Hi, I'm using zimbra. I triggered the antivirus using a EICAR file. Maybe you can help me.
The logs is:
Sep 30 17:01:03 zimbraserver postfix/smtpd[11557]: 535721E1E6C: client=pccenofi35.ldomain.local[192.0.0.135], sasl_method=LOGIN, sasl_username=[email protected]
Sep 30 17:01:03 zimbraserver postfix/smtpd[11557]: message repeated 2 times: [ 535721E1E6C: client=pccenofi35.ldomain.local[192.0.0.135], sasl_method=LOGIN, sasl_username=[email protected]]
Sep 30 17:01:03 zimbraserver postfix/cleanup[19459]: 535721E1E6C: message-id=[email protected]
Sep 30 17:01:03 zimbraserver postfix/cleanup[19459]: message repeated 2 times: [ 535721E1E6C: message-id=[email protected]]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 535721E1E6C: from=[email protected], size=3454, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: message repeated 2 times: [ 535721E1E6C: from=[email protected], size=3454, nrcpt=1 (queue active)]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: connect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: message repeated 2 times: [ connect from localhost[127.0.0.1]]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: 6CE4E1E1E71: client=localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: message repeated 2 times: [ 6CE4E1E1E71: client=localhost[127.0.0.1]]
Sep 30 17:01:03 zimbraserver postfix/cleanup[19459]: 6CE4E1E1E71: message-id=[email protected]
Sep 30 17:01:03 zimbraserver postfix/cleanup[19459]: message repeated 2 times: [ 6CE4E1E1E71: message-id=[email protected]]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: disconnect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 6CE4E1E1E71: from=<>, size=4209, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: disconnect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 6CE4E1E1E71: from=<>, size=4209, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: disconnect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 6CE4E1E1E71: from=<>, size=4209, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: connect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: message repeated 2 times: [ connect from localhost[127.0.0.1]]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: 73C6D1E1E73: client=localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: message repeated 2 times: [ 73C6D1E1E73: client=localhost[127.0.0.1]]
Sep 30 17:01:03 zimbraserver postfix/cleanup[19459]: 73C6D1E1E73: message-id=[email protected]
Sep 30 17:01:03 zimbraserver postfix/cleanup[19459]: message repeated 2 times: [ 73C6D1E1E73: message-id=[email protected]]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: disconnect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 73C6D1E1E73: from=[email protected], size=2513, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: disconnect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 73C6D1E1E73: from=[email protected], size=2513, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: disconnect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 73C6D1E1E73: from=[email protected], size=2513, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/smtp[20923]: 73C6D1E1E73: to=[email protected], relay=none, delay=0.01, delays=0/0/0/0, dsn=5.4.6, status=bounced (mail for zimbraserver.ldomain.local loops back to myself)
Sep 30 17:01:03 zimbraserver postfix/smtp[20923]: message repeated 2 times: [ 73C6D1E1E73: to=[email protected], relay=none, delay=0.01, delays=0/0/0/0, dsn=5.4.6, status=bounced (mail for zimbraserver.ldomain.local loops back to myself)]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: connect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: message repeated 2 times: [ connect from localhost[127.0.0.1]]
Sep 30 17:01:03 zimbraserver postfix/cleanup[19459]: 764B91E1E75: message-id=[email protected]
Sep 30 17:01:03 zimbraserver postfix/cleanup[19459]: message repeated 2 times: [ 764B91E1E75: message-id=[email protected]]
Sep 30 17:01:03 zimbraserver postfix/bounce[20924]: 73C6D1E1E73: sender non-delivery notification: 764B91E1E75
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 764B91E1E75: from=<>, size=4492, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/bounce[20924]: 73C6D1E1E73: sender non-delivery notification: 764B91E1E75
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: 77B3F1E1E74: client=localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 764B91E1E75: from=<>, size=4492, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/bounce[20924]: 73C6D1E1E73: sender non-delivery notification: 764B91E1E75
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 764B91E1E75: from=<>, size=4492, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: 77B3F1E1E74: client=localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: 77B3F1E1E74: client=localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 73C6D1E1E73: removed
Sep 30 17:01:03 zimbraserver postfix/cleanup[19459]: 77B3F1E1E74: message-id=[email protected]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 73C6D1E1E73: removed
Sep 30 17:01:03 zimbraserver postfix/cleanup[19459]: 77B3F1E1E74: message-id=[email protected]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 73C6D1E1E73: removed
Sep 30 17:01:03 zimbraserver postfix/cleanup[19459]: 77B3F1E1E74: message-id=[email protected]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: disconnect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: disconnect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 77B3F1E1E74: from=[email protected], size=1322, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/amavisd/smtpd[17226]: disconnect from localhost[127.0.0.1]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 77B3F1E1E74: from=[email protected], size=1322, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 77B3F1E1E74: from=[email protected], size=1322, nrcpt=1 (queue active)
Sep 30 17:01:03 zimbraserver postfix/smtp[20923]: 764B91E1E75: to=[email protected], relay=none, delay=0.01, delays=0.01/0/0/0, dsn=5.4.6, status=bounced (mail for zimbraserver.ldomain.local loops back to myself)
Sep 30 17:01:03 zimbraserver postfix/smtp[20923]: message repeated 2 times: [ 764B91E1E75: to=[email protected], relay=none, delay=0.01, delays=0.01/0/0/0, dsn=5.4.6, status=bounced (mail for zimbraserver.ldomain.local loops back to myself)]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 764B91E1E75: removed
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: message repeated 2 times: [ 764B91E1E75: removed]
Sep 30 17:01:03 zimbraserver postfix/smtp[20566]: 535721E1E6C: to=[email protected], relay=127.0.0.1[127.0.0.1]:10026, delay=0.21, delays=0.06/0/0.01/0.14, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=25930-18 - INFECTED: Eicar-Test-Signature)
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 535721E1E6C: removed
Sep 30 17:01:03 zimbraserver postfix/smtp[20566]: 535721E1E6C: to=[email protected], relay=127.0.0.1[127.0.0.1]:10026, delay=0.21, delays=0.06/0/0.01/0.14, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=25930-18 - INFECTED: Eicar-Test-Signature)
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 535721E1E6C: removed
Sep 30 17:01:03 zimbraserver postfix/smtp[20566]: 535721E1E6C: to=[email protected], relay=127.0.0.1[127.0.0.1]:10026, delay=0.21, delays=0.06/0/0.01/0.14, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=25930-18 - INFECTED: Eicar-Test-Signature)
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 535721E1E6C: removed
Sep 30 17:01:03 zimbraserver postfix/lmtp[19468]: 77B3F1E1E74: to=[email protected], relay=svcenmbx01.ldomain.local[192.0.0.21]:7025, delay=0.15, delays=0.01/0/0.09/0.05, dsn=2.1.5, status=sent (250 2.1.5 Delivery OK)
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 77B3F1E1E74: removed
Sep 30 17:01:03 zimbraserver postfix/lmtp[19468]: 77B3F1E1E74: to=[email protected], relay=svcenmbx01.ldomain.local[192.0.0.21]:7025, delay=0.15, delays=0.01/0/0.09/0.05, dsn=2.1.5, status=sent (250 2.1.5 Delivery OK)
Sep 30 17:01:03 zimbraserver postfix/lmtp[19468]: 77B3F1E1E74: to=[email protected], relay=svcenmbx01.ldomain.local[192.0.0.21]:7025, delay=0.15, delays=0.01/0/0.09/0.05, dsn=2.1.5, status=sent (250 2.1.5 Delivery OK)
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 77B3F1E1E74: removed
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 77B3F1E1E74: removed
Sep 30 17:01:03 zimbraserver postfix/lmtp[19465]: 6CE4E1E1E71: to=[email protected], relay=svcenmbx01.ldomain.local[192.0.0.21]:7025, delay=0.21, delays=0.02/0/0.1/0.09, dsn=2.1.5, status=sent (250 2.1.5 Delivery OK)
Sep 30 17:01:03 zimbraserver postfix/lmtp[19465]: message repeated 2 times: [ 6CE4E1E1E71: to=[email protected], relay=svcenmbx01.ldomain.local[192.0.0.21]:7025, delay=0.21, delays=0.02/0/0.1/0.09, dsn=2.1.5, status=sent (250 2.1.5 Delivery OK)]
Sep 30 17:01:03 zimbraserver postfix/qmgr[15025]: 6CE4E1E1E71: removed
But nothing are listed in sendmailanalyzer's amavis statspage. Same thing with spam.
Sep 30 17:10:30 svcenmta01 postfix/smtpd[11557]: message repeated 2 times: [ disconnect from unknown[192.168.0.17]]
Sep 30 17:10:43 svcenmta01 postfix/smtpd[11557]: connect from pccenofi35.ldomain.local[192.168.0.135]
Sep 30 17:10:43 svcenmta01 postfix/smtpd[11557]: message repeated 2 times: [ connect from pccenofi35.ldomain.local[192.168.0.135]]
Sep 30 17:10:43 svcenmta01 postfix/smtpd[11557]: Anonymous TLS connection established from pccenofi35.ldomain.local[192.168.0.135]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Sep 30 17:10:43 svcenmta01 postfix/smtpd[11557]: message repeated 2 times: [ Anonymous TLS connection established from pccenofi35.ldomain.local[192.168.0.135]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)]
Sep 30 17:10:43 svcenmta01 postfix/smtpd[11557]: NOQUEUE: filter: RCPT from pccenofi35.ldomain.local[192.168.0.135]: [email protected]: Sender address triggers FILTER smtp-amavis:[127.0.0.1]:10026; from=[email protected] to=[email protected] proto=ESMTP helo=
Sep 30 17:10:43 svcenmta01 postfix/smtpd[11557]: message repeated 2 times: [ NOQUEUE: filter: RCPT from pccenofi35.ldomain.local[192.168.0.135]: [email protected]: Sender address triggers FILTER smtp-amavis:[127.0.0.1]:10026; from=[email protected] to=[email protected] proto=ESMTP helo=]
Sep 30 17:10:43 svcenmta01 postfix/smtpd[11557]: CDBF11E1E6C: client=pccenofi35.ldomain.local[192.168.0.135], sasl_method=LOGIN, sasl_username=[email protected]
Sep 30 17:10:43 svcenmta01 postfix/smtpd[11557]: message repeated 2 times: [ CDBF11E1E6C: client=pccenofi35.ldomain.local[192.168.0.135], sasl_method=LOGIN, sasl_username=[email protected]]
Sep 30 17:10:43 svcenmta01 postfix/cleanup[26180]: CDBF11E1E6C: message-id=[email protected]
Sep 30 17:10:43 svcenmta01 postfix/cleanup[26180]: message repeated 2 times: [ CDBF11E1E6C: message-id=[email protected]]
Sep 30 17:10:43 svcenmta01 postfix/qmgr[15025]: CDBF11E1E6C: from=[email protected], size=3499, nrcpt=1 (queue active)
Sep 30 17:10:43 svcenmta01 postfix/qmgr[15025]: message repeated 2 times: [ CDBF11E1E6C: from=[email protected], size=3499, nrcpt=1 (queue active)]
Sep 30 17:10:43 svcenmta01 postfix/dkimmilter/smtpd[26184]: connect from localhost[127.0.0.1]
Sep 30 17:10:43 svcenmta01 postfix/dkimmilter/smtpd[26184]: message repeated 2 times: [ connect from localhost[127.0.0.1]]
Sep 30 17:10:43 svcenmta01 postfix/dkimmilter/smtpd[26184]: E82171E1E71: client=localhost[127.0.0.1]
Sep 30 17:10:43 svcenmta01 postfix/dkimmilter/smtpd[26184]: message repeated 2 times: [ E82171E1E71: client=localhost[127.0.0.1]]
Sep 30 17:10:43 svcenmta01 postfix/cleanup[26180]: E82171E1E71: message-id=[email protected]
Sep 30 17:10:43 svcenmta01 postfix/cleanup[26180]: message repeated 2 times: [ E82171E1E71: message-id=[email protected]]
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: E82171E1E71: from=[email protected], size=3961, nrcpt=1 (queue active)
Sep 30 17:10:44 svcenmta01 postfix/dkimmilter/smtpd[26184]: disconnect from localhost[127.0.0.1]
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: E82171E1E71: from=[email protected], size=3961, nrcpt=1 (queue active)
Sep 30 17:10:44 svcenmta01 postfix/dkimmilter/smtpd[26184]: disconnect from localhost[127.0.0.1]
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: E82171E1E71: from=[email protected], size=3961, nrcpt=1 (queue active)
Sep 30 17:10:44 svcenmta01 postfix/dkimmilter/smtpd[26184]: disconnect from localhost[127.0.0.1]
Sep 30 17:10:44 svcenmta01 postfix/smtp[26181]: CDBF11E1E6C: to=[email protected], relay=127.0.0.1[127.0.0.1]:10026, delay=0.26, delays=0.07/0/0/0.18, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10030): 250 2.0.0 Ok: queued as E82171E1E71)
Sep 30 17:10:44 svcenmta01 postfix/smtp[26181]: message repeated 2 times: [ CDBF11E1E6C: to=[email protected], relay=127.0.0.1[127.0.0.1]:10026, delay=0.26, delays=0.07/0/0/0.18, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10030): 250 2.0.0 Ok: queued as E82171E1E71)]
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: CDBF11E1E6C: removed
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: message repeated 2 times: [ CDBF11E1E6C: removed]
Sep 30 17:10:44 svcenmta01 postfix/amavisd/smtpd[26191]: connect from localhost[127.0.0.1]
Sep 30 17:10:44 svcenmta01 postfix/amavisd/smtpd[26191]: message repeated 2 times: [ connect from localhost[127.0.0.1]]
Sep 30 17:10:44 svcenmta01 postfix/amavisd/smtpd[26191]: C71221E1E6C: client=localhost[127.0.0.1]
Sep 30 17:10:44 svcenmta01 postfix/amavisd/smtpd[26191]: message repeated 2 times: [ C71221E1E6C: client=localhost[127.0.0.1]]
Sep 30 17:10:44 svcenmta01 postfix/cleanup[26180]: C71221E1E6C: message-id=[email protected]
Sep 30 17:10:44 svcenmta01 postfix/cleanup[26180]: message repeated 2 times: [ C71221E1E6C: message-id=[email protected]]
Sep 30 17:10:44 svcenmta01 postfix/amavisd/smtpd[26191]: disconnect from localhost[127.0.0.1]
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: C71221E1E6C: from=[email protected], size=4436, nrcpt=1 (queue active)
Sep 30 17:10:44 svcenmta01 postfix/amavisd/smtpd[26191]: disconnect from localhost[127.0.0.1]
Sep 30 17:10:44 svcenmta01 postfix/amavisd/smtpd[26191]: disconnect from localhost[127.0.0.1]
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: C71221E1E6C: from=[email protected], size=4436, nrcpt=1 (queue active)
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: C71221E1E6C: from=[email protected], size=4436, nrcpt=1 (queue active)
Sep 30 17:10:44 svcenmta01 postfix/smtp[26187]: E82171E1E71: to=[email protected], relay=127.0.0.1[127.0.0.1]:10032, delay=0.88, delays=0.08/0/0.01/0.79, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=15303-02 - spam)
Sep 30 17:10:44 svcenmta01 postfix/smtp[26187]: E82171E1E71: to=[email protected], relay=127.0.0.1[127.0.0.1]:10032, delay=0.88, delays=0.08/0/0.01/0.79, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=15303-02 - spam)
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: E82171E1E71: removed
Sep 30 17:10:44 svcenmta01 postfix/smtp[26187]: E82171E1E71: to=[email protected], relay=127.0.0.1[127.0.0.1]:10032, delay=0.88, delays=0.08/0/0.01/0.79, dsn=2.7.0, status=sent (250 2.7.0 Ok, discarded, id=15303-02 - spam)
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: E82171E1E71: removed
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: E82171E1E71: removed
Sep 30 17:10:44 svcenmta01 postfix/smtp[26192]: C71221E1E6C: to=[email protected], relay=none, delay=0.01, delays=0.01/0/0/0, dsn=5.4.6, status=bounced (mail for svcenmta01.ldomain.local loops back to myself)
Sep 30 17:10:44 svcenmta01 postfix/smtp[26192]: message repeated 2 times: [ C71221E1E6C: to=[email protected], relay=none, delay=0.01, delays=0.01/0/0/0, dsn=5.4.6, status=bounced (mail for svcenmta01.ldomain.local loops back to myself)]
Sep 30 17:10:44 svcenmta01 postfix/cleanup[26180]: CB5D81E1E73: message-id=[email protected]
Sep 30 17:10:44 svcenmta01 postfix/cleanup[26180]: message repeated 2 times: [ CB5D81E1E73: message-id=[email protected]]
Sep 30 17:10:44 svcenmta01 postfix/bounce[27320]: C71221E1E6C: sender non-delivery notification: CB5D81E1E73
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: CB5D81E1E73: from=<>, size=6415, nrcpt=1 (queue active)
Sep 30 17:10:44 svcenmta01 postfix/bounce[27320]: C71221E1E6C: sender non-delivery notification: CB5D81E1E73
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: CB5D81E1E73: from=<>, size=6415, nrcpt=1 (queue active)
Sep 30 17:10:44 svcenmta01 postfix/bounce[27320]: C71221E1E6C: sender non-delivery notification: CB5D81E1E73
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: CB5D81E1E73: from=<>, size=6415, nrcpt=1 (queue active)
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: C71221E1E6C: removed
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: message repeated 2 times: [ C71221E1E6C: removed]
Sep 30 17:10:44 svcenmta01 postfix/smtp[26192]: CB5D81E1E73: to=[email protected], relay=none, delay=0.01, delays=0.01/0/0/0, dsn=5.4.6, status=bounced (mail for svcenmta01.ldomain.local loops back to myself)
Sep 30 17:10:44 svcenmta01 postfix/smtp[26192]: message repeated 2 times: [ CB5D81E1E73: to=[email protected], relay=none, delay=0.01, delays=0.01/0/0/0, dsn=5.4.6, status=bounced (mail for svcenmta01.ldomain.local loops back to myself)]
Sep 30 17:10:44 svcenmta01 postfix/qmgr[15025]: CB5D81E1E73: removed
Thanks in advance