
Umfassende Analyse der CVE-2022-30190 (Follina MSDT-Schwachstelle) mit IOCs, Erkennungsregeln für SIEMs/EDR, YARA-Signaturen, Minderungsskripte und pädagogische Aufschlüsselung des Exploits aus der Perspektive eines Verteidigers.
Dieses Repository behandelt den Follina MSDT aus der Defender-Perspektive
Der Fehler ist eine Remote-Codeausführungsschwachstelle im Microsoft Windows Support Diagnostic Tool (MSDT), die von crazyman der Shadow Chaser Group gemeldet wurde. Microsoft verfolgt sie nun als CVE-2022-30190. Der Fehler betrifft alle Windows-Versionen, die noch Sicherheitsupdates erhalten (Windows 7+ und Server 2008+).
Wie der Sicherheitsforscher nao_sec herausfand, wird er von Bedrohungsakteuren verwendet, um bösartige PowerShell-Befehle über MSDT auszuführen, was Microsoft als Angriffe mit beliebiger Codeausführung (ACE) beschreibt, wenn Word-Dokumente geöffnet oder in der Vorschau angezeigt werden.
„Ein Angreifer, der diese Schwachstelle erfolgreich ausnutzt, kann beliebigen Code mit den Berechtigungen der aufrufenden Anwendung ausführen“, erklärt Microsoft.
Für die Bedrohungsjagd finden Sie die Sigma-Regel HIER
Nachfolgend sind die Erkennungsregeln, die weiter angepasst werden können. Dank an Bala Ganesh. Den vollständigen Artikel finden Sie HIER
MS Defender:
DeviceProcessEvents | where ((ProcessCommandLine contains "WINWORD.EXE") and (ProcessCommandLine contains "msdt.exe") and (ProcessCommandLine contains "sdiagnhost.exe" or ProcessCommandLine contains "csc.exe" or ProcessCommandLine contains "PCWDiagnostic" or ProcessCommandLine contains "IT_ReBrowserForFile" or ProcessCommandLine contains "IT_BrowserForFile" or ProcessCommandLine contains "conhost.exe"))
[Doc Malware]
alert.severity = 2
description = Detection (Rule ID: 74566a6a66aaasdq2ed)
cron_schedule = 0 * * * *
disabled = 1
is_scheduled = 1
is_visible = 1
dispatch.earliest_time = -60m@m
dispatch.latest_time = now
search = (source="WinEventLog:*" AND (CommandLine="*WINWORD.EXE*") AND (CommandLine="*msdt.exe*") AND (CommandLine="*sdiagnhost.exe*" OR CommandLine="*csc.exe*" OR CommandLine="*PCWDiagnostic*" OR CommandLine="*IT_ReBrowserForFile*" OR CommandLine="*IT_BrowserForFile*" OR CommandLine="*conhost.exe*"))
alert.suppress = 0
alert.track = 1
SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Process CommandLine" ilike '%WINWORD.EXE%') and ("Process CommandLine" ilike '%msdt.exe%') and ("Process CommandLine" ilike '%sdiagnhost.exe%' or "Process CommandLine" ilike '%csc.exe%' or "Process CommandLine" ilike '%PCWDiagnostic%' or "Process CommandLine" ilike '%IT_ReBrowserForFile%' or "Process CommandLine" ilike '%IT_BrowserForFile%' or "Process CommandLine" ilike '%conhost.exe%')
(CommandLine.keyword:*WINWORD.EXE* AND CommandLine.keyword:*msdt.exe* AND CommandLine.keyword:(*sdiagnhost.exe* *csc.exe* *PCWDiagnostic* *IT_ReBrowserForFile* *IT_BrowserForFile* *conhost.exe*))
Sumologic
(_sourceCategory=*windows* AND (CommandLine = "*WINWORD.EXE*") AND (CommandLine = "*msdt.exe*") AND (CommandLine = "*sdiagnhost.exe*" OR CommandLine = "*csc.exe*" OR CommandLine = "*PCWDiagnostic*" OR CommandLine = "*IT_ReBrowserForFile*" OR CommandLine = "*IT_BrowserForFile*" OR CommandLine = "*conhost.exe*"))
(process.command_line:*WINWORD.EXE* AND process.command_line:*msdt.exe* AND process.command_line:(*sdiagnhost.exe* OR *csc.exe* OR *PCWDiagnostic* OR *IT_ReBrowserForFile* OR *IT_BrowserForFile* OR *conhost.exe*))
Die folgende Abfrage, beschrieben von Brent Murphy HIER, kann ebenfalls angewendet werden
process where event.type in ("start" , "process_created") and (process.pe.original_file_name : "msdt.exe" or process.name : "msdt.exe") and (process.parent.pe.original_file_name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe") or process.parent.name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe"))
# office processes spawning msdt.exe