YARA version 4.0.0 was released. One of its new features that caught my eye, is base64 strings. This is the example rule for the base64 modifier from YARA's documentation:
This rule will search for ASCII strings that are possible BASE64-encodings of ASCII string "This program cannot". Didier Stevens |
DidierStevens 650 Posts ISC Handler May 10th 2020 |
Thread locked Subscribe |
May 10th 2020 2 years ago |
Sign Up for Free or Log In to start participating in the conversation!