Untitled attachment
https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/119/929/808/599/881/original/a9b582c66ba7f09e.png
More than one month after Elastic Security Labs publicly described "LNK Stomping" (now CVE-2024-38217) exploit variants, the "path segment" variant has still zero detections on VirusTotal.
I slapped together a naive YARA rule that seems to work well to detect this variant of CVE-2024-38217 exploits:
https://gist.github.com/wdormann/7379c4c4fb0631d8ec6a5b12d50ba782
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.