Just as a side note, normal rules are catching the samples, so I don't know
if it would display both YARA and the others.
Here's what the samples show without YARA:
Win.Ransomware.WannaCry-6313053-0 FOUND
Win.Trojan.Agent-6312832-0 FOUND

I tested with one YARA script I saw on twitter (Florian Roth), but it didn't
catch them, so I can't really help out more.
Don't know if that's my end or not, just a default install with Homebrew on
OSX to test it out.


Eric Tykwinski
TrueNet, Inc.
P: 610-429-8300

clamav-users mailing list

Help us build a comprehensive ClamAV guide:


Reply via email to