Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Yara rules DSHELL/production/yara/APT_Backdoor_Win_DShell_1.yar and APT_Backdoor_Win_DShell_2.yar trigger too many matches exception in yara-python #22

Open
jwoytek opened this issue Mar 17, 2021 · 0 comments

Comments

@jwoytek
Copy link

jwoytek commented Mar 17, 2021

Using yara-python to match against these rules, the following rules trigger a too many matches exception ("internal error: 30") when run against certain files:

rules/DSHELL/production/yara/APT_Backdoor_Win_DShell_1.yar
rules/DSHELL/production/yara/APT_Backdoor_Win_DShell_3.yar

At least one example hash that will trigger the exception against these rules is:
sha256: 04a88437468e6e9c447805d733ec82e08fd4256af44542797f16a7e318f763f8
md5: 86031c9fc72b42fef6a4c7f8b72cda83
sha1: 6a4c3370eaa373aca1113f0067d40076615b4d66

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant