Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2022-30190 | Kitploit
도구/GitHubGitHub/gyaansastra/cve-2022-30190
Indicator of Compromise (IOC) ManagementVulnerability AnalysisExploitationForensicsMalware AnalysisThreat IntelligenceLearning & EducationIncident Response
GitHubgyaansastra/cve-2022-30190

CVE-2022-30190

저장소 보기
224년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2022-30190

이 저장소는 Defender 관점에서 Follina MSDT에 대해 다룹니다.

색인

  • 소개
  • 타임라인
  • 익스플로잇 이해하기
  • IOC 목록
  • 탐지 전략
  • 테스트 및 연구
  • 완화 계획
  • 참고 자료

소개

이 버그는 Shadow Chaser Group의 crazyman이 보고한 Microsoft Windows 지원 진단 도구(MSDT) 원격 코드 실행 취약점입니다. Microsoft는 현재 이를 CVE-2022-30190로 추적하고 있습니다. 이 결함은 여전히 보안 업데이트를 받는 모든 Windows 버전(Windows 7 이상 및 Server 2008 이상)에 영향을 미칩니다.

보안 연구원 nao_sec이 발견한 바와 같이, 이 취약점은 위협 행위자가 Word 문서를 열거나 미리 보기할 때 MSDT를 통해 악성 PowerShell 명령을 실행하는 데 사용되며, Microsoft는 이를 임의 코드 실행(ACE) 공격으로 설명합니다.

Microsoft는 "이 취약점을 성공적으로 악용한 공격자는 호출 애플리케이션의 권한으로 임의 코드를 실행할 수 있습니다"라고 설명합니다.

타임라인

  • 2022년 4월 12일 — APT 헌팅 그룹인 Shadowchasing1의 리더가 Microsoft MSRC에 최초 보고했습니다. 이 문서는 러시아를 표적으로 한 실제 환경(in the wild)의 실전 악용으로, 러시아 구인 면접을 가장한 것입니다.
  • 2022년 4월 21일 — Microsoft MSRC가 보안 관련 문제가 아니라며 티켓을 종료했습니다 (참고로, 매크로가 비활성화된 상태에서 msdt가 실행되는 것은 문제입니다).
  • 2022년 5월 ??일 — Microsoft가 Office 365 Insider 채널에서 이 문제를 수정하려 했거나 우연히 수정했을 수 있지만, CVE를 문서화하거나 어디에도 기록하지 않았습니다. 다른 제품은 여전히 취약합니다.
  • 2022년 5월 27일 — 보안 업체 Nao가 벨라루스에서 업로드된 문서를 트윗했으며, 이 역시 실제 환경(in the wild) 공격입니다.
  • 2022년 5월 27일 — MSRC에 다시 보고되었습니다.
  • 2022년 5월 29일 — Andy Ful이 이를 공개적으로 제로데이로 확인했습니다. Office 365 Semi-Annual 채널과 '온프레미스(on-prem)' Office 버전에서 여전히 동작하며, EDR 제품도 탐지하지 못하고 있습니다.

익스플로잇 이해하기

  • 이 익스플로잇의 작동 원리에 대한 전체 세부 사항을 이해하려면 Huntress 블로그 여기를 참조하세요.
  • 익스플로잇과 그 대응 방법을 이해하려면 이 비디오를 시청하세요.

IOC 목록

  • 주요 오브젝트 - 05-2022-0438.doc
    • sha256 4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784
    • sha1 06727ffda60359236a8029e0b3e8a0fd11c23313
    • md5 52945af1def85b171870b31fa4782e52
  • 드롭된 실행 파일
    • sha256 C:\Users\admin\AppData\Local\Temp\SDIAG_ecb8c0a2-7a1e-4b6c-8ae0-2245f03bcc15\DiagPackage.dll 3218488d62cb0858101d2ec63ec73a032bc9787f5f87cb46abbea4477c97b16f
    • sha256 C:\Users\admin\AppData\Local\Temp\SDIAG_ecb8c0a2-7a1e-4b6c-8ae0-2245f03bcc15\en-US\DiagPackage.dll.mui c6d837ec0850e22c83b400fcded1791a2f4f99f0c56d6fc7d93e92a8b72c098d
    • sha256 C:\Users\admin\AppData\Local\Temp\r5qxr4ie.dll aa967ae9f6d80bdbd0f315defa17aaee0e756e7e2ad0e5261d8254bc0af1cc02
    • sha256 C:\Users\admin\AppData\Local\Temp\t52wyhbe.dll daf716cbe8810085251e6ef1e39869a9e61d929fac12ea5684c3b2caf993666b
    • sha256 C:\Users\admin\AppData\Local\Temp\qtwoghs1.dll f5361b6c9db8ac25433ae21f9a7b6490cc372ce2b1f802e2b06d5b904ce97109
  • DNS 요청
    • domain www[.]xmlformats[.]com
  • 연결
    • ip 141.105.65.149
    • ip 20.42.65.85
    • ip 13.107.42.16
  • HTTP/HTTPS 요청
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/wordprocessingDrawing/
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/wordprocessingDrawing/RDF842l[.]html

탐지 전략

  • 위협 헌팅을 수행하려면 Sigma 규칙을 여기에서 찾을 수 있습니다.

  • 아래는 추가로 튜닝할 수 있는 탐지 규칙입니다. Bala Ganesh에게 감사를 표합니다. 전체 문서는 여기에서 확인할 수 있습니다.

  • MS Defender:

root@kitploit:~
DeviceProcessEvents | where ((ProcessCommandLine contains "WINWORD.EXE") and (ProcessCommandLine contains "msdt.exe") and (ProcessCommandLine contains "sdiagnhost.exe" or ProcessCommandLine contains "csc.exe" or ProcessCommandLine contains "PCWDiagnostic" or ProcessCommandLine contains "IT_ReBrowserForFile" or ProcessCommandLine contains "IT_BrowserForFile" or ProcessCommandLine contains "conhost.exe"))
  • Splunk:
root@kitploit:~
[Doc Malware]
alert.severity = 2
description = Detection (Rule ID: 74566a6a66aaasdq2ed)
cron_schedule = 0 * * * *
disabled = 1
is_scheduled = 1
is_visible = 1
dispatch.earliest_time = -60m@m
dispatch.latest_time = now
search = (source="WinEventLog:*" AND (CommandLine="*WINWORD.EXE*") AND (CommandLine="*msdt.exe*") AND (CommandLine="*sdiagnhost.exe*" OR CommandLine="*csc.exe*" OR CommandLine="*PCWDiagnostic*" OR CommandLine="*IT_ReBrowserForFile*" OR CommandLine="*IT_BrowserForFile*" OR CommandLine="*conhost.exe*"))
alert.suppress = 0
alert.track = 1
  • Qradar:
root@kitploit:~
SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Process CommandLine" ilike '%WINWORD.EXE%') and ("Process CommandLine" ilike '%msdt.exe%') and ("Process CommandLine" ilike '%sdiagnhost.exe%' or "Process CommandLine" ilike '%csc.exe%' or "Process CommandLine" ilike '%PCWDiagnostic%' or "Process CommandLine" ilike '%IT_ReBrowserForFile%' or "Process CommandLine" ilike '%IT_BrowserForFile%' or "Process CommandLine" ilike '%conhost.exe%')
  • GrayLog
root@kitploit:~
(CommandLine.keyword:*WINWORD.EXE* AND CommandLine.keyword:*msdt.exe* AND CommandLine.keyword:(*sdiagnhost.exe* *csc.exe* *PCWDiagnostic* *IT_ReBrowserForFile* *IT_BrowserForFile* *conhost.exe*))
Sumologic
(_sourceCategory=*windows* AND (CommandLine = "*WINWORD.EXE*") AND (CommandLine = "*msdt.exe*") AND (CommandLine = "*sdiagnhost.exe*" OR CommandLine = "*csc.exe*" OR CommandLine = "*PCWDiagnostic*" OR CommandLine = "*IT_ReBrowserForFile*" OR CommandLine = "*IT_BrowserForFile*" OR CommandLine = "*conhost.exe*"))
  • Elastic KQL:
root@kitploit:~
(process.command_line:*WINWORD.EXE* AND process.command_line:*msdt.exe* AND process.command_line:(*sdiagnhost.exe* OR *csc.exe* OR *PCWDiagnostic* OR *IT_ReBrowserForFile* OR *IT_BrowserForFile* OR *conhost.exe*))

Brent Murphy가 여기에서 설명한 아래 쿼리도 적용할 수 있습니다

root@kitploit:~
process where event.type in ("start" , "process_created") and (process.pe.original_file_name : "msdt.exe" or process.name : "msdt.exe") and (process.parent.pe.original_file_name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe") or process.parent.name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe"))
  • Cortex XDR에서 XQL 검색을 사용하여 이 공격을 헌팅할 수 있습니다: 자세한 내용은 여기에서 확인하세요.
root@kitploit:~
# office processes spawning msdt.exe

config case_sensitive = false timeframe = 30d
| dataset = xdr_data
| filter event_type = ENUM.PROCESS and action_process_image_command_line contains "msdt.exe" and actor_process_image_name in ("winword.exe", "powerpnt.exe", "excel.exe", "msaccess.exe","visio.exe","onenote.exe","powershell.exe")
| fields agent_hostname , action_process_image_command_line , action_process_image_path , actor_process_command_line , actor_process_image_path , causality_actor_process_image_path

# msdt.exe execution with suspicious argument

config case_sensitive = false timeframe = 30d
| dataset = xdr_data
| filter event_type = ENUM.PROCESS and action_process_image_command_line contains "msdt.exe" and
action_process_image_command_line contains "it_browseforfile"
| fields agent_hostname , action_process_image_command_line , action_process_image_path , actor_process_command_line , actor_process_image_path , causality_actor_process_image_path
  • 동작 헌팅 외에도 레지스트리 키 *HKEY_USERS*SID\SOFTWARE\Microsoft\Office\16.0\Common\Internet\Server Cache**를 대규모로 쿼리하고 결과를 분석하는 것도 유용합니다! 전체 게시물은 여기를 참조하세요.
  • Velociraptor는 악성 Office 문서에서 가능한 C2 URL을 식별하기 위해 Return Office Internet Server Cache 레지스트리 키와 값을 탐지하는 로직을 여기에 만들었습니다.
  • Joe Security가 개발한 YARA 규칙은 여기에서 찾을 수 있습니다.
  • CrowdStrike 쿼리는 아래와 같이 수행할 수 있습니다-
root@kitploit:~
index=main (ProcessRollup2 OR SyntheticProcessRollup2 OR ProcessBlocked*) ParentBaseFileName IN ("OUTLOOK.EXE","WINWORD.EXE","EXCEL.EXE") CommandLine="*msdt.exe*"
| table ComputerName ParentBaseFileName CommandLine FileName
  • 실행 시 %localappdata%\Diagnostics 및 %localappdata%\ElevatedDiagnostics(상승된 인스턴스의 경우) 안에 "PCW.debugreport.xml" 파일이 생성되며, 이 파일에는 페이로드가 포함되어 있습니다. 여기에서 확인하세요.
  • 현재 버전의 개념 증명(PoC)은 Microsoft Office 애플리케이션에서 msdt.exe를 호출합니다. CrowdStrike Falcon을 위한 일반화된 헌팅 쿼리는 여기에서 찾을 수 있습니다:
root@kitploit:~
index=main sourcetype=ProcessRollup* event_simpleName=ProcessRollup2
| search ParentBaseFileName IN (winword.exe, excel.exe, powerpnt.exe, outlook.exe) 
| search FileName=msdt.exe
| table _time, aid, ComputerName, UserName, UserSid_readable, ParentBaseFileName, FileName, CommandLine
| lookup local=true aid_master aid OUTPUT AgentVersion, Version, MachineDomain, OU, SiteName
  • 환경에서 정상적인 msdt.exe 사용을 추가로 프로파일링하고 기준을 설정하려면 CrowdStrike Falcon에서 다음 쿼리를 사용할 수 있습니다:
root@kitploit:~
index=main sourcetype=ProcessRollup* event_simpleName=ProcessRollup2
| search FileName=msdt.exe
| eval FileName=lower(FileName)
| eval ParentBaseFileName=lower(ParentBaseFileName)
| stats dc(aid) as endpointCount, count(aid) as executionCount by FileName, ParentBaseFileName
| sort -executionCount
  • Elastic Security 팀은 SIEM용 기존 규칙을 업데이트하고 msdt.exe를 lolbin으로 취급하는 새 규칙을 추가했습니다. 탐지 규칙1 및 규칙2을 확인하세요.
  • MS Sentinel을 사용하는 경우 아래를 사용할 수 있습니다-
root@kitploit:~
#Detects the exploitation of Follina Microsoft Code Execution vulnerability

SecurityEvent 
| where EventID==4688 
| where ParentProcessName has_any ('winword.exe','excel.exe','outlook.exe') 
| where NewProcessName contains "msdt.exe" or CommandLine contains "msdt.exe"
| project TimeGenerated, NewProcessId, NewProcessName, ParentProcessName, CommandLine, EventID, Activity, Computer

#The below query could return false-positives please verify the output and modify the query according to your environment.

SecurityEvent 
| where EventID==4688 
| where ParentProcessName has_any ('sdiagnhost.exe', 'msdt.exe')
//| where NewProcessName contains "powershell" or NewProcessname contains "cmd.exe"  //optional: you can include this line for directly finding powershell or cmd process spawns
| project TimeGenerated, NewProcessId, NewProcessName, ParentProcessName, CommandLine, EventID, Activity, Computer

테스트 및 연구

⚠⚠아래 내용은 연구 및 학습 목적으로만 사용하세요

  • 첨부된 샘플을 활용하세요
  • John Hammond가 만든 훌륭한 코드와 플랫폼을 여기에서 활용하세요
  • 무기화된 CVE-2021-40444는 여기에서 찾을 수 있습니다
  • Cas van Cooten이 만든 이 PoC를 여기에서 활용하세요

완화 계획

  • Microsoft의 공식 대응이 나올 때까지 ms-msdt 프로토콜 처리기를 제거하는 것이 가장 안전한 완화 방법일 가능성이 높습니다. 대규모 엔터프라이즈 환경에서는 이 방법을 테스트하지 않았으므로, 프로토콜 처리기를 광범위하게 비활성화할 경우 부수적인 영향이 있을 수 있습니다. 그러나 성공적인 악용(임의 코드 실행)의 영향을 고려할 때, 이는 합리적인 위험 기반 접근 방식으로 보입니다(최소한 Office 문서가 열리는 모든 시스템에서는). 프로토콜 처리기 제거는 관리자 명령 프롬프트에서 다음 명령을 실행하는 것만큼 간단합니다:
root@kitploit:~
reg delete HKEY_CLASSES_ROOT\ms-msdt /f

***패치가 제공되면 레지스트리에 다시 병합할 수 있도록, 이 키의 내용을 삭제하기 전에 백업해 두어야 합니다.

  • 아래 PS 스크립트를 사용하여 레지스트리 수정을 수행할 수 있습니다. Kelvin Tegelaar에게 감사를 표합니다.
root@kitploit:~
$ENV:ActivateWorkaround = "Yes"
if($ENV:ActivateWorkaround -eq "Yes") {
    New-PSDrive -PSProvider registry -Root HKEY_CLASSES_ROOT -Name HKCR
    Set-Item -Path "HKCR:\ms-msdt" -Value "URL:ms-msdt_bak"
    Rename-Item -Path "HKCR:\ms-msdt" -newName "ms-msdt_bak"
} else {
    New-PSDrive -PSProvider registry -Root HKEY_CLASSES_ROOT -Name HKCR
    Rename-Item -Path "HKCR:\ms-msdt_bak" -newName "ms-msdt"

    Set-Item -Path "HKCR:\ms-msdt" -Value "URL:ms-msdt"
}

  • 사용자에게 첨부 파일이 포함된 이메일은 반드시 신고하고 열지 말도록 교육하세요. 이 취약점은 단순히 마우스를 올려놓기만 해도 악용될 수 있습니다. 따라서 최종 사용자는 반드시 주의해야 합니다.
  • 환경에서 Microsoft Defender의 공격 표면 축소(ASR) 규칙을 활용하는 경우, "모든 Office 애플리케이션이 자식 프로세스를 만들지 차단" 규칙을 차단(Block) 모드로 활성화하면 이 취약점의 악용을 방지할 수 있습니다. 그러나 아직 ASR을 사용하지 않는다면 먼저 감사(Audit) 모드로 규칙을 실행하고 최종 사용자에게 부정적인 영향이 없는지 결과를 모니터링하는 것이 좋습니다.

참고 자료

  • https://thehackernews.com/2022/05/watch-out-researchers-spot-new.html
  • https://reaqta.com/2022/05/threat-analysis-msdt-exploit-with-maldocs/
  • https://www.joesandbox.com/analysis/636202/0/html
  • https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-mitigation-for-office-zero-day-exploited-in-attacks/
  • https://nakedsecurity.sophos.com/2022/05/31/mysterious-follina-zero-day-hole-in-office-what-to-do/
  • https://www.theregister.com/2022/05/30/follina_microsoft_office_vulnerability/
  • https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/
  • https://unit42.paloaltonetworks.com/cve-2022-30190-msdt-code-execution-vulnerability/
도구 다운로드