
CVE-2022-30190 (Follina MSDT भेद्यता) का व्यापक विश्लेषण, जिसमें IOCs, SIEMs/EDR के लिए डिटेक्शन नियम, YARA सिग्नेचर, मिटिगेशन स्क्रिप्ट और एक रक्षक के दृष्टिकोण से शैक्षिक एक्सप्लॉइट विश्लेषण शामिल है।
यह रिपॉजिटरी डिफेंडर के परिप्रेक्ष्य से Follina MSDT के बारे में बात करता है
यह बग Microsoft Windows Support Diagnostic Tool (MSDT) में एक remote code execution भेद्यता है, जिसे Shadow Chaser Group के crazyman द्वारा रिपोर्ट किया गया। Microsoft अब इसे CVE-2022-30190 के रूप में ट्रैक कर रहा है। यह दोष सभी Windows संस्करणों को प्रभावित करता है जो अभी भी सुरक्षा अपडेट प्राप्त कर रहे हैं (Windows 7+ और Server 2008+)।
जैसा कि सुरक्षा शोधकर्ता nao_sec ने पाया, इसका उपयोग खतरे के अभिनेताओं द्वारा MSDT के माध्यम से दुर्भावनापूर्ण PowerShell कमांड निष्पादित करने के लिए किया जाता है, जिसे Redmond द्वारा Arbitrary Code Execution (ACE) हमलों के रूप में वर्णित किया गया है, जब Word दस्तावेज़ खोले या पूर्वावलोकन किए जाते हैं।
"एक हमलावर जो इस भेद्यता का सफलतापूर्वक शोषण करता है, वह कॉलिंग एप्लिकेशन के विशेषाधिकारों के साथ मनमाना कोड चला सकता है," Microsoft बताता है।
खतरे का शिकार करने के लिए आप Sigma नियम यहाँ पा सकते हैं।
नीचे पहचान नियम दिए गए हैं जिन्हें और अधिक ट्यून किया जा सकता है। बाला गणेश का धन्यवाद। पूरा लेख यहाँ पाया जा सकता है।
MS Defender:
DeviceProcessEvents | where ((ProcessCommandLine contains "WINWORD.EXE") and (ProcessCommandLine contains "msdt.exe") and (ProcessCommandLine contains "sdiagnhost.exe" or ProcessCommandLine contains "csc.exe" or ProcessCommandLine contains "PCWDiagnostic" or ProcessCommandLine contains "IT_ReBrowserForFile" or ProcessCommandLine contains "IT_BrowserForFile" or ProcessCommandLine contains "conhost.exe"))
[Doc Malware]
alert.severity = 2
description = Detection (Rule ID: 74566a6a66aaasdq2ed)
cron_schedule = 0 * * * *
disabled = 1
is_scheduled = 1
is_visible = 1
dispatch.earliest_time = -60m@m
dispatch.latest_time = now
search = (source="WinEventLog:*" AND (CommandLine="*WINWORD.EXE*") AND (CommandLine="*msdt.exe*") AND (CommandLine="*sdiagnhost.exe*" OR CommandLine="*csc.exe*" OR CommandLine="*PCWDiagnostic*" OR CommandLine="*IT_ReBrowserForFile*" OR CommandLine="*IT_BrowserForFile*" OR CommandLine="*conhost.exe*"))
alert.suppress = 0
alert.track = 1
SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Process CommandLine" ilike '%WINWORD.EXE%') and ("Process CommandLine" ilike '%msdt.exe%') and ("Process CommandLine" ilike '%sdiagnhost.exe%' or "Process CommandLine" ilike '%csc.exe%' or "Process CommandLine" ilike '%PCWDiagnostic%' or "Process CommandLine" ilike '%IT_ReBrowserForFile%' or "Process CommandLine" ilike '%IT_BrowserForFile%' or "Process CommandLine" ilike '%conhost.exe%')
(CommandLine.keyword:*WINWORD.EXE* AND CommandLine.keyword:*msdt.exe* AND CommandLine.keyword:(*sdiagnhost.exe* *csc.exe* *PCWDiagnostic* *IT_ReBrowserForFile* *IT_BrowserForFile* *conhost.exe*))
Sumologic
(_sourceCategory=*windows* AND (CommandLine = "*WINWORD.EXE*") AND (CommandLine = "*msdt.exe*") AND (CommandLine = "*sdiagnhost.exe*" OR CommandLine = "*csc.exe*" OR CommandLine = "*PCWDiagnostic*" OR CommandLine = "*IT_ReBrowserForFile*" OR CommandLine = "*IT_BrowserForFile*" OR CommandLine = "*conhost.exe*"))
(process.command_line:*WINWORD.EXE* AND process.command_line:*msdt.exe* AND process.command_line:(*sdiagnhost.exe* OR *csc.exe* OR *PCWDiagnostic* OR *IT_ReBrowserForFile* OR *IT_BrowserForFile* OR *conhost.exe*))
नीचे Brent Murphy द्वारा वर्णित क्वेरी यहाँ भी लागू की जा सकती है
process where event.type in ("start" , "process_created") and (process.pe.original_file_name : "msdt.exe" or process.name : "msdt.exe") and (process.parent.pe.original_file_name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe") or process.parent.name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe"))
# office processes spawning msdt.exe
config case_sensitive = false timeframe = 30d
| dataset = xdr_data
| filter event_type = ENUM.PROCESS and action_process_image_command_line contains "msdt.exe" and actor_process_image_name in ("winword.exe", "powerpnt.exe", "excel.exe", "msaccess.exe","visio.exe","onenote.exe","powershell.exe")
| fields agent_hostname , action_process_image_command_line , action_process_image_path , actor_process_command_line , actor_process_image_path , causality_actor_process_image_path
# msdt.exe execution with suspicious argument