SUSP_DOC_RTF_ExternalResource_EMAIL_Jun22

Rule Info

Av Ratio
0
Score
70
Name
SUSP_DOC_RTF_ExternalResource_EMAIL_Jun22
Minimum Yara
1.7
Required Modules
[]
Description
Detects a suspicious pattern in RTF files which downloads external resources as seen in CVE-2022-30190 / Follina inside e-mail attachment
Date
2022-06-01
Tags
['SUSP', 'CVE_2022_30190', 'DEMO', 'T1223']
Rule Hash
2a28de258aa3f7b17201fa7579b490b5
Author
Christian Burkard

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
0
Suspicious (< 10 engines)
0
Clean (0 engines)
0

Rule Matches

No matches yet

Rule Matches per Month (last 24 months)