MSDT abused to achieve RCE on Microsoft Office
ID: 00de27ee-9212-5308-82c4-83aa50cc5439
STIX ID: report--00de27ee-9212-5308-82c4-83aa50cc5439
Feed Name: Sekoia.com
This report documents active exploitation of CVE-2022-30190 (aka Follina) in which crafted DOCX and RTF files use MSHTML and the ms-msdt URI scheme to invoke msdt.exe with an IT_BrowseForFile argument that results in arbitrary PowerShell execution. The authors enumerate malicious document and loader hashes, IPs and domains, a retrieved PyInstaller loader that fetches a Cobalt Strike beacon, detection indicators (process execution pattern, YARA and Sigma rules), suggested GPO/registry mitigations, and note multiple unrelated samples observed in the wild suggesting reuse or repurposing by different actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
