Yara-Rules/rules

Rule contradiction

Inndy opened this issue · 2 comments

Inndy commented

uint16(0) == 0x5a4d and ( $x1 at 0 ) and filesize < 14KB and all of ($s*)

This rule will match nothing because of contradiction.

Totally agree, two different conditions at offset 0x0 cannot be never true.

This rule was created by https://github.com/Neo23x0 so it may be worth to ask him about it.