Open TLINDEN opened 6 years ago
I don't know what you're doing wrong but when I took your rules file and ran it here using Yara 3.9 it worked fine. Perhaps your PDF files have a $ver which matches your regex?
If you're still troubled by this (I know your OP was a long time ago) please let me have a sample file to scan.
Hello,
I can't get it to work at all. I have the following rule (from Yara-Rules):
If I scan an infected PDF with this, I get nothing:
However, If I do the same with ClamAV, I get:
I am using latest yara (version 3.8.1). I also tried the 3.7 branch, just in case current master is instable, to no avail - same result. OS is FreeBSD 10.3.
What am I doing wrong?