Skip to content

Comments

Update generic_pdf.yar#3995

Merged
keaton-sublime merged 2 commits intomainfrom
keaton-sublime.fn.esc-6938.pdf_yara_rule
Feb 11, 2026
Merged

Update generic_pdf.yar#3995
keaton-sublime merged 2 commits intomainfrom
keaton-sublime.fn.esc-6938.pdf_yara_rule

Conversation

@keaton-sublime
Copy link
Member

Description

adding additional pdf yara rule to generic pdf rule file. Matching on JPEG images found within phishing PDFs.
Good coverage in set of 2500ish pdfs.

Associated samples

adding additional pdf yara rule to generic pdf rule file. Matching on JPEG images found within phishing PDFs.
@keaton-sublime keaton-sublime marked this pull request as ready for review February 10, 2026 14:41
@keaton-sublime
Copy link
Member Author

Setting as ready for review - no MQL rule so we can hunt on the updated rule.

@keaton-sublime keaton-sublime added the review-needed Indicates that a PR is waiting for review label Feb 10, 2026
@keaton-sublime keaton-sublime added this pull request to the merge queue Feb 11, 2026
Merged via the queue into main with commit e224bba Feb 11, 2026
3 checks passed
@keaton-sublime keaton-sublime deleted the keaton-sublime.fn.esc-6938.pdf_yara_rule branch February 11, 2026 14:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants