In this new version of zipdump.py, you can provide a YARA rule directly on the command line, without having to store it inside a file.
Just start the value of option -y with # and type your rule (use quotes because of spaces):
zipdump_v0_0_9.zip (https)
MD5: 2700AF663980204075107164AA12750A
SHA256: 5686F24373AF64E1F5D866C71B29A22CE97964EC563A2219681A6268CC9A1153
[…] zipdump was updated to version 0.0.9, allowing users to include YARA rules directly on the commandline Update: zipdump.py Version 0.0.9 […]
Pingback by Week 27 – 2017 – This Week In 4n6 — Sunday 9 July 2017 @ 13:08