Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
MSDT_CVE-2022-30190 — 이 저장소는 Defender 관점에서 Follina MSDT에 대해 다룹니다. | Kitploit
도구/GitHubGitHub/archanchoudhury/msdt_cve-2022-30190
Indicator of Compromise (IOC) ManagementVulnerability AnalysisMalware AnalysisThreat IntelligenceLearning & EducationIncident Response
GitHubarchanchoudhury/msdt_cve-2022-30190

MSDT_CVE-2022-30190

이 저장소는 Defender 관점에서 Follina MSDT에 대해 다룹니다.

저장소 보기
3710254년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

MSDT_CVE-2022-30190

이 저장소는 Follina MSDT를 Defender 관점에서 다루고 있습니다.

목차

  • 개요
  • 타임라인
  • 익스플로잇 이해하기
  • IOC 목록
  • 탐지 전략
  • 테스트 및 연구
  • 완화 계획
  • 참고 자료

개요

이 버그는 crazyman(Shadow Chaser Group 소속)이 보고한 Microsoft Windows 지원 진단 도구(MSDT) 원격 코드 실행 취약점입니다. Microsoft는 현재 이를 CVE-2022-30190로 추적하고 있습니다. 이 결함은 보안 업데이트를 계속 받는 모든 Windows 버전(Windows 7+ 및 Server 2008+)에 영향을 미칩니다.

보안 연구원 nao_sec이 발견한 바와 같이, 위협 행위자들이 Word 문서를 열거나 미리보기할 때 MSDT를 통해 악성 PowerShell 명령을 실행하는 데 사용되며, Microsoft는 이를 ACE(임의 코드 실행) 공격으로 설명합니다.

"이 취약점을 성공적으로 악용한 공격자는 호출 애플리케이션의 권한으로 임의 코드를 실행할 수 있습니다."라고 Microsoft는 설명합니다.

타임라인

  • 2022년 4월 12일 — APT 헌팅 그룹 Shadowchasing1의 리더가 Microsoft MSRC에 첫 번째 신고. 이 문서는 러시아를 표적으로 한 실제 야생 익스플로잇으로, 러시아 구직 면접을 주제로 함.
  • 2022년 4월 21일 — Microsoft MSRC가 보안 관련 문제가 아니라며 티켓을 종료(참고: 매크로가 비활성화된 상태에서 msdt 실행은 문제임).
  • 2022년 5월 ??일 — Microsoft가 CVE를 문서화하거나 기록하지 않고 Office 365 Insider 채널에서 이 문제를 수정했거나 실수로 수정했을 수 있음. 다른 제품은 여전히 취약함.
  • 2022년 5월 27일 — 보안 업체 Nao가 벨로루시에서 업로드된 문서를 트윗. 이 역시 야생 공격임.
  • 2022년 5월 27일 — MSRC에 다시 신고.
  • 2022년 5월 29일 — Andy Ful이 이 취약점이 Office 365 Semi Annual 채널 및 '온프레미스' Office 버전에서 여전히 작동하고 EDR 제품이 탐지에 실패하는 제로데이임을 공개적으로 확인.

익스플로잇 이해하기

  • 이 익스플로잇의 작동 원리에 대한 전체 세부 사항은 Huntress 블로그 여기를 참조하세요.
  • 익스플로잇 및 그 해결 방법을 이해하려면 이 동영상을 시청하세요.

IOC 목록

  • 주요 개체 - 05-2022-0438.doc
    • sha256 4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784
    • sha1 06727ffda60359236a8029e0b3e8a0fd11c23313
    • md5 52945af1def85b171870b31fa4782e52
  • 드롭된 실행 파일
    • sha256 C:\Users\admin\AppData\Local\Temp\SDIAG_ecb8c0a2-7a1e-4b6c-8ae0-2245f03bcc15\DiagPackage.dll 3218488d62cb0858101d2ec63ec73a032bc9787f5f87cb46abbea4477c97b16f
    • sha256 C:\Users\admin\AppData\Local\Temp\SDIAG_ecb8c0a2-7a1e-4b6c-8ae0-2245f03bcc15\en-US\DiagPackage.dll.mui c6d837ec0850e22c83b400fcded1791a2f4f99f0c56d6fc7d93e92a8b72c098d
    • sha256 C:\Users\admin\AppData\Local\Temp\r5qxr4ie.dll aa967ae9f6d80bdbd0f315defa17aaee0e756e7e2ad0e5261d8254bc0af1cc02
    • sha256 C:\Users\admin\AppData\Local\Temp\t52wyhbe.dll daf716cbe8810085251e6ef1e39869a9e61d929fac12ea5684c3b2caf993666b
    • sha256 C:\Users\admin\AppData\Local\Temp\qtwoghs1.dll f5361b6c9db8ac25433ae21f9a7b6490cc372ce2b1f802e2b06d5b904ce97109
  • DNS 요청
    • 도메인 www[.]xmlformats[.]com
  • 연결
    • ip 141.105.65.149
    • ip 20.42.65.85
    • ip 13.107.42.16
  • HTTP/HTTPS 요청
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/wordprocessingDrawing/
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/wordprocessingDrawing/RDF842l[.]html

탐지 전략

  • 위협 헌팅을 위한 Sigma 규칙은 여기에서 찾을 수 있습니다.

  • 아래는 추가로 튜닝할 수 있는 탐지 규칙입니다. Bala Ganesh에게 감사드립니다. 전체 기사는 여기에서 확인할 수 있습니다.

  • MS Defender:

root@kitploit:~
DeviceProcessEvents | where ((ProcessCommandLine contains "WINWORD.EXE") and (ProcessCommandLine contains "msdt.exe") and (ProcessCommandLine contains "sdiagnhost.exe" or ProcessCommandLine contains "csc.exe" or ProcessCommandLine contains "PCWDiagnostic" or ProcessCommandLine contains "IT_ReBrowserForFile" or ProcessCommandLine contains "IT_BrowserForFile" or ProcessCommandLine contains "conhost.exe"))
  • Splunk:
root@kitploit:~
[Doc Malware]
alert.severity = 2
description = Detection (Rule ID: 74566a6a66aaasdq2ed)
cron_schedule = 0 * * * *
disabled = 1
is_scheduled = 1
is_visible = 1
dispatch.earliest_time = -60m@m
dispatch.latest_time = now
search = (source="WinEventLog:*" AND (CommandLine="*WINWORD.EXE*") AND (CommandLine="*msdt.exe*") AND (CommandLine="*sdiagnhost.exe*" OR CommandLine="*csc.exe*" OR CommandLine="*PCWDiagnostic*" OR CommandLine="*IT_ReBrowserForFile*" OR CommandLine="*IT_BrowserForFile*" OR CommandLine="*conhost.exe*"))
alert.suppress = 0
alert.track = 1
  • Qradar:
root@kitploit:~
SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Process CommandLine" ilike '%WINWORD.EXE%') and ("Process CommandLine" ilike '%msdt.exe%') and ("Process CommandLine" ilike '%sdiagnhost.exe%' or "Process CommandLine" ilike '%csc.exe%' or "Process CommandLine" ilike '%PCWDiagnostic%' or "Process CommandLine" ilike '%IT_ReBrowserForFile%' or "Process CommandLine" ilike '%IT_BrowserForFile%' or "Process CommandLine" ilike '%conhost.exe%')
  • GrayLog
root@kitploit:~
(CommandLine.keyword:*WINWORD.EXE* AND CommandLine.keyword:*msdt.exe* AND CommandLine.keyword:(*sdiagnhost.exe* *csc.exe* *PCWDiagnostic* *IT_ReBrowserForFile* *IT_BrowserForFile* *conhost.exe*))
Sumologic
(_sourceCategory=*windows* AND (CommandLine = "*WINWORD.EXE*") AND (CommandLine = "*msdt.exe*") AND (CommandLine = "*sdiagnhost.exe*" OR CommandLine = "*csc.exe*" OR CommandLine = "*PCWDiagnostic*" OR CommandLine = "*IT_ReBrowserForFile*" OR CommandLine = "*IT_BrowserForFile*" OR CommandLine = "*conhost.exe*"))
  • Elastic KQL:
root@kitploit:~
(process.command_line:*WINWORD.EXE* AND process.command_line:*msdt.exe* AND process.command_line:(*sdiagnhost.exe* OR *csc.exe* OR *PCWDiagnostic* OR *IT_ReBrowserForFile* OR *IT_BrowserForFile* OR *conhost.exe*))

아래는 Brent Murphy가 여기에서 설명한 쿼리로도 적용 가능합니다.

root@kitploit:~
process where event.type in ("start" , "process_created") and (process.pe.original_file_name : "msdt.exe" or process.name : "msdt.exe") and (process.parent.pe.original_file_name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe") or process.parent.name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe"))
  • Cortex XDR에서 XQL 검색을 사용하여 이 공격을 헌팅할 수 있습니다. 자세한 내용은 여기에서 확인하세요.
root@kitploit:~
# office processes spawning msdt.exe

config case_sensitive = false timeframe = 30d
| dataset = xdr_data
| filter event_type = ENUM.PROCESS and action_process_image_command_line contains "msdt.exe" and actor_process_image_name in ("winword.exe", "powerpnt.exe", "excel.exe", "msaccess.exe","visio.exe","onenote.exe","powershell.exe")
| fields agent_hostname , action_process_image_command_line , action_process_image_path , actor_process_command_line , actor_process_image_path , causality_actor_process_image_path

# msdt.exe execution with suspicious argument

config case_sensitive = false timeframe = 30d
| dataset = xdr_data
| filter event_type = ENUM.PROCESS and action_process_image_command_line contains "msdt.exe" and
action_process_image_command_line contains "it_browseforfile"
| fields agent_hostname , action_process_image_command_line , action_process_image_path , actor_process_command_line , actor_process_image_path , causality_actor_process_image_path
  • 또한, 이 동작을 헌팅하는 것 외에도 레지스트리 키 *HKEY_USERS*SID\SOFTWARE\Microsoft\Office\16.0\Common\Internet\Server Cache**를 규모에 맞게 쿼리하고 결과를 분석하는 것이 유용합니다! 전체 게시물은 여기를 참조하세요.
  • Velociraptor는 악성 Office 문서에서 열린 C2 URL을 식별하기 위해 Return Office Internet Server Cache 레지스트리 키와 값을 식별하는 탐지 로직을 여기에 만들었습니다.
  • Joe Security가 개발한 YARA 규칙은 여기에서 찾을 수 있습니다.
  • Crowdstrike 쿼리는 아래와 같이 수행할 수 있습니다.
root@kitploit:~
index=main (ProcessRollup2 OR SyntheticProcessRollup2 OR ProcessBlocked*) ParentBaseFileName IN ("OUTLOOK.EXE","WINWORD.EXE","EXCEL.EXE") CommandLine="*msdt.exe*"
| table ComputerName ParentBaseFileName CommandLine FileName
  • 실행 시 생성되는 "%localappdata%\Diagnostics" 및 "%localappdata%\ElevatedDiagnostics"(상승된 인스턴스의 경우) 내의 "PCW.debugreport.xml" 파일에는 페이로드가 포함되어 있습니다. 여기에서 확인하세요.
  • 현재 개념 증명(PoC) 반복은 Microsoft Office 애플리케이션에서 msdt.exe를 호출합니다. Crowdstrike Falcon을 위한 일반화된 헌팅 쿼리는 여기에서 확인할 수 있습니다.
root@kitploit:~
index=main sourcetype=ProcessRollup* event_simpleName=ProcessRollup2
| search ParentBaseFileName IN (winword.exe, excel.exe, powerpnt.exe, outlook.exe) 
| search FileName=msdt.exe
| table _time, aid, ComputerName, UserName, UserSid_readable, ParentBaseFileName, FileName, CommandLine
| lookup local=true aid_master aid OUTPUT AgentVersion, Version, MachineDomain, OU, SiteName
  • 환경에서 정상적인 msdt.exe 사용을 추가로 프로파일링하고 기준을 설정하려면 Crowdstrike Falcon에서 다음 쿼리를 사용할 수 있습니다.
root@kitploit:~
index=main sourcetype=ProcessRollup* event_simpleName=ProcessRollup2
| search FileName=msdt.exe
| eval FileName=lower(FileName)
| eval ParentBaseFileName=lower(ParentBaseFileName)
| stats dc(aid) as endpointCount, count(aid) as executionCount by FileName, ParentBaseFileName
| sort -executionCount
  • Elastic Security 팀은 SIEM용 기존 규칙을 업데이트하고 msdt.exe를 lolbin으로 사용하는 새로운 규칙을 추가했습니다. 탐지 규칙 1 및 규칙2를 확인하세요.
  • MS Sentinel을 사용하는 경우 아래를 사용할 수 있습니다.
root@kitploit:~
#Detects the exploitation of Follina Microsoft Code Execution vulnerability

SecurityEvent 
| where EventID==4688 
| where ParentProcessName has_any ('winword.exe','excel.exe','outlook.exe') 
| where NewProcessName contains "msdt.exe" or CommandLine contains "msdt.exe"
| project TimeGenerated, NewProcessId, NewProcessName, ParentProcessName, CommandLine, EventID, Activity, Computer

#The below query could return false-positives please verify the output and modify the query according to your environment.

SecurityEvent 
| where EventID==4688 
| where ParentProcessName has_any ('sdiagnhost.exe', 'msdt.exe')
//| where NewProcessName contains "powershell" or NewProcessname contains "cmd.exe"  //optional: you can include this line for directly finding powershell or cmd process spawns
| project TimeGenerated, NewProcessId, NewProcessName, ParentProcessName, CommandLine, EventID, Activity, Computer

테스트 및 연구

⚠⚠연구 및 학습 목적으로만 아래를 사용하십시오⚠⚠

  • 첨부된 샘플을 활용하세요.
  • John Hammond가 만든 훌륭한 코드와 플랫폼 여기를 활용하세요.
  • 무기화된 CVE-2021-40444는 여기에서 찾을 수 있습니다.
  • Cas van Cooten이 만든 이 PoC 여기를 활용하세요.

완화 계획

  • Microsoft의 공식 응답이 있을 때까지 ms-msdt 프로토콜 핸들러를 제거하는 것이 가장 안전한 완화 방법일 가능성이 높습니다. 대규모 기업에서 이 방법을 테스트하지 않았으므로 프로토콜 핸들러를 광범위하게 비활성화하면 일부 부작용이 있을 수 있습니다. 그러나 성공적인 악용(임의 코드 실행)의 영향을 고려할 때, 이는 합리적인 위험 기반 접근 방식으로 보입니다(적어도 Office 문서가 열리는 모든 시스템에서). 프로토콜 핸들러를 제거하는 것은 상승된 명령 프롬프트에서 다음 명령을 실행하는 것만큼 간단합니다.
root@kitploit:~
reg delete HKEY_CLASSES_ROOT\ms-msdt /f

***패치를 사용할 수 있게 되면 레지스트리에 다시 병합할 수 있도록 삭제 전에 이 키의 내용을 백업해야 합니다.

  • 아래 PS 스크립트를 사용하여 레지스트리 수정을 수행할 수 있습니다. Kelvin Tegelaar에게 감사드립니다.
root@kitploit:~
$ENV:ActivateWorkaround = "Yes"
if($ENV:ActivateWorkaround -eq "Yes") {
    New-PSDrive -PSProvider registry -Root HKEY_CLASSES_ROOT -Name HKCR
    Set-Item -Path "HKCR:\ms-msdt" -Value "URL:ms-msdt_bak"
    Rename-Item -Path "HKCR:\ms-msdt" -newName "ms-msdt_bak"
} else {
    New-PSDrive -PSProvider registry -Root HKEY_CLASSES_ROOT -Name HKCR
    Rename-Item -Path "HKCR:\ms-msdt_bak" -newName "ms-msdt"

    Set-Item -Path "HKCR:\ms-msdt" -Value "URL:ms-msdt"
}

  • 사용자에게 첨부 파일이 포함된 이메일이 오면 항상 신고하고 열지 않도록 교육하세요. 이 취약점은 마우스를 올리는 것만으로도 악용될 수 있습니다. 따라서 최종 사용자는 반드시 주의해야 합니다.
  • 환경에서 Microsoft Defender의 ASR(공격 표면 축소) 규칙을 사용하는 경우, "모든 Office 응용 프로그램에서 자식 프로세스 생성 차단" 규칙을 차단 모드로 활성화하면 이 악용을 방지할 수 있습니다. 그러나 아직 ASR을 사용하지 않는 경우에는 먼저 감사 모드로 규칙을 실행하고 결과를 모니터링하여 최종 사용자에게 부정적인 영향이 없는지 확인하는 것이 좋습니다.

참고 자료

  • https://thehackernews.com/2022/05/watch-out-researchers-spot-new.html
  • https://reaqta.com/2022/05/threat-analysis-msdt-exploit-with-maldocs/
  • https://www.joesandbox.com/analysis/636202/0/html
  • https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-mitigation-for-office-zero-day-exploited-in-attacks/
  • https://nakedsecurity.sophos.com/2022/05/31/mysterious-follina-zero-day-hole-in-office-what-to-do/
  • https://www.theregister.com/2022/05/30/follina_microsoft_office_vulnerability/
  • https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/
  • https://unit42.paloaltonetworks.com/cve-2022-30190-msdt-code-execution-vulnerability/
도구 다운로드