Yara Undefined values


Author: David Zimmer
Date: 02.25.20 - 10:14am



In the yara pe module, anything that is not explicitly set is initialized with the value UNDEFINED. This causes that section of rule (and or etc) to evaluate to a false in the condition statement, however there is no explicit way to test for the undefined value in itself.

So what if you want to test to see if the rich_signature exists or not?

The only way I have found to do this is to wrap it into its own distinct rule, which then gets properly cast to a boolean that you can then work with.

private rule richHeaderExists 
{
    condition: pe.rich_signature.offset 
}

rule noRichHeader
{
    condition: not richHeaderExists 
}

If you are up for modifying the yara source, you can also add a new function such as the following which I added to pe.c

//declare_function("isdef", "s", "i", isdef); 
//ex: pe.dbg(pe.isdef("rich_signature.offset"))
//    pe.dbg(pe.isdef("number_of_signatures"))
define_function(isdef) 
{
	YR_OBJECT* module = module();
	char* txt = string_argument(1);
	if (yr_object_has_undefined_value(module, txt)){
		return_integer(0);
	}else{
		return_integer(1);
	}
}





Comments: (1)

On 03.27.20 - 11:02pm Dave wrote:
from yara dev plusvic:

Actually, as part of the fix for issue #1180, Im changing the behavior for comparison operators. When some operand is UNDEFINED, the result is false instead of UNDEFINED, so not not (pe.section_index(".symtab") >= 0) will work in YARA 4.0.

For arithmetic and bitwise operations the result is still UNDEFINED if some operand is UNDEFINED

 
Leave Comment:
Name:
Email: (not shown)
Message: (Required)
Math Question: 82 + 95 = ? followed by the letter: R 



Twitter
RSS
About Me
More Blogs
Main Site
Posts: (All)
2020 (5)
     Vb6 PCode Internals
     Vb6 Runtime ForLoop Disasm
     VB6 Pcode - For Loops
     Yara Corrupt Imports
     Yara Undefined values
2019 (12)
     Yara WorkBench
     SafeArrayGetVartype
     vbdec dbg updates
     vb6 PCode NOP
     vb6 API and call backs
     how pcode works Pt1
     PrintFile
     ImpAdCallNonVirt
     Reversing PCode Args
     VB6 PCode Disassembly
     VB6 PCode Debugger
     UConnect Disable Cell Modem
2017 ( 5 )
2016 ( 4 )
2015 ( 6 )
2014 ( 5 )
2013 ( 9 )
2012 ( 13 )
2011 ( 19 )
2010 ( 11 )
2009 ( 1 )