Closed djlukic closed 5 months ago
Bear in mind that this rule can be extremely slow for files containing multiple occurrences of { 50 4B 03 04 }
. My guess is that some of the random files have a multiple occurrences of that string and it apparently takes forever to complete. It would be great if try to identify which of those 1000 files is actually taking too long.
Hi,
I wrote a rule to match certain condition within PKZIP format but if I try to scan 1000 random files with that rule scan never finishes.
I tried this command line:
.\yara64.exe .\ruleset.yara "C:\Program Files" -r
If I try to scan a matching ZIP archive or several of them, there is no problem, they get detected.
Yara version is 4.3.1
Thanks!