malware detection changes

Hello,

As of yesterday morning (7/9/15 0800 PST) we were suddenly having zip files blocked on outgoing.  Message received:  "The attachment has been blocked by Office 365.  Please contact xxxx if you believe the attachment was safe." (I am xxxx).  This was from an employee to another employee, with the sender being off-site using a third party wireless network.   User said they were able to send very similar zip file (made some small edits this morning to one sent earlier) the day before.  We have malware filter set to default (lowest).  Tried changing file extension and resending; no luck (wasn't in the list of blocked extensions).  Anyone aware of any updates made overnight that might be the problem?

Thanks for any help you can provide!

July 10th, 2015 2:29pm

Hi 

Just check if the blocked zipped files is password protected.

Most of the scanning filters will block the  password protected zip files due to security reasons.

since the scanning engines will not be able to decry-pt   password protected zip files .

Solution :- Set exception in your malware filters for password protected ZIP files.And also check with office 365 support to add an exception for the password protected ZIP files.

Make sure that you add exceptions only for trusted domains,IP's. Ex: IP from banks, Governments and block rest all.

Risk Factor :- make sure that you have the scanning systems at your end points(end users PC's)  very strong and updated since these files will not be scanned at the server level.

Free Windows Admin Tool Kit Click here and download it now
July 11th, 2015 3:44am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics