SUSP_LNK_Follina_Jun22

Rule Info

Av Ratio
0
Score
75
Name
SUSP_LNK_Follina_Jun22
Minimum Yara
1.7
Required Modules
[]
Description
Detects LNK files with suspicious Follina / CVE-2022-30190 strings
Date
2022-06-02
Tags
['T1210', 'FILE', 'DEMO', 'CVE_2022_30190', 'SUSP', 'T1023']
Rule Hash
4185f9d4af993b73a4cf905a71719db7
Author
Paul Hager

Antivirus Verdicts

Rating
Number of Samples
Malicious (>= 10 engines)
0
Suspicious (< 10 engines)
0
Clean (0 engines)
0

Rule Matches

No matches yet

Rule Matches per Month (last 24 months)