diff --git a/assemblyline/common/identify_defaults.py b/assemblyline/common/identify_defaults.py index 00ca8e38d..5a9ae94d8 100644 --- a/assemblyline/common/identify_defaults.py +++ b/assemblyline/common/identify_defaults.py @@ -127,6 +127,7 @@ {"al_type": "executable/mach-o", "regex": r"^Mach-O"}, {"al_type": "archive/7-zip", "regex": r"^7-zip archive data"}, {"al_type": "archive/ace", "regex": r"^ACE archive data"}, + {"al_type": "archive/asar", "regex": r"^Electron ASAR archive"}, {"al_type": "archive/bzip2", "regex": r"^bzip2 compressed data"}, {"al_type": "archive/cabinet", "regex": r"^installshield cab"}, {"al_type": "archive/cabinet", "regex": r"^microsoft cabinet archive data"}, @@ -136,7 +137,7 @@ {"al_type": "archive/lzma", "regex": r"^LZMA compressed data"}, {"al_type": "archive/rar", "regex": r"^rar archive data"}, {"al_type": "archive/tar", "regex": r"^(GNU|POSIX) tar archive"}, - {"al_type": "archive/ar", "regex": r"ar archive"}, + {"al_type": "archive/ar", "regex": r"^current ar archive"}, {"al_type": "archive/vhd", "regex": r"^Microsoft Disk Image"}, {"al_type": "archive/xz", "regex": r"^XZ compressed data"}, {"al_type": "archive/zip", "regex": r"^zip archive data"},