I am having a weird situation where I am trying to match a sample where in condition I specified
and not pe.version_info["FileDescription"] == "Test"
and I also tried with
pe.version_info["FileDescription"] != "Test"
but it doesn't hit because RT_VERSION resource doesn't exist.
Is this intended that and not or != won't have a match when RT_VERSION doesn't exist?
version_info can be YR_UNDEFINED,
Try to use something like this:
and (not defined pe.version_info["FileDescription"] or not (pe.version_info["FileDescription"] matches /Test/) )
Hi,
I am having a weird situation where I am trying to match a sample where in condition I specified
and not pe.version_info["FileDescription"] == "Test"
and I also tried withpe.version_info["FileDescription"] != "Test"
but it doesn't hit because RT_VERSION resource doesn't exist. Is this intended that and not or != won't have a match when RT_VERSION doesn't exist?Thanks!