YARA rules
yara
yara64rule Yara_example {
meta:
description = "Yara example"
author = "PMAT"
date = "2021-10-15"
strings:
$string1="YOURTHEMANNOWDOG" ascii
$string2="nim"
$PE_magic_byte = "MZ"
$sus_hex_string={ FF E4 ?? 00 FF}
condition:
$PE_magic_byte at 0 and
($string1 or $string2) or
$sus_hex_string
}


Last updated