macOS 入門ブログシリーズの続きとして、XProtect に短いブログ投稿を割り当てることにしました。
XProtect は、macOS に組み込まれている Apple のウイルス対策・マルウェアシグネチャシステムです。
これは XProtectService の一部として動作し、アプリケーションやその他の実行可能コンテンツを既知のマルウェアシグネチャと照合してスキャンします。
XProtect はバックグラウンドで動作し、Apple が XProtectRemediator メカニズムを通じて静かに更新します(詳細は後述)。
主な機能は3つあります:
/Library/Apple/System/Library/CoreServices/XProtect.bundle ディレクトリは、XProtect の構成とシグネチャ定義を含むメインバンドルです。
これは読み取り専用のシステムディレクトリで、Apple が XProtect アップデートを通じて静かに更新します。
この下には、Apple が定期的に更新し、システム整合性保護(SIP) によって保護されている、注目すべきファイルがいくつかあります。
/Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.plist ファイルには、XProtect が既知の脅威を検出するために使用するマルウェアシグネチャが格納されています。
マルウェアファミリーを、ハッシュやファイル名パターンを含む特定の検出ルールにマッピングするエントリが含まれています。
以下は、あるマルウェアファミリー – Bundalore の例です:
<dict>
<key>Description</key>
<string>OSX.Bundlore.D</string>
<key>LaunchServices</key>
<dict>
<key>LSItemContentType</key>
<string>com.apple.application-bundle</string>
</dict>
<key>Matches</key>
<array>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>46617364554153</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>20006500630068006F002000</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>20007C0020006F00700065006E00730073006C00200065006E00630020002D006100650073002D003200350036002D0063006600620020002D007000610073007300200070006100730073003A</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073</string>
</dict>
</array>
</dict>
これはかなり人間が読みやすい形式です。注目すべき唯一の点は、各マッチの string 引数が16進数表現であることです。例えば 002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073 は -salt -A -a -d | bash -s に対応します。
これはもちろん、回避すべきパターンを正確に知っているマルウェア作者にとっては宝の山です。
/Library/Apple/System/Library/CoreServices/XProtect.bundle/XProtect.meta.plist ファイルは、適用ポリシーやバージョン情報など、XProtect の追加ルールを定義するメタデータファイルです。
どの macOS バージョンが特定の XProtect ルールを適用するか、検出時に実行されるアクション、およびプラグインのブラックリストを指定します。
以下はその例です:
<key>JavaWebComponentVersionMinimum</key>
<string>1.6.0_45-b06-451</string>
<key>PlugInBlacklist</key>
<dict>
<key>10</key>
<dict>
<key>com.apple.java.JavaAppletPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>14.8.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.apple.java.JavaPlugin2_NPAPI</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>14.8.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.macromedia.Flash Player ESR.plugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>18.0.0.382</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.macromedia.Flash Player.plugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>32.0.0.101</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.microsoft.SilverlightPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>5.1.41212.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.oracle.java.JavaAppletPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>1.8.51.16</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
</dict>
</dict>
ご覧のとおり、これらには例えば「ブラックリスト登録された」プラグインのバージョン情報が含まれています。
最近のバージョンでは、XProtect は YARA のサポートを開始したようです。
/Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.yara ファイルには、テキスト形式の YARA ルールがいくつか含まれています。以下はその短い例です:
rule XProtect_MACOS_SLEEPYSTEGOSAURUS_SYM {
meta:
description = "MACOS.SLEEPYSTEGOSAURUS.SYM"
uuid = "BB4F7D16-C939-4047-A9AF-E74E7B51FAC1"
strings:
$a1 = { 45 78 65 63 43 6D 64 }
$a2 = { 47 65 74 48 6F 73 74 49 6E 66 6F }
$a3 = { 52 75 6E 53 63 72 69 70 74 }
$a4 = { 52 75 6E 53 63 72 69 70 74 55 72 6C }
$a5 = { 4C 61 75 6E 63 68 50 6C 69 73 74 }
$a6 = { 43 68 65 63 6B 50 72 6F 63 65 73 73 }
$a7 = { 43 68 65 63 6B 49 6E }
$a8 = { 52 75 6E 43 6D 64 46 69 6C 65 }
$a9 = { 53 68 6F 77 48 74 6D 6C }
$a10 = { 50 6C 69 73 74 48 65 6C 70 65 72 }
$a11 = { 4C 61 75 6E 63 68 64 48 65 6C 70 65 72 }
$a12 = { 43 6F 6D 6D 61 6E 64 46 69 6C 65 }
$a13 = { 57 72 69 74 65 50 6C 69 73 74 }
$a14 = { 4A 53 4F 4E 46 69 6C 65 50 72 6F 63 65 73 73 6F 72 }
$a15 = { 43 68 72 6F 6D 65 48 65 6C 70 65 72 }
$a16 = { 53 61 6E 64 62 6F 78 65 72 }
condition:
Macho and filesize < 2MB and all of them
}
これは YARA ルールに関するブログ投稿ではありませんが、前述のとおり、これもマルウェア作者にとっては宝の山です(例: 43 68 65 63 6B 50 72 6F 63 65 73 73 は CheckProcess)。