diff --git a/packers/packer.yar b/packers/packer.yar index 7757ede9..7d5a1280 100644 --- a/packers/packer.yar +++ b/packers/packer.yar @@ -17191,6 +17191,8 @@ condition: } +/* false positive - https://www.zscaler.com/blogs/research/your-windows-8-packed + rule Armadillov1xxv2xx { meta: @@ -17200,7 +17202,7 @@ strings: condition: $a0 at pe.entry_point -} +}*/ rule HACKSTOPv111c diff --git a/packers/peid.yar b/packers/peid.yar index 2d726024..a45498c5 100644 --- a/packers/peid.yar +++ b/packers/peid.yar @@ -5928,6 +5928,7 @@ rule Armadillo_v310: PEiD } +/* false positive - https://www.zscaler.com/blogs/research/your-windows-8-packed rule Armadillo_v1xx_v2xx_additional: PEiD { strings: @@ -5935,7 +5936,7 @@ rule Armadillo_v1xx_v2xx_additional: PEiD condition: $a at pe.entry_point -} +}*/ rule DOS32_v33_DOS_Extender_and_Loader_Hint_DOS_EP: PEiD { @@ -39949,6 +39950,7 @@ rule MCLOCK_13: PEiD } +/* false positive - https://www.zscaler.com/blogs/research/your-windows-8-packed rule Armadillo_v1xx_v2xx: PEiD { strings: @@ -39956,7 +39958,7 @@ rule Armadillo_v1xx_v2xx: PEiD condition: $a at pe.entry_point -} +}*/ rule Lattice_C_v101: PEiD {