
Rule Info
Av Ratio
0
Score
70
Name
SUSP_Doc_RTF_ExternalResource_May22
Minimum Yara
3.2.0
Required Modules
[]
Description
Detects a suspicious pattern in RTF files which downloads external resources as seen in CVE-2022-30190 / Follina exploitation
Reference
Modified
2022-05-31
Date
2022-05-30
Tags
['DEMO', 'SUSP', 'CVE_2022_30190', 'FILE']
Rule Hash
7b74dfae48ff8c589709f8ed7d9daf95
Author
Tobias Michalski, Christian Burkard
Virustotal Matches
Antivirus Verdicts
Rating
Number of Samples
Malicious (>= 10 engines)
0
Suspicious (< 10 engines)
0
Clean (0 engines)
1