SUSP_Doc_RTF_ExternalResource_May22

Rule Info

Author
Tobias Michalski, Christian Burkard
Minimum Yara
3.2.0
Name
SUSP_Doc_RTF_ExternalResource_May22
Date
2022-05-30
Description
Detects a suspicious pattern in RTF files which downloads external resources as seen in CVE-2022-30190 / Follina exploitation
Tags
['FILE', 'EXPLOIT', 'DEMO', 'CVE_2022_30190', 'SUSP']
Score
70
Modified
2022-05-31
Av Ratio
0
Required Modules
[]
Rule Hash
7b74dfae48ff8c589709f8ed7d9daf95

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
0
Suspicious (< 10 engines)
0
Clean (0 engines)
1

Rule Matches

Hash
Positives
Total
Timestamp
VT
c273caecc520f8ab9250dc412980174524bd0c12bb218225b2ec4d52d6af2cec
0
56
2022-06-09 14:27:51

Rule Matches per Month (last 24 months)