Commit c8c198a4 by garanews Committed by GitHub

Create ipv4_pub

yara rule to ONLY match PUBLIC IPv4 address
parent 0d301454
This Yara ruleset is under the GNU-GPLv2 license ( and open to any user or organization, as
long as you use it under this license.
This rule:
doesn't match this invalid ips (ex. 999.999.999.999)
doesn't match local IPs (
doesn't match broadcast IPs (ex.
rule IP {
author = "garanews"
$ip = /([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])(?<!172\.(16|17|18|19|20|21|22|23|24|25|26|27|28|29|30|31))(?<!127)(?<!^10)(?<!^0)\.([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])(?<!192\.168)(?<!172\.(16|17|18|19|20|21|22|23|24|25|26|27|28|29|30|31))\.([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\.([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])(?<!\.0$)(?<!\.255$)
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment