Skip to content

Conversation

@octo-sts
Copy link
Contributor

@octo-sts octo-sts bot commented Jan 26, 2025

2025-01-26 third-party rule update for malcontent.

@egibs egibs merged commit 3147dd1 into main Jan 26, 2025
13 of 14 checks passed
@egibs egibs deleted the third-party-rule-update-2025-01-26 branch January 26, 2025 20:05
stevebeattie added a commit to stevebeattie/malcontent that referenced this pull request Feb 4, 2025
In commit 3147dd1 ("Update third-party rules as of
2025-01-26 (chainguard-dev#780)"), the the YARAForge rule for detecting
Eziriz .NET Reactor obfuscated DLLs was renamed from
`COD3NYM_SUSP_OBF_NET_Reactor_Indicators_Jan24` to
`COD3NYM_Reactor_Indicators`.

However, this rule has a false positive exception because it seems
Sonarqube uses this obfuscator on its CSharp and VBWeb plugin DLLs,
but the exception rule was not updated at the same time the rule was
renamed. Fix that.

[Verified that none of the other rule names in the third-party rules
update that changed are referenced in the false_positives directory.]

Signed-off-by: Steve Beattie <[email protected]>
stevebeattie added a commit to stevebeattie/malcontent that referenced this pull request Feb 4, 2025
In commit 3147dd1 ("Update third-party rules as of
2025-01-26 (chainguard-dev#780)"), the the YARAForge rule for detecting
Eziriz .NET Reactor obfuscated DLLs was renamed from
`COD3NYM_SUSP_OBF_NET_Reactor_Indicators_Jan24` to
`COD3NYM_Reactor_Indicators`.

However, this rule has a false positive exception because it seems
Sonarqube uses this obfuscator on its CSharp and VBWeb plugin DLLs,
but the exception rule was not updated at the same time the rule was
renamed. Fix that.

[Verified that none of the other rule names in the third-party rules
update that changed are referenced in the false_positives directory.]

v2: perform `yr fmt` on the sonarqube.yara file to make the CI happy

Signed-off-by: Steve Beattie <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant