Messages using Content-Transfer-Encoding: base64
I have started to notice phishing messages that are using Content-Transfer-Encoding: base64 to obfuscate the text in the message. This then makes rules not function unless you translater the words into base64.
Is it possible for PhishER to decode Base64 and check the resultant text and apply rules?
-
Hi Charles, I submitted a feature request for this exact issue but my request was a little bit different. Yara provides a modifier for base64 support (https://yara.readthedocs.io/en/stable/writingrules.html#base64-strings As of the most recent update to PhishER, they (finally) support a version of Yara that allows you to make use of this modifier.
Por favor, entrar para comentar.
Comentários
2 comentários