Categories: Antispam Cloud

How to Proactively Block Dangerous Attachments

With nettigritty’s Antispam Cloud you can block a very large amount of malware, yet there can sometimes be new Malware campaigns that are able to evade all Antivirus and Anti-Spam filters. Due to this we would highly recommend to enable the “Block attachments that contain hidden executables” option by default for all your domains. This is already enabled by default.

This is highly effective against so called 0-day malware. Once this is enabled, messages that are sent with executables within a compressed archive (.zip, .rar etc) are rejected and quarantined.

Be Advised: The Block attachments that contain hidden executables option will only affect messages that contain an executable within a compressed archive. The check is executed 3 layers deep into archived messages.

Block attachments that contain hidden executables by default for all domains
To block dangerous by default for all your existing domains and future domains that you will add, go to: Super-Admin Dashboard > Outgoing > Default Domain Settings. From here on, click on the Attachment Restrictions tab from the left hand side menu and tick check the tickbox in front of “Block attachments that contain hidden executables”.

Be advised that this will automatically enable the Block attachments that contain hidden executables feature to all domains that have the default value (and not a custom setting for this) and future added domains. This can be overruled at domain level.

Block attachments that contain hidden executables at domain level
To block dangerous attachments for a specific domain only, you will need to, login as the domain user and go to: Domain Dashboard > Email Restrictions > Attachment Restrictions and check the tickbox in front of “Block attachments that contain hidden executables”.

Block certain extensions
It’s also possible to block messages based on their attachment. By default nettigritty’s Antispam Cloud already pre-fills a selected list of attachments that are blocked. However you can of course add / remove any other attachment file types that are deemed necessary.

Block Password Protected Archives
Spammers often use a trick by sending password encrypted archives in the hope to bypass some filters, and saying the “password” in the body of the spam message. These messages can be blocked by enabling the “Block Password Protected Attachments” feature. This can be enabled at both the default level and domain level as mentioned above.

Enable Scanned Link Extensions
This option not enabled by default, allows you to configure your domain(s) to have the ability to download files from links in the email that contain a specific extension. This is extremely powerful when it comes to messages that have direct links in the emails that direct to a malicious file. For example http://bad.example.com/mybadfile.zip.

By default the zip file is not downloaded, however with this enabled, it allows our systems to download the .zip file and scan with our engines.

We recommend you enable this where possible with the following settings:

Message link size limit (in bytes): 2000000
Add the following to the current list of scanned extensions: zip,rar,jar,js,java,aspx,doc,docm,xls,xlsm
Note, for redirect links (commonly seen in Invoice related spam), an extra link-follow option is needed. This currently needs to be enabled only by our support team. If you require this, please contact us.

Admin

Share
Published by
Admin

Recent Posts

Enable Outgoing SMTP Server Authentication

All our servers need you to enable outgoing SMTP server authentication to be able to…

4 years ago

Plesk Tutorials – How to configure DNS for a domain in Plesk

Learn how to configure and check your DNS settings in Plesk. After you registered your…

5 years ago

cPanel Tutorials – Force HTTPS Redirect

This video demonstrates how to use the Force HTTPS Redirect feature. This feature allows you…

5 years ago

cPanel Tutorials – MultiPHP Manager

Use cPanel's MultiPHP Manager to manage your domains' PHP version. Being able to manage the…

5 years ago

Email account setup in Outlook 2016

This tutorial will help you to configure Microsoft Outlook 2016 for an email account. Step…

5 years ago

Message Queueing

Generally emails are directly delivered to the destination server. However, if the delivery attempt to…

5 years ago