SUSP_DOC_RTF_ExternalResource_EMAIL_Jun22

Rule Info

Name
SUSP_DOC_RTF_ExternalResource_EMAIL_Jun22
Author
Christian Burkard
Description
Detects a suspicious pattern in RTF files which downloads external resources as seen in CVE-2022-30190 / Follina inside e-mail attachment
Score
70
Date
2022-06-01
Minimum Yara
1.7
Rule Hash
2a28de258aa3f7b17201fa7579b490b5
Tags
['CVE_2022_30190', 'DEMO', 'SUSP']
Required Modules
[]

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
1
Suspicious (< 10 engines)
0
Clean (0 engines)
1

Rule Matches

Timestamp
Positives
Total
Hash
VT
2024-01-15 23:02:57
13
58
59ac556af2ab3db3f4604cd8a785a588661a2fb907e16fabce1965ac96620614
2023-02-28 13:46:51
0
59
8ad202530fadf434643bc8766976ac5c37208d06870dc91cbdc9b439cd35f08d

Rule Matches per Month (last 24 months)