Other > Non-Avast security products

YARA signatures almost got detected by every antiviruses

(1/2) > >>

lichesssatrancturkiye:
Hello I collecting YARA rules but my YARA signatures are got detected. How can I fix that? I don't want hide them.

DavidR:
In order to help we need information and we/I can't talk about other antiviruses only if it is specific to Avast.  I have no idea what YARA rules or signatures are about.

If you are getting an Avast Alert what is the information contained in that alert.  You can attach a screenshot of the Alert window with the Details option selected.

Attaching Images to your post - When you Click the Reply button it opens a text window for you to post your comment (reply or post).
Click the Preview button, that shows what you have input and expands it to include 'Attachments and other options'. Click that it further expands, here you can attach images, etc. at the bottom of your post.
See my attached image, click to expand.

lichesssatrancturkiye:
https://www.virustotal.com/gui/file-analysis/OTEwYjMwYjM3MmUyZjEwMmUxMWFiNjI0ZmFlMmRmODE6MTcwNDM4ODYzMw==

DavidR:
Unfortunately the VT link didn't provide the requested information (screenshot of the alert windows with the details option selected.), all it does is confirm Avast isn't alone in detecting this.


--- Quote from: lichesssatrancturkiye ---How can I fix that? I don't want hide them.
--- End quote ---

I don't know what you mean by 'Fix' or what you mean by not wanting to 'Hide' them.

This may well just be a language issue Fix and Hide meaning something different to me.

DavidR:
A forum friend has updated me on what Yara is.

https://www.varonis.com/blog/yara-rules

--- Quote from: Extract ---YARA rules are used to classify and identify malware samples by creating descriptions of malware families based on textual or binary patterns
--- End quote ---

https://virustotal.github.io/yara/

--- Quote from: Extract ---YARA is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns. Each description, a.k.a rule, consists of a set of strings and a boolean expression which determine its logic. Let's see an example:
--- End quote ---

I'm not surprised that Avast considers it suspect, it is very much the same as having a second active antivirus installed (detecting each others signatures).

Navigation

[0] Message Index

[#] Next page

Go to full version