~4m21:08
Taylor Walton

Shuffle and Yara - Find Malware In Your Email Attachements!

Mar 21, 2022

Read: ~5m · You save: 16 min

Shuffle and Yara - Find Malware In Your Email Attachments!

This article details a workflow designed to automatically scan email attachments for malware using the open-source tool Yara, orchestrated by the automation platform Shuffle. The process involves collecting emails, analyzing attachments with Yara, and creating alerts in The Hive for security teams.

Workflow Overview

The described workflow begins with collecting emails, specifically focusing on attachments. These attachments are then passed to a Yara subflow for analysis. If Yara detects malicious content based on its signature matching, an alert is generated within The Hive. The malicious attachment is also added to the alert for further investigation by security analysts.

A key component of this workflow is the use of the iCAR file, a benign file designed to test malware detection tools. This allows for safe testing of the detection capabilities without introducing actual malware.

The workflow can be broken down into the following stages:

  1. Email Collection: Emails are collected, with a specific focus on including attachment data.
  2. Attachment Upload: Attachments are uploaded to Shuffle for storage and referencing.
  3. Yara Scanning: The uploaded attachments are scanned by the Yara application within Shuffle.
  4. Conditional Alerting: If Yara identifies a match (indicating potential malware), an alert is created in The Hive.
  5. Attachment Association: The identified malicious attachment is added to the corresponding alert in The Hive.
  6. Optional: Email Deletion: If the attachment is confirmed as malicious, the original email can be automatically deleted from the user's inbox.

Implementation Details

Email Collection with Outlook

The process starts by using the Outlook app within Shuffle to retrieve emails. The "Get Emails" action is configured to target the "Sent" folder, with a limit of one email and set to retrieve only unread messages. Crucially, "Include Attachment Data" and "Upload Attachments to Shuffle" are set to true. This ensures that the attachment's content is accessible within Shuffle for subsequent analysis.

Upon successful execution, Shuffle stores the attachment, assigning it a unique UUID. This file can then be viewed in the Shuffle admin tab under "Files."

Subflow for Yara Scanning

To manage the data flow more effectively, the email collection is passed to a dedicated subflow named "Demo Yara Scan." This subflow is triggered by a "Shuffle Workflow" trigger. The execution arguments passed to this subflow include the "messages list" from the collected email, using a .# notation to indicate that the entire list should be processed.

Within the "Demo Yara Scan" subflow, the "Repeat Email" node processes the incoming data. The Yara application is then integrated using the "Analyze File" action. The file_id for Yara scanning is dynamically referenced from the attachment.uid of the collected email. A timeout of 15 seconds is set for the Yara scan.

Yara Detection and Alerting

When Yara scans the iCARtest.txt file, it triggers five rules, including malware_w_icar. This positive match indicates that the file is flagged as potentially malicious. The number of matched rules (five in this instance) serves as a threshold for creating an alert.

A condition is implemented before creating an alert in The Hive. This condition checks if the number of matches in the Yara scan result is greater than zero. This is achieved using a Liquid expression that evaluates the size of the matches list within the Yara scan output. If the size is not equal to zero, the condition is met, and an alert is generated.

The "Create Alert" action in The Hive is configured with the following details:

  • Type: Yara
  • Source: Email
  • Source Reference: The message_id from the email.
  • Title: Yara match on email attachment
  • Description: Dynamically constructed using the sender's email address (header.from) and a message indicating a malicious attachment.

Associating Attachments and Further Analysis

Following the alert creation, an "Add Attachment" action is configured to associate the malicious file with the alert in The Hive. This uses the alert_id from the previously created alert and the file_id from the Yara scan.

Once the attachment is added to The Hive, it becomes an observable. This allows for further analysis, such as submitting the file to VirusTotal for a comprehensive scan. The results from VirusTotal can then be reviewed within The Hive. Analysts can also download the attachment for offline analysis in sandboxed environments.

Optional Email Deletion

As a final step, an optional "Delete Email" action can be added to automatically remove the malicious email from the user's inbox. This action requires the message_id of the email. A caution is advised, as this step should only be implemented if Yara's detection is highly reliable to avoid accidental deletion of legitimate emails due to false positives.

Automation and Scheduling

The "Collect Email" workflow can be scheduled to run periodically, for example, every minute, by setting a schedule of 60 seconds. This ensures continuous monitoring of incoming emails for malicious attachments.

The two workflows created in this demonstration have been published on shuffler.io under the "opensecure" profile, allowing users to download and implement them directly into their own Shuffle environments.

Introduction to Shuffle and Yara

Introduction to using Shuffle and Yara for scanning email attachments. Yara is an open-source tool for signature-based malware detection, and it's available as an app within Shuffle, allowing for an integrated workflow.

  • Yara is an open-source tool for signature-based malware detection.
  • Shuffle provides Yara as an integrated app.
  • The workflow involves collecting emails, scanning attachments with Yara, and alerting The Hive.

Collecting Emails with Shuffle

Setting up the email collection process using Shuffle's Outlook app. The workflow is configured to get unread emails from the sent folder, include attachment data, and upload attachments to Shuffle for further processing.

  • The Outlook app's 'Get Emails' action is used.
  • Emails are collected from the 'Sent' folder due to Microsoft restrictions.
  • Key settings include 'Amount: 1', 'Unread: True', 'Include Attachment Data: True', and 'Upload Attachments to Shuffle: True'.

Creating a Subflow for Yara Scanning

Structuring the workflow by passing email data to a subflow for Yara scanning. This involves creating a 'Demo Yara Scan' workflow and using a Shuffle workflow trigger to pass the collected email messages list to it.

  • A subflow is created to handle Yara scanning.
  • A Shuffle workflow trigger connects the email collection workflow to the subflow.
  • The 'messages' list from the collected email is passed to the subflow using a '.#' notation.

Performing Yara Scan on Attachments

Integrating the Yara app within the subflow to analyze email attachments. The 'Analyze File' action is used, referencing the attachment's file ID stored by Shuffle. The workflow checks for positive Yara hits.

  • The Yara app's 'Analyze File' action is used.
  • The 'File ID' is referenced using the attachment's UUID (e.g., repeat_email.attachment.uid).
  • A timeout can be set for the Yara scan.
  • The output shows the number of Yara rules triggered (e.g., 5 for an iCAR file).

Alerting The Hive on Malicious Files

Creating alerts in The Hive based on Yara scan results. A condition is set to only create an alert if Yara detects a match (number of matches > 0). The alert includes details like source, reference, title, and description.

  • The Hive app is used to create alerts.
  • An 'if' condition checks if the size of the 'matches' list from Yara is not equal to 0.
  • Alert details include type (Yara), source (Email), message ID, title ('Yara match on email attachment'), and description.
  • The alert is created only if Yara finds malicious content.

Adding Attachments to Hive Alerts

Adding the malicious attachment as an observable to the Hive alert for further investigation. The 'Create Alert File Observable' action links the attachment to the specific alert ID generated previously.

  • The Hive app's 'Create Alert File Observable' action is used.
  • The 'Alert ID' is referenced from the previous 'Create Alert' step.
  • The 'File ID' from the Yara scan is used to identify the attachment.
  • The attachment is added to the Hive alert for analyst review.

Advanced Analysis and Email Deletion

Performing further analysis by submitting the attachment to VirusTotal via Cortex and optionally deleting the malicious email. A caution is advised regarding potential false positives when deleting emails.

  • The attachment can be submitted to VirusTotal through Cortex for analysis.
  • VirusTotal results can indicate a high number of positive hits.
  • The malicious email can be deleted from the user's inbox using the Outlook app's 'Delete Email' action.
  • Caution is advised when deleting emails due to the risk of false positives.

Automation and Workflow Availability

Automating the workflow by scheduling email collection and making the workflows available for download. The 'Collect Email' workflow can be set to run periodically (e.g., every minute).

  • The 'Collect Email' workflow can be scheduled to run automatically.
  • The schedule is set in seconds (e.g., 60 seconds for every minute).
  • The created workflows are published on shuffler.io for users to download and implement.
This analysis saves 16 min of your time (21:08 → ~5m)