Legacy variables

Legacy variables (deprecated)

YARA offers a mechanism for defining custom variables that has been used in Livehunt for providing additional information about the file being scanned. These variables are now deprecated in favor of our vt, they will continue to work as always for backward compatibility. You can find list of variables defined by Livehunt below, but we highly encourage you to start using the vt module instead.

Deprecated Variablevt.metadata mapping
file_namevt.metadata.file_name
file_typevt.metadata.file_typestring becomes a reference, to replicate previous functionality for "doc" you could use vt.FileType.DOC
imphashvt.metadata.imphash
md5vt.metadata.md5
new_filevt.metadata.new_file
positivesvt.metadata.analysis_stats.malicious
sha256vt.metadata.sha256
sha1vt.metadata.sha1
signaturesvt.metadata.signaturesstring becomes a dictionary, to replicate previous functionality you could use: for any engine, signature in vt.metadata.signatures : ( signature contains "x")
submissionsvt.metadata.times_submitted
ssdeepvt.metadata.ssdeep
tagsvt.metadata.tagsstring becomes a dictionary, to replicate previous functionality you could use: for any tag in vt.metadata.tags : ( tag == "signed" )
vhashvt.metadata.vhash

Back to top