SUSP_Doc_WordXMLRels_May22
Description
Detects a suspicious pattern in docx document.xml.rels file as seen in CVE-2022-30190 / Follina exploitation
Query · yara
strings:
$a1 = "<Relationships" ascii
$a2 = "TargetMode=\"External\"" ascii
$x1 = ".html!" ascii
$x2 = ".htm!" ascii
$x3 = "%2E%68%74%6D%6C%21" ascii /* encoded version of .html! */
$x4 = "%2E%68%74%6D%21" ascii /* encoded version of .htm! */
condition:
filesize < 50KB
and all of ($a*)
and 1 of ($x*)