Common Information
Type Value
Value
rule EXP_CVE_2020_35730 {
	meta:
		author = "Insikt Group, Recorded Future"
		date = "2023-06-13"
		description = "Detects CVE-2020-35730 use in EML files"
		version = "1"
	strings:
		$ = "[<script>" base64
		$ = "</script>]:##str_replacement_" base64
		$ = "From:"
		$ = "To:"
		$ = "Subject:"
	condition:
		all of them
}
Category
Type Yara Rule
Misp Type
Description
Details Published Attributes CTI Title
Details Pdf 2023-06-19 51 BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage Activities