SUSP_Doc_RTF_ExternalResource_May22
Description
Detects a suspicious pattern in RTF files which downloads external resources as seen in CVE-2022-30190 / Follina exploitation
Query · yara
strings:
$s1 = " LINK htmlfile \"http" ascii
$s2 = ".html!\" " ascii
condition:
uint32be(0) == 0x7B5C7274 and
filesize < 300KB and
all of them