Closed aleksf closed 4 years ago
Please disregard, apparently was related to testing with Mutt MUA. Extraction with YaRa dispatcher works with following config:
[core]
log_level: DEBUG
providers: dirmon
archivers: filedir
connectors: filedir,stdout
dispatchers: yara
[dirmon]
source_dir=/home/stoq/Maildir/new
[filedir]
archive_dir=/home/stoq/analysis/archive
results_dir=/home/stoq/analysis/results
[smtp]
always_dispatch=hash,exif,mimetype,vtmis-search,tika
archive_attachments=True
extract_iocs=True
omit_body=True
[yara]
dispatch_rules=/home/stoq/stoqyara/dispatcher.yar
worker_rules=/home/stoq/stoqyara/rules/index-custom.yar
[vtmis-search]
apikey=
Hi, I am new to Stoq. Only started playing with it yesterday. Stoq installed from Git. Python 3.6.9.
I am using command below to process Maildir files with further dispatch to YaRa. I am testing with single RFC822-compliant forwarded email sample that contains ZIP attachment. ZIP contains PE. What I am trying to achieve is trivial:
Command produces inconsistent results. In most cases it fails with error:
On every run mimetype is identified properly by plugin and in payload meta: payload meta:
mimetype plugin:
Occasionally it works and I get PE extracted and archived. Please help to identify the issue.