Skip to content

[BUG] yara-x error compile rules #451

@xCEVre

Description

@xCEVre

yara-x error compile rules:

./index_gen.sh

   **************************
          Yara-Rules
        Index generator
   **************************
[+] Generating antidebug_antivm index...
[+] Generating capabilities index...
[+] Generating crypto index...
[+] Generating cve_rules index...
[+] Generating email index...
[+] Generating exploit_kits index...
[+] Generating maldocs index...
[+] Generating malware index...
[+] Generating mobile_malware index...
[+] Generating packers index...
[+] Generating webshells index...
[+] Generating index_w_mobile...
[+] Generating index...

yr scan index.yar ~/ -r

error[E002]: wrong type
  --> ./malware/APT_CrashOverride.yar:10:6
   |
10 |   pe.exports("Crash") & pe.characteristics
   |      ^^^^^^^^^^^^^^^^ expression should be `integer`, but it is `boolean`
   |
error[E014]: invalid regular expression
  --> ./malware/RAT_PlugX.yar:59:41
   |
59 |   $data=/\\AppData\\Roaming\\[0-9]{9,12}\VMwareCplLauncher\.exe/
   |                                         ^^ unrecognized escape sequence
   |
   = note: did you mean `\\V` instead of `\V`?
error[E014]: invalid regular expression
  --> ./malware/RAT_PoetRATPython.yar:13:9
   |
13 |         $grammer_massacre = /BADD|Bad Error Happened|/
   |         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ this regexp can match empty strings
   |
error[E014]: invalid regular expression
  --> ./webshells/Wshell_ChineseSpam.yar:17:42
   |
17 |         $c = /if ?\(\$_POST\[Submit\]\) ?{/
   |                                          ^ unclosed counted repetition
   |
   = note: did you mean `\{` instead of `{`?

yr -V

yara-x-cli 1.3.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions