SUSP_EXPL_Follina_CVE_2022_30190_Jun22_1

Rule Info

Av Ratio
22.57
Score
60
Name
SUSP_EXPL_Follina_CVE_2022_30190_Jun22_1
Minimum Yara
1.7
Required Modules
[]
Description
Hunting Rule for Follina Exploits
Date
2022-06-10
Tags
['SUSP', 'CVE_2022_30190', 'EXPLOIT']
Rule Hash
c34334c68727ca9aff70d3d2a80710da
Author
Florian Roth

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
41
Suspicious (< 10 engines)
14
Clean (0 engines)
21

Rule Matches

Positives
Hash
Total
Timestamp
VT
13
56af3fc7c64c355b3bf1b468d5df77f11eb03c6fe77f136c2a65c84a5a94d988
47
2022-06-17 10:04:13
23
83511e786f325b5c75cf56c6fb34011a6c3aa1068af38a66790f6acecf74b78b
55
2022-06-17 09:41:29
2
a1ca6c60551c68039d3c67bf01372fc02e2846081b56cdd1dda0703680e0ff8a
58
2022-06-17 09:13:39
25
e65b4dee3971d9a986acdc4eed26ebecfe1f2396c1dc199b9767a637f34fe8b8
57
2022-06-17 06:06:48
1
9cc58874a1314e639d0fc468d3a18bbe66bc5deea9443216d98baa11913d506f
56
2022-06-17 03:30:50
22
6789fab6790ded2ca9f2fd9ccc810a6998d910903c7e919bcd4453b1d8a4f996
56
2022-06-17 01:16:50
26
2a0fe90ee450f19920f89f40c58ab03ffece6c7c22779dc83f22f58c8dc395bc
57
2022-06-16 23:21:17
8
8bd7e905d57f9bffe4bd6ad49f99cde323a9985c091aa21870280a683beb1ce1
56
2022-06-16 22:46:10
0
a7100484900421fa24ee3274ada7cc1971fb3d8c3c577b92917859f178ae1257
56
2022-06-16 22:09:44
0
5248864deb8b00407d2e5e5ead2e45b0b65b3a911ea4ad6de7d19ec5bd44c9c5
56
2022-06-16 19:59:53
0
5d38f1bea9dd1df12722f6919122abf4707b34a34bf5af38fa178f9c747cbb76
56
2022-06-16 19:18:22
19
0b7a0a71f4e2571f797cff059a081089bc5a09b18e4ef7fb6661a8ec429c1950
56
2022-06-16 19:17:08
5
076b22f6815cf168a813fa64e7f0b7e45d5312de16f8c9e65593160cc2c9cb1e
56
2022-06-16 18:50:08
19
410de84920e5022b6d34cf9eb1b83f7409549a4655244f9e39279f678976653b
56
2022-06-16 16:51:48
0
b0e6adf5adeae869fcf09bfca0e59ab495354d674d2ccd949590dd727db96e27
57
2022-06-16 16:51:47
0
2b830face2555a52c682c9b219aba9f66c8ac2e52cdc61553bd27a966ee251fe
56
2022-06-16 16:43:01
18
9888a5883635347f48797116e9ab8d0c524a7775692612a9ee94e9c04b80071c
56
2022-06-16 16:36:55
24
901ac450eb02a63a6daba010a564ba9a4ae042c342d0e4e4969840059b185bda
56
2022-06-16 16:18:27
3
9c4cfd05e31b290449fba2bbc2f2f1a903240054c3712d9b22ac7cd8c363474a
58
2022-06-16 16:15:13
27
50eb0ffb78908931ee490fa8bd772301efbf64cc61499d625f273bb7fd6e194f
55
2022-06-16 16:10:09
14
37b40d799364a8c857e88b64d1ccb2e210c4348c5cb00748041423ffc8e46053
54
2022-06-16 15:53:39
0
9e0a72ef2c9f39b84fec430f6f98fdfc51aaf44ffc5ec85dd2522b93aa044e54
57
2022-06-16 15:17:57
18
cb22379a5c294d27ee150123247831fbb30acb38b01b235ab4ea22507cd5d090
56
2022-06-16 15:14:24
26
32ec74ccefc7d7feb5c8817097652fc6014c6217f5b6a2695a95e680d6958153
56
2022-06-16 15:06:57
0
6bab44260b6a53dfaeb2cc58731516d02bf9bc2e26dff840a813478a9e17c57e
57
2022-06-16 13:54:55
23
7e3247883be19a94f3c93bdf6f94a05bf03a00274f48908314e569204af7f11d
55
2022-06-16 13:52:45
0
0b8d09ff76e9ccf839b68150fe62f8ca012870f1fbbb3d03cb8eda3b9ac52978
57
2022-06-16 13:39:20
23
82670522b096c1eadf946e3782e562e86d09b3efc2575a06761cf035d8aec2bd
56
2022-06-16 12:50:30
23
73705716172ac96b070b00d6fb09d58f44275259af893779beea6ea8fc7ae907
56
2022-06-16 11:08:15
0
e339f24c298d17c6834fdd1136751a98d121998ae4537a617c1f6a2dd44048d6
54
2022-06-16 07:08:18
24
d193880450e2fc96229484ae38a2e6e41c91716d2746432ea782572a1e27afdd
56
2022-06-16 05:18:44
0
b1c144c697120de37de830a72e3d3b95e4b608ec6592e3c18e0affba84635f38
57
2022-06-15 22:28:25
16
c6427f7610368fe0118764b71c12661b70bcc0e282f4187dbb493849b9f6a4fe
52
2022-06-15 20:40:10
30
4f643bf57abe70e3c4ed64f05167da5d6c35f2dac1d7fda78523ab231f903575
55
2022-06-15 17:42:39
15
74d26b7e3547ba4569fd1617bcf638df4081d1f7de24464f27bb30b6ea9e8aee
56
2022-06-15 17:23:27
23
fd4ee34a813f829594cc2dc760afada467c1320621e66491517e4bf95a0ace06
56
2022-06-15 16:54:42
26
66462e2e98fa2eec11fc6fedbf7cdb1875d59f8ed300290493d0be1f12233bcb
56
2022-06-15 16:30:19
24
56abf7aa8a2a74e7db6bdd73ab496d896d07da04db9c87bc8c45b4eef6b9fafd
56
2022-06-15 16:28:09
0
9cf1f3658ee6b92742ece05dc88b26858f80a7de3d69cec12f82469145732c84
57
2022-06-15 16:04:04
0
da5368a187c834e191d3c7a26a37e1e6a1d6141447ad8c3a98d340427dead74c
57
2022-06-15 15:09:20
0
800e639a6459baa405e18081170f8279be7b8196defab7608aa42afa4f7e96b0
57
2022-06-15 15:06:10
19
d24eeb669f70dbd9a7e95a72206a5d93c117951d404864dbec7fb0d692770f34
56
2022-06-15 14:49:54
0
c36b032ee1eccd92987c273a1a4ea7688330c503b1265f7c309a2083aa8ec80d
57
2022-06-15 13:23:35
3
3b5fdfe19974d64b7018f4e3e0b68b850df3881abdd67efc068fa518b51e1773
56
2022-06-15 13:23:32
4
3aa16a340aacc5aecbdb902a5f6668f117b62e27966ab41f8a71a1dd1a08f8bd
56
2022-06-15 13:23:32
22
044f90bf9eea350d4c68b02d5b70d737a6a7c81ca30720382759301e6c849742
56
2022-06-15 13:21:25
0
50e0991c3b54773ba846af20ce411644208abbaea5c3a297388ddbcb7602a623
57
2022-06-15 10:34:09
23
29a2e761b63e40523d9dc42f00235a7c884cfb035ddbbadd377cebbf0f6f9a68
56
2022-06-15 10:16:18
25
dd2b0c59ad2b28643a627c2544fc4a6cbc499aab6b340d2e76eaeb0bafe5adb0
58
2022-06-15 09:55:54
24
26a0d403343757dfe73f9c3203a2e401db3febfd37dc6c0bd7739c528dfc88bf
58
2022-06-15 09:54:28
7
b32dc832c74f91ca6566a29b055b0d214142904310c9fa60cea1d4af36450465
56
2022-06-15 09:40:36
23
e78dbcf9eb548872f3da21953f67d02a0d157dd12a0194a044a07eea47278304
56
2022-06-15 09:14:52
21
a190903509ff8827a3c95c3a790fefffdcaeadc6dc6dfd9656d83f184b0b9760
59
2022-06-15 08:50:57
0
605de7ec84ab7b0f44ec564b3c9fcabdae4891ef2129fd1bf2a7d11c23196cae
57
2022-06-15 08:46:03
0
db660364e91a7aa6f4364a49678ff926894ab1a3e567f48f22d783349930b3b6
57
2022-06-15 08:41:11
19
13b9481bff8b169bb175bf97064f52cbbffe1561ba8641dda3551ea5781e547c
56
2022-06-15 08:11:47
24
2cdd875b905065d9e35e323eb56f8f5b1dca141be94da35f79daf833d88728a7
56
2022-06-15 07:18:30
18
9959f8340d73eccb3c328ae37eba68f8c3f9b47815d796c2e2f5dfcedaa7946a
56
2022-06-15 05:11:59
24
c61fe40f46226d24f0f17c46acc4db6a0091c68abc6a3d995b3f6df1bbfcbb1e
56
2022-06-15 04:17:02
23
ad32d583c227a059eed515ed617c473ca8697d6856276c390b0299b573178966
56
2022-06-15 04:10:54
0
52b33f3f6ed477a037f60de95803d24bcf0ae4a137ffe786bf80188cabbd1478
57
2022-06-15 01:09:14
0
43e45b5d643bea7d374bcffa11d600af7117a78a604b8d20578fa3c83a55a0d5
57
2022-06-14 19:28:30
4
8af0b95e1d25c545ac64f600605f2361c921739ccb719e5484beac890eff6fc1
56
2022-06-14 19:21:33
0
617e67b16b6ce9e984c022892c2c1289fc9be502913871bd20abadd967a015f3
57
2022-06-14 19:07:01
19
0ee768abe14eadfa2be002febae6b747e48ec6578ecdc5a642a92a35573b0374
56
2022-06-14 16:01:15
21
1c785f29f11bbd4751b3147aca6e39c37821960523f978b36735c70e63ade6c0
56
2022-06-14 11:46:15
6
85017c355f7544a8ec3676367cf01df2803c0a2dcac5f1b75a4db0e6b0de7e04
55
2022-06-14 04:47:50
0
6e74957ddd4d93780f6f9048a4e2f703b3cce763b29602601396891079460698
57
2022-06-13 19:17:22
25
e7886967c692329f846ec87e8c6db4c6d7eca61a2f87563dcb398be0ce3a1d58
56
2022-06-13 17:17:35
30
3bf2bed980adca2fb8035c308241659346a37d70d53ed549d1dfd5a8e03a2c64
57
2022-06-13 16:22:34
28
cdec208ec12fa58c122db1887abb7f58c7998a9ba6eeebffc501e11de3975215
57
2022-06-13 14:12:47
3
a692a8db038cc63bcdc44b617387d1f41a8f4d4d3dcac55de86990c0a6c9c1c1
56
2022-06-13 13:44:47
4
8bc9176226696d277edac98fbf2a17e1e633a2b1e2a681a6a3001833cfcfe546
56
2022-06-13 10:57:20
4
77c8f41b5a6829e341e8d887df719bb4d8d768cc0845fdacd5f3481100f8dd37
55
2022-06-13 09:04:13
14
d16ff4fac89e6582d3735abbca36431dd75375e47119c4cc27cd1840853f78f4
55
2022-06-13 08:47:52
2
b5e57cd620dd9dec39edbe5a588d81f531c0bf82b85c18b4cb403468afb95331
56
2022-06-13 08:45:47

Rule Matches per Month (last 24 months)