
Rule Info
Tags
['SUSP', 'DEMO']
Description
Detects a suspicious pattern in RTF files which downloads external resources inside e-mail attachments
Required Modules
[]
Date
2022-06-01
Score
75
Author
Christian Burkard
Name
SUSP_Doc_RTF_OLE2Link_EMAIL_Jun22
Rule Hash
f9222ea38e3fd3e18d4ec45aad4e1f42
Reference
Internal Research
Minimum Yara
1.7
Antivirus Verdicts
Rating
Number of Samples
Malicious (>= 10 engines)
13
Suspicious (< 10 engines)
0
Clean (0 engines)
1
Rule Matches
Total
Positives
Timestamp
Hash
VT