安天引擎精准检测Windows CryptoAPI漏洞构造的免杀样本
图1-1 0601漏洞对恶意程序数字签名前后VT上各引擎检出情况对比
(图片源自网络)
安天引擎具有对数字签名证书的完整解析能力和本地验证功能,并有效支撑了智甲终端防御系统的在面向SCADA、专用终端等场景的纯白环境、黑白双控机制。针对此次的CVE-2020-0601漏洞,安天基于解析数字证书的能力和分析漏洞机理,迅速升级引擎,增加检测模块和规则,可有效检测各种基于该漏洞制作的免杀工具“签发”的文件样本。从报警优先级别上看,如发现被仿冒“签发”的文件,是已知病毒,则告警已知病毒名称(如图2-1)所示;对被仿冒“签发”的文件未检测到已知病毒的,则告警为CVE-2020-0601漏洞编号,(如图2-2)所示。
[1]CVE-2020-0601 | Windows CryptoAPI Spoofing Vulnerability
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601
[2]关于安天智甲终端防御系统
[3]对Stuxnet蠕虫攻击工业控制系统事件的综合分析报告
https://www.antiy.cn/research/notice&report/research_report/20100927.html
[4]CVE-2020-0601: the ChainOfFools/CurveBall attack explained with PoC
https://research.kudelskisecurity.com/2020/01/15/cve-2020-0601-the-chainoffools-attack-explained-with-poc/
[5] National Security Agency | Cybersecurity Advisory
https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF
漏洞背景
漏洞描述
漏洞原理分析
受影响范围
漏洞影响Windows 10、Windows Server 2016、Windows Server 2019等多个版本:
Windows 10 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1709 for 32-bit Systems
Windows 10 Version 1709 for ARM64-based Systems
Windows 10 Version 1709 for x64-based Systems
Windows 10 Version 1803 for 32-bit Systems
Windows 10 Version 1803 for ARM64-based Systems
Windows 10 Version 1803 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows Server 2016
Windows Server 2016 (Server Core installation)
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server, version 1803 (Server Core Installation)
Windows Server, version 1903 (Server Core installation)
Windows Server, version 1909 (Server Core installation)
修复及缓解建议
1、用户可以自动更新后手动安装微软关于此漏洞的补丁程序[1],受影响的操作系统版本对应的补丁链接见附录三。
2、用户可使用安天智甲终端防御系统[2](以下简称“智甲”)进行漏洞修复,智甲最新版本支持对该漏洞进行检测、修复和一键加固。通过安天引擎,可对该漏洞生成的带有数字签名的恶意程序有效防护查杀,包括在无法打本补丁的系统中,对攻击程序进行主防拦截。安天智甲终端防御系统与安天资产安全运维系统组合使用,可充分减少暴露面,形成威胁防御响应的基础能力。
受影响的操作系统版本 | 补丁链接 |
Windows 10 for 32-bit Systems | https://www.catalog.update.microsoft.com/Search.aspx?q=KB4534306 |
Windows 10 for x64-based Systems | https://www.catalog.update.microsoft.com/Search.aspx?q=KB4528760 |
Windows 10 Version 1607 for 32-bit Systems | https://www.catalog.update.microsoft.com/Search.aspx?q=KB4534271 |
Windows 10 Version 1607 for x64-based Systems | https://www.catalog.update.microsoft.com/Search.aspx?q=KB4534271 |
Windows 10 Version 1709 for 32-bit Systems | https://www.catalog.update.microsoft.com/Search.aspx?q=KB4534276 |
Windows 10 Version 1709 for ARM64-based Systems | https://www.catalog.update.microsoft.com/Search.aspx?q=KB4534276 |
Windows 10 Version 1709 for x64-based Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534276 |
Windows 10 Version 1803 for 32-bit Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534293 |
Windows 10 Version 1803 for ARM64-based Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534293 |
Windows 10 Version 1803 for x64-based Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534293 |
Windows 10 Version 1809 for 32-bit Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534273 |
Windows 10 Version 1809 for ARM64-based Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534273 |
Windows 10 Version 1809 for x64-based Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534273 |
Windows 10 Version 1903 for 32-bit Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4528760 |
Windows 10 Version 1903 for ARM64-based Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4528760 |
Windows 10 Version 1903 for x64-based Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4528760 |
Windows 10 Version 1909 for 32-bit Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4528760 |
Windows 10 Version 1909 for ARM64-based Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4528760 |
Windows 10 Version 1909 for x64-based Systems | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4528760 |
Windows Server 2016 | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534271 |
Windows Server 2016 (Server Core installation) | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534271 |
Windows Server 2019 | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534273 |
Windows Server 2019 (Server Core installation) | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534273 |
Windows Server, version 1803 (Server Core Installation) | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4534293 |
Windows Server, version 1903 (Server Core installation) | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4528760 |
Windows Server, version 1909 (Server Core installation) | https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4528760 |
往期推荐