继续我关于 macOS 介绍的博客系列,我决定用一篇简短的博文专门介绍 XProtect。
XProtect 是 Apple 为 macOS 内置的防病毒和恶意软件签名系统。
它作为 XProtectService 的一部分运行,扫描应用程序和其他可执行内容以查找已知的恶意软件签名。
XProtect 在后台运行,由 Apple 通过 XProtectRemediator 机制静默更新(稍后会详细介绍)。
它有 3 个主要功能:
目录 /Library/Apple/System/Library/CoreServices/XProtect.bundle 是包含 XProtect 配置和签名定义的主 bundle。
这是一个只读的系统目录,由 Apple 通过 XProtect 更新静默更新。
在其下,我们可以找到一些值得关注的文件,这些文件都由 Apple 定期更新,并受 System Integrity Protection (SIP) 保护。
文件 /Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.plist 存储 XProtect 用于检测已知威胁的恶意软件签名。
它包含将恶意软件家族映射到特定检测规则的条目,包括哈希和文件名模式。
以下是其中一个恶意软件家族——Bundalore 的示例:
<dict>
<key>Description</key>
<string>OSX.Bundlore.D</string>
<key>LaunchServices</key>
<dict>
<key>LSItemContentType</key>
<string>com.apple.application-bundle</string>
</dict>
<key>Matches</key>
<array>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>46617364554153</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>20006500630068006F002000</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>20007C0020006F00700065006E00730073006C00200065006E00630020002D006100650073002D003200350036002D0063006600620020002D007000610073007300200070006100730073003A</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073</string>
</dict>
</array>
</dict>
这相当易读,唯一值得注意的是每个匹配中的 string 参数是十六进制表示,例如 002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073 对应 -salt -A -a -d | bash -s。
当然,这对恶意软件作者来说是一个金矿,因为他们确切知道要避免哪些模式。
文件 /Library/Apple/System/Library/CoreServices/XProtect.bundle/XProtect.meta.plist 是一个元数据文件,为 XProtect 定义附加规则,包括执行策略和版本信息。
它指定了哪些 macOS 版本强制执行某些 XProtect 规则、检测到威胁后采取的操作,以及插件黑名单。
以下是一个示例:
<key>JavaWebComponentVersionMinimum</key>
<string>1.6.0_45-b06-451</string>
<key>PlugInBlacklist</key>
<dict>
<key>10</key>
<dict>
<key>com.apple.java.JavaAppletPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>14.8.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.apple.java.JavaPlugin2_NPAPI</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>14.8.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.macromedia.Flash Player ESR.plugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>18.0.0.382</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.macromedia.Flash Player.plugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>32.0.0.101</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.microsoft.SilverlightPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>5.1.41212.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.oracle.java.JavaAppletPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>1.8.51.16</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
</dict>
</dict>
如你所见,这些包含“黑名单”插件的版本信息,例如。
在最近的版本中,XProtect 似乎开始支持 YARA。
文件 /Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.yara 包含若干文本格式的 YARA 规则,以下是其中的一个简短示例:
rule XProtect_MACOS_SLEEPYSTEGOSAURUS_SYM {
meta:
description = "MACOS.SLEEPYSTEGOSAURUS.SYM"
uuid = "BB4F7D16-C939-4047-A9AF-E74E7B51FAC1"
strings:
$a1 = { 45 78 65 63 43 6D 64 }
$a2 = { 47 65 74 48 6F 73 74 49 6E 66 6F }
$a3 = { 52 75 6E 53 63 72 69 70 74 }
$a4 = { 52 75 6E 53 63 72 69 70 74 55 72 6C }
$a5 = { 4C 61 75 6E 63 68 50 6C 69 73 74 }
$a6 = { 43 68 65 63 6B 50 72 6F 63 65 73 73 }
$a7 = { 43 68 65 63 6B 49 6E }
$a8 = { 52 75 6E 43 6D 64 46 69 6C 65 }
$a9 = { 53 68 6F 77 48 74 6D 6C }
$a10 = { 50 6C 69 73 74 48 65 6C 70 65 72 }
$a11 = { 4C 61 75 6E 63 68 64 48 65 6C 70 65 72 }
$a12 = { 43 6F 6D 6D 61 6E 64 46 69 6C 65 }
$a13 = { 57 72 69 74 65 50 6C 69 73 74 }
$a14 = { 4A 53 4F 4E 46 69 6C 65 50 72 6F 63 65 73 73 6F 72 }
$a15 = { 43 68 72 6F 6D 65 48 65 6C 70 65 72 }
$a16 = { 53 61 6E 64 62 6F 78 65 72 }
condition:
Macho and filesize < 2MB and all of them
}
这不是一篇关于 YARA 规则的博文,但和之前一样——这对恶意软件作者来说是一个金矿(例如 43 68 65 63 6B 50 72 6F 63 65 73 73 就是 CheckProcess)。
在这里你可以看到 Apple 如何设计 XProtect 与 Gatekeeper 集成——尽管这个文件主要供 syspolicyd 使用。
文件 /Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/gk.db 是一个 SQLite 数据库,包含要阻止的文件哈希和团队 ID 的“黑名单”。
你可以使用 sqlite3 实用程序查看它: