Skip to content

fix: compile index.yar under yara-x (type and regex) - #461

Open
Tito0015 wants to merge 2 commits into
Yara-Rules:masterfrom
Tito0015:fix/yara-x-issue-451
Open

Tito0015 wants to merge 2 commits into
Yara-Rules:masterfrom
Tito0015:fix/yara-x-issue-451

Conversation

@Tito0015

Copy link
Copy Markdown

Fixes #451

Summary

  • E002 — malware/APT_CrashOverride.yar: replace pe.exports(Crash) & pe.characteristics with pe.exports(Crash) and pe.characteristics != 0.
  • E014 — malware/RAT_PlugX.yar: add missing path separator before VMwareCplLauncher (\\V not \V).
  • E014 — malware/RAT_PoetRATPython.yar: remove trailing | that made the regex match empty strings.
  • E014 — webshells/Wshell_ChineseSpam.yar: escape literal { as \{.

CrashOverride note

pe.exports() is boolean in yara-x; legacy YARA coerced the old & conjunct. We use and pe.characteristics != 0 for type-safe parity with that behavior rather than guessing a specific PE characteristics bit mask or deleting the clause. Valid PE files almost never have characteristics == 0, so this remains a no-op once the export check passes.

Verification

  • yr compile index.yar — exit 0
  • Legacy yara64.exe index.yar dummy.bin — exit 0 (no syntax errors on stderr)

Engines tested: yara-x-cli 1.21.0 (yr -V); YARA 4.5.5 (yara64.exe --version, VirusTotal v4.5.5-2368-win64.zip fallback).

Replace bitwise & between boolean export check and integer characteristics with type-safe and != 0 for yara-x E002.
PlugX path separator, PoetRAT empty alternative, ChineseSpam escaped brace.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] yara-x error compile rules

1 participant