Skip to content

remove hashes from rules (#625)

VirusTotal YARA-CI / Rules Analysis completed Nov 15, 2024 in 5s

Warnings found

Status Count
🟢 Files OK 984
🟠 Files with warnings 12
🔴 Files with errors 0
Files ignored 699

Annotations

Check warning on line 7 in rules/anti-static/base64/obfuscated_caller.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/anti-static/base64/obfuscated_caller.yara#L7

rule "base64_str_replace": string "$b" may slow down scanning

Check warning on line 6 in rules/anti-static/binary/opaque.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/anti-static/binary/opaque.yara#L6

rule "opaque_binary": string "$word_with_spaces" may slow down scanning

Check warning on line 7 in rules/anti-static/obfuscation/php.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/anti-static/obfuscation/php.yara#L7

rule "base64_str_replace": string "$b" may slow down scanning

Check warning on line 20 in rules/anti-static/obfuscation/php.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/anti-static/obfuscation/php.yara#L20

rule "gzinflate_str_replace": string "$b" may slow down scanning

Check warning on line 140 in rules/anti-static/obfuscation/php.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/anti-static/obfuscation/php.yara#L140

rule "php_str_replace_obfuscation": string "$o_recursive_single" may slow down scanning

Check warning on line 190 in rules/anti-static/obfuscation/php.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/anti-static/obfuscation/php.yara#L190

rule "php_short_concat": string "$concat" may slow down scanning

Check warning on line 202 in rules/anti-static/obfuscation/php.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/anti-static/obfuscation/php.yara#L202

rule "php_short_concat_multiple": string "$concat" may slow down scanning

Check warning on line 225 in rules/anti-static/obfuscation/python.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/anti-static/obfuscation/python.yara#L225

rule "python_long_hex": string "$assign" may slow down scanning

Check warning on line 237 in rules/anti-static/obfuscation/python.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/anti-static/obfuscation/python.yara#L237

rule "python_long_hex_multiple": string "$assign" may slow down scanning

Check warning on line 254 in rules/anti-static/obfuscation/python.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/anti-static/obfuscation/python.yara#L254

rule "python_hex_decimal": string "$trash" may slow down scanning

Check warning on line 460 in rules/anti-static/obfuscation/python.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/anti-static/obfuscation/python.yara#L460

rule "decompress_base64_entropy": string "$long_str" may slow down scanning

Check warning on line 7 in rules/c2/addr/ip.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/c2/addr/ip.yara#L7

rule "hardcoded_ip": string "$sus_ipv4" may slow down scanning

Check warning on line 8 in rules/c2/addr/ip.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/c2/addr/ip.yara#L8

rule "hardcoded_ip": string "$not_version" may slow down scanning

Check warning on line 27 in rules/c2/addr/ip.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/c2/addr/ip.yara#L27

rule "elf_hardcoded_ip": string "$sus_ipv4" may slow down scanning

Check warning on line 28 in rules/c2/addr/ip.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/c2/addr/ip.yara#L28

rule "elf_hardcoded_ip": string "$not_version" may slow down scanning

Check warning on line 66 in rules/c2/addr/ip.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/c2/addr/ip.yara#L66

rule "hardcoded_ip_port": string "$ipv4" may slow down scanning

Check warning on line 9 in rules/exec/shell/background-sleep.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/exec/shell/background-sleep.yara#L9

rule "sleep_and_background": string "$cmd_bg" may slow down scanning

Check warning on line 30 in rules/exfil/curl_elf.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/exfil/curl_elf.yara#L30

rule "exfil_libcurl_elf": string "$word_with_spaces" may slow down scanning

Check warning on line 9 in rules/impact/degrade/app.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/impact/degrade/app.yara#L9

rule "osascript_window_closer": string "$c_app_name" may slow down scanning

Check warning on line 26 in rules/impact/degrade/app.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/impact/degrade/app.yara#L26

rule "osascript_quitter": string "$c_app_name" may slow down scanning

Check warning on line 309 in rules/impact/remote_access/php.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/impact/remote_access/php.yara#L309

rule "php_str_replace_obfuscation": string "$o_recursive_single" may slow down scanning

Check warning on line 27 in rules/malware/family/amos.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/malware/family/amos.yara#L27

rule "amos_magic_var": string "$word_with_spaces" may slow down scanning

Check warning on line 8 in rules/persist/systemd/no_docs_or_comments.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/persist/systemd/no_docs_or_comments.yara#L8

rule "systemd_no_comments_or_documentation": string "$ex_comment" may slow down scanning

Check warning on line 23 in rules/sus/compiler.yara

See this annotation in the file changed.

@virustotal-yara-ci virustotal-yara-ci / Rules Analysis

rules/sus/compiler.yara#L23

rule "small_opaque_archaic_gcc": string "$word_with_spaces" may slow down scanning