Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
MSDT_CVE-2022-30190 — 这个仓库从Defender视角讨论Follina MSDT。 | Kitploit
工具/GitHubGitHub/archanchoudhury/msdt_cve-2022-30190
危害指标 (IOC) 管理漏洞分析恶意软件分析威胁情报学习与教育事件响应
GitHubarchanchoudhury/msdt_cve-2022-30190

MSDT_CVE-2022-30190

这个仓库从Defender视角讨论Follina MSDT。

查看仓库
3710334年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

MSDT_CVE-2022-30190

本仓库从 Defender 视角讨论 Follina MSDT 漏洞

目录

  • 关于
  • 时间线
  • 理解漏洞利用
  • IOC 列表
  • 检测策略
  • 测试与研究
  • 缓解方案
  • 参考

关于

该漏洞是 Microsoft Windows 支持诊断工具 (MSDT) 的远程代码执行漏洞,由 Shadow Chaser Group 的 crazyman 报告。Microsoft 现已将其跟踪为 CVE-2022-30190。该漏洞影响所有仍在接收安全更新的 Windows 版本(Windows 7+ 及 Server 2008+)。

正如安全研究员 nao_sec 发现的,威胁行为者利用该漏洞通过 MSDT 执行恶意 PowerShell 命令,Microsoft 将其描述为打开或预览 Word 文档时的任意代码执行 (ACE) 攻击。

"成功利用此漏洞的攻击者可以以调用应用程序的权限运行任意代码," Microsoft 解释道。

时间线

  • 2022年4月12日 — APT 狩猎组织 Shadowchasing1 的负责人首次向 Microsoft MSRC 报告。该文档是一个针对俄罗斯的野外真实世界漏洞利用,以俄罗斯求职面试为主题。
  • 2022年4月21日 — Microsoft MSRC 关闭了工单,称这不是安全问题(值得注意的是,在宏禁用的情况下 msdt 仍能执行确实是个问题)
  • 2022年5月??日 — Microsoft 可能曾在 Office 365 Insider 频道中尝试修复或意外修复了该问题,但没有记录 CVE 或任何地方的书面说明。其他产品仍然存在漏洞。
  • 2022年5月27日 — 安全厂商 Nao 在 Twitter 上发布了一份来自白俄罗斯的上传文档,这也是一次野外攻击。
  • 2022年5月27日 — 再次向 MSRC 报告。
  • 2022年5月29日 — Andy Ful 公开确认这是一次零日攻击,因为它仍然适用于 Office 365 Semi Annual 频道以及 'on prem' Office 版本,并且 EDR 产品未能检测到。

理解漏洞利用

  • 您可以参考 Huntress 的博客 此处 来全面了解该漏洞利用的工作原理。
  • 观看此 视频 以理解漏洞利用及其修复方法。

IOC 列表

  • 主要对象 - 05-2022-0438.doc
    • sha256 4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784
    • sha1 06727ffda60359236a8029e0b3e8a0fd11c23313
    • md5 52945af1def85b171870b31fa4782e52
  • 释放的可执行文件
    • sha256 C:\Users\admin\AppData\Local\Temp\SDIAG_ecb8c0a2-7a1e-4b6c-8ae0-2245f03bcc15\DiagPackage.dll 3218488d62cb0858101d2ec63ec73a032bc9787f5f87cb46abbea4477c97b16f
    • sha256 C:\Users\admin\AppData\Local\Temp\SDIAG_ecb8c0a2-7a1e-4b6c-8ae0-2245f03bcc15\en-US\DiagPackage.dll.mui c6d837ec0850e22c83b400fcded1791a2f4f99f0c56d6fc7d93e92a8b72c098d
    • sha256 C:\Users\admin\AppData\Local\Temp\r5qxr4ie.dll aa967ae9f6d80bdbd0f315defa17aaee0e756e7e2ad0e5261d8254bc0af1cc02
    • sha256 C:\Users\admin\AppData\Local\Temp\t52wyhbe.dll daf716cbe8810085251e6ef1e39869a9e61d929fac12ea5684c3b2caf993666b
    • sha256 C:\Users\admin\AppData\Local\Temp\qtwoghs1.dll f5361b6c9db8ac25433ae21f9a7b6490cc372ce2b1f802e2b06d5b904ce97109
  • DNS 请求
    • 域名 www[.]xmlformats[.]com
  • 连接
    • ip 141.105.65.149
    • ip 20.42.65.85
    • ip 13.107.42.16
  • HTTP/HTTPS 请求
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/wordprocessingDrawing/
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/wordprocessingDrawing/RDF842l[.]html

检测策略

  • 要进行威胁狩猎,您可以在此处找到 Sigma 规则 此处

  • 以下是可进一步调整的检测规则。感谢 Bala Ganesh。完整文章见 此处

  • MS Defender:

DeviceProcessEvents | where ((ProcessCommandLine contains "WINWORD.EXE") and (ProcessCommandLine contains "msdt.exe") and (ProcessCommandLine contains "sdiagnhost.exe" or ProcessCommandLine contains "csc.exe" or ProcessCommandLine contains "PCWDiagnostic" or ProcessCommandLine contains "IT_ReBrowserForFile" or ProcessCommandLine contains "IT_BrowserForFile" or ProcessCommandLine contains "conhost.exe"))
  • Splunk:
[Doc Malware]
alert.severity = 2
description = Detection (Rule ID: 74566a6a66aaasdq2ed)
cron_schedule = 0 * * * *
disabled = 1
is_scheduled = 1
is_visible = 1
dispatch.earliest_time = -60m@m
dispatch.latest_time = now
search = (source="WinEventLog:*" AND (CommandLine="*WINWORD.EXE*") AND (CommandLine="*msdt.exe*") AND (CommandLine="*sdiagnhost.exe*" OR CommandLine="*csc.exe*" OR CommandLine="*PCWDiagnostic*" OR CommandLine="*IT_ReBrowserForFile*" OR CommandLine="*IT_BrowserForFile*" OR CommandLine="*conhost.exe*"))
alert.suppress = 0
alert.track = 1
  • Qradar:
SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Process CommandLine" ilike '%WINWORD.EXE%') and ("Process CommandLine" ilike '%msdt.exe%') and ("Process CommandLine" ilike '%sdiagnhost.exe%' or "Process CommandLine" ilike '%csc.exe%' or "Process CommandLine" ilike '%PCWDiagnostic%' or "Process CommandLine" ilike '%IT_ReBrowserForFile%' or "Process CommandLine" ilike '%IT_BrowserForFile%' or "Process CommandLine" ilike '%conhost.exe%')
  • GrayLog
(CommandLine.keyword:*WINWORD.EXE* AND CommandLine.keyword:*msdt.exe* AND CommandLine.keyword:(*sdiagnhost.exe* *csc.exe* *PCWDiagnostic* *IT_ReBrowserForFile* *IT_BrowserForFile* *conhost.exe*))
Sumologic
(_sourceCategory=*windows* AND (CommandLine = "*WINWORD.EXE*") AND (CommandLine = "*msdt.exe*") AND (CommandLine = "*sdiagnhost.exe*" OR CommandLine = "*csc.exe*" OR CommandLine = "*PCWDiagnostic*" OR CommandLine = "*IT_ReBrowserForFile*" OR CommandLine = "*IT_BrowserForFile*" OR CommandLine = "*conhost.exe*"))
  • Elastic KQL:
(process.command_line:*WINWORD.EXE* AND process.command_line:*msdt.exe* AND process.command_line:(*sdiagnhost.exe* OR *csc.exe* OR *PCWDiagnostic* OR *IT_ReBrowserForFile* OR *IT_BrowserForFile* OR *conhost.exe*))

以下查询由 Brent Murphy 描述,见 此处,也可使用:

process where event.type in ("start" , "process_created") and (process.pe.original_file_name : "msdt.exe" or process.name : "msdt.exe") and (process.parent.pe.original_file_name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe") or process.parent.name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe"))
  • 您可以使用 Cortex XDR 中的 XQL 搜索来狩猎此攻击:了解更多 此处
# office processes spawning msdt.exe

config case_sensitive = false timeframe = 30d
| dataset = xdr_data
| filter event_type = ENUM.PROCESS and action_process_image_command_line contains "msdt.exe" and actor_process_image_name in ("winword.exe", "powerpnt.exe", "excel.exe", "msaccess.exe","visio.exe","onenote.exe","powershell.exe")
| fields agent_hostname , action_process_image_command_line , action_process_image_path , actor_process_command_line , actor_process_image_path , causality_actor_process_image_path

# msdt.exe execution with suspicious argument

config case_sensitive = false timeframe = 30d
| dataset = xdr_data
| filter event_type = ENUM.PROCESS and action_process_image_command_line contains "msdt.exe" and
action_process_image_command_line contains "it_browseforfile"
| fields agent_hostname , action_process_image_command_line , action_process_image_path , actor_process_command_line , actor_process_image_path , causality_actor_process_image_path
下载工具