Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
safe-mail: A Docker service used by analysts to extract and inspect suspicious .MSG, .EML, and documents
Everyone, I would like to introduce a new utility for Security Analysts that I built called safe-mail. You can find the repository here: https://github.com/swimlane/safe-mail


safe-mail is a Docker service used by analysts to upload, extract, and inspect suspicious .MSG, .EML, and documents. safe-mail can be used locally on your workstation or can be deployed for shared (or dedicated) use.

safe-mail has an API and a (limited) UI which allows a user to upload and retrieve artifacts generated by safe-mail.

safe-mail has the following features and functionality:

Message Features

• Upload EML and MSG mail messages as well as Microsoft Office documents themselves
• .MSG mail messages are Microsoft binary email format messages - typically from Microsoft Outlook clients
• Generates a PNG of the message itself named {filename}.png
• Extracts all embedded & attached images/attachments within the email message
• Provides a OCR text file of the generated mail message
• Generates a JSON file representing the mail message headers

Attachment/Document Features

• Extracts attachments of mail messages
• Generates an image & PDF of each attachment
• Attempts to extract any identified Macros within attachments and creates a JSON file representing the Macro code base
• PDF Documents will generate output from pdfid & pdfparser  tools
• ZIP attachments will extract the zip and return any files within the zip

Enjoy! I hope this helps you all on a daily basis!
🗣[
Unas](https://www.reddit.com/r/blueteamsec/comments/ftynlo/safemailadockerserviceusedbyanalyststo/)


🎖@malwr
I discovered a vulnerability in Safari that allowed unauthorized websites to access your camera on iOS and macOS
🗣ga-vu

Nice write up and it's cool to see the Apple program finally paying out bounties to non-blessed researchers!
👤SirensToGo

Nice
👤morrislesterszyslak

And this is why I use an adblocker. Though recently, I have stepped up my game with a PiHole as well.
👤thatvhstapeguy


🎖@malwr
Common Ports to Remember (credits: packetlife.net)
🗣ATTACKERSA

This very same printout follows me from desk-to-desk. Very good reference point to the not-so-easy-to-remember ports.
👤native_rooted

All u need to know is 20,22,21,25,389,3389,80,53
👤Calvimn

What about WhatsApp?
👤wthinastix


🎖@malwr
Starting Fires by Hacking 3D Printers, pt 1
🗣FlyingTriangle

And this is why I bought a printer without wifi. Nothing is perfect, but it's one less attack vector.
👤digitaldude87

I’m not surprised that they companies don’t institute security from the very beginning.
👤macgeek89

lp0 on fire all over again...
👤ihave10felonies


🎖@malwr