SekoiaLab / Fastir_Collector

https://sekoialab.github.io/Fastir_Collector/
GNU General Public License v3.0
506 stars 126 forks source link

Receiving error with yara rules #27

Open angi3rr opened 6 years ago

angi3rr commented 6 years ago

I'm looking for some help with an error I'm seeing in the logs.

`line 23, in _load_yara_rules SyntaxError: C:\Users(path)\apt_ta17_318A.yar(88): invalid field name "imphash"

2018-08-08 13:52:56,358`

The file changes to a new one as I remove the yara rule. I am running as administrator.

gaelmuller commented 6 years ago

Could you please tell us how you are using FastIR ? (using source code or compiled binary ? in case of a compiled binary, which version ?)

angi3rr commented 6 years ago

We're using compiled binary, version 1.5.