The Rule Matches |
You can view information about all the matches of the particular YARA rule. To do this: 1.At the top of the Dr.Web vxCube main page, click . 2.In the column for the required rule, click the number. The full list of matches for this rule opens. For each match, the following information is displayed: • The name of the file that the match occurred on. • The format of the file that the match occurred on. • The hash of the file. • The date when the match was occurred. • The list of operating systems that the analysis has been done for. From the rule match report, you can go to the analysis report related to the particular match: •To go to the report main page, click the file name in the corresponding row. •To go to the report page for the specific platform, click the OS name in the corresponding row.
Figure 10. Report on YARA rule matches |