12-27-2017 10:42 PM - edited 03-08-2019 07:30 PM
Hello,
last week we received a wave of email with ACE archives. This archives contained a malicious EXE file.
Only the ACE files was scanned by AMP but the archive was not extracted to scan the content. As far as I know, archives should be extracted for scanning. Why is this not working with ACE files?
ACE archives are listed as an compressed file type ESA can handle.
Furthermore, we have a content filter which removes attached files with executeable ending (.exe, .bat, .scr, ...). This content filter is also working even the files are in an archive (zip, ...). But it's not working with ACE archives, why?
We run 2 C370 with the latest AsyncOS.
Regards,
Werner
Solved! Go to Solution.
12-27-2017 11:00 PM
Hi Werner,
Currently the content filtering on the ESA cannot scan within ace compressed files, this is being tracked under the below feature request.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCve02589/?reffering_site=dumpcr
If ace compressed files are not a business requirement, you could update the filters to block files based on .ace filename.
Regards,
Libin Varghese
12-28-2017 12:50 AM
ACE files are not uploaded for file analysis by AMP as per this:
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg50132/?reffering_site=dumpcr
12-27-2017 11:00 PM
Hi Werner,
Currently the content filtering on the ESA cannot scan within ace compressed files, this is being tracked under the below feature request.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCve02589/?reffering_site=dumpcr
If ace compressed files are not a business requirement, you could update the filters to block files based on .ace filename.
Regards,
Libin Varghese
12-27-2017 11:51 PM
Hi Libin,
thank you for your quick reply.
What about AMP? Shouldn't the ACE archive be extracted for AMP scanning?
Kind regards,
Werner
12-28-2017 12:50 AM
ACE files are not uploaded for file analysis by AMP as per this:
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg50132/?reffering_site=dumpcr
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide