, I was unsure where to post it.

    this can only be achieved with a modification.
    Please find details in OSS note 561593

  • Security Services \ Outbreak Filters - Maximum Message Size to Scan?

    We still have the Maximum Message Size to Scan: set to 256K is that too low by today's standards?

    We have our set to 1M.  The only issue is that it will use more memory to scan.  Other than that, no issues for us when we change it.

  • Emails from my Blackberry are getting trapped by spam filtering

    It's not a consistent thing, which makes this more aggravating, but I have my work email set up on my Storm (9530), and many times, when I reply to an email that involves my co-workers, my emails get trapped by our online spam filtering.  Both my work email, as well as the "bis" Blackberry information has been added to the "whitelist", but these emails still have occasion to be trapped.
    Can someone please help me get to the bottom of what is being embedded in the source header information from these emails that might be causing this problem?
    I've noticed this is true of other emails originating from BlackBerry phones, regardless of the carrier.
    Thank you.

    Hi and Welcome to the Forums!
    I'm thinking that you need to work with your SPAM filtration vendor...all of the header information is fully visible to an administrator who traps one of the captured emails. They need to compare that trapped email to the rules they have in their SPAM filter. I pretty much doubt that anyone "out here" could possibly have the level of access required to do any meaningful diagnostics. Unless I misunderstand your request...
    Good luck!
    Occam's Razor nearly always applies when troubleshooting technology issues!
    If anyone has been helpful to you, please show your appreciation by clicking the button inside of their post. Please click here and read, along with the threads to which it links, for helpful information to guide you as you proceed. I always recommend that you treat your BlackBerry like any other computing device, including using a regular backup schedule...click here for an article with instructions.
    Join our BBM Channels
    BSCF General Channel
    PIN: C0001B7B4   Display/Scan Bar Code
    Knowledge Base Updates
    PIN: C0005A9AA   Display/Scan Bar Code

Maybe you are looking for