A malware identification and classification tool

YARA is a tool aimed at helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families based on textual or binary patterns contained on samples of those families. Each description consists of a set of strings and a Boolean expression which determines its logic. Let's see an example:

Source Files (show merged sources derived from linked package)
Filename Size Changed
v3.6.1.tar.gz 0000505302 493 KB over 3 years
yara.changes 0000005615 5.48 KB over 3 years
yara.spec 0000004971 4.85 KB over 3 years
Comments for yara 0