{"id":20462,"date":"2021-06-25T18:43:27","date_gmt":"2021-06-25T16:43:27","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=20462"},"modified":"2021-06-25T18:43:27","modified_gmt":"2021-06-25T16:43:27","slug":"nice-microsoft-signierte-network-filtertreiber-der-als-rootkit-aus-china-fungiert","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2021\/06\/25\/nice-microsoft-signierte-network-filtertreiber-der-als-rootkit-aus-china-fungiert\/","title":{"rendered":"Nice: Microsoft signierte signed network filter driver acting as a rootkit from China"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" width=\"200\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/2021\/06\/25\/nice-microsoft-signierte-network-filtertreiber-der-als-rootkit-aus-china-fungiert\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Security researchers have come across a Microsoft digitally signed WFP Application Layer Enforcement Callout Driver, which turned out to be a network filter rootkit. The driver automatically established connections to an IP address used by a server in China. Here is some information about this strange case.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg04.met.vgwort.de\/na\/336a8a1703ac4fda99584c360fa306b8\" width=\"1\" height=\"1\">I became aware of the case via the following <a href=\"https:\/\/twitter.com\/GossiTheDog\/status\/1405805536403243009\" target=\"_blank\" rel=\"noopener\">tweet<\/a> from Kevin Beaumont, which is documented at GData in <a href=\"https:\/\/www.gdatasoftware.com\/blog\/microsoft-signed-a-malicious-netfilter-rootkit\" target=\"_blank\" rel=\"noopener\">this blog post<\/a>.<\/p>\n<p><a href=\"https:\/\/twitter.com\/GossiTheDog\/status\/1405805536403243009\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"Network-Filter-Rootkit\" alt=\"Network-Filter-Rootkit\" src=\"https:\/\/i.imgur.com\/A7Yg6OW.png\"><\/a><\/p>\n<p>Looking at the details from Virustotal, it is a network filter that carries a valid signature and has been signed by Microsoft, but is a rootkit, which phones to China. <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"Rootkit-Signatur\" alt=\"Rootkit-Signatur\" src=\"https:\/\/i.imgur.com\/vwsjtNg.png\" width=\"495\" height=\"658\"><\/p>\n<p>On Twitter, Beaumont posted more details about the driver. But the more interesting thing is the <a href=\"https:\/\/www.gdatasoftware.com\/blog\/microsoft-signed-a-malicious-netfilter-rootkit\" target=\"_blank\" rel=\"noopener\">GData blog post here<\/a>. In mid-June 2021, the GDATA alert system struck, informing their analysis of a possible false positive. Discovered was a driver that was signed by Microsoft. Since Windows Vista, any code that runs in kernel mode must be tested and signed before public release to ensure the stability of the operating system. Drivers without a Microsoft certificate cannot be installed by default.<\/p>\n<h2>It was not a false positive alarm<\/h2>\n<p>In this case, the detection of the digitally signed driver as malware was a positive hit. The signed driver was dropped by a dropper under the following path.<\/p>\n<p>%APPDATA%\\netfilter.sys<\/p>\n<p>Then another file:<\/p>\n<p>%TEMP%\\c.xalm<\/p>\n<p>which then executed a command to enter and register the driver in the registry. GData then describes that the Netfilter driver accesses the rookit's server to retrieve updated binaries as well as configuration information. According to WHOIS, it belongs to Ningbo Zhuo Zhi Innovation Network Technology Co, Ltd, a company listed by the US Department of Defense as a communist Chinese military company. <\/p>\n<p>The details can be found in the GDATA blog post. Anyway, the Chinese managed to get Microsoft to sign the driver. After GData forwarded these findings to Microsoft, Redmond immediately added malware signatures to Windows Defender. At the same time, an internal investigation was started to clarify how this digital signing could happen. So far, however, no result is known.&nbsp; <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Security researchers have come across a Microsoft digitally signed WFP Application Layer Enforcement Callout Driver, which turned out to be a network filter rootkit. The driver automatically established connections to an IP address used by a server in China. Here &hellip; <a href=\"https:\/\/borncity.com\/win\/2021\/06\/25\/nice-microsoft-signierte-network-filtertreiber-der-als-rootkit-aus-china-fungiert\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69,194],"class_list":["post-20462","post","type-post","status-publish","format-standard","hentry","category-security","tag-security","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/20462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=20462"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/20462\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=20462"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=20462"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=20462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}