¶«Éƽ̨ADLab£ºMSCÎļþµÄÔÚÒ°ÀûÓÃÇé¿öÓëºÚ¿Í¹¥»÷»î¶¯·ÖÎö
Ðû²¼Ê±¼ä 2024-09-14Ò»¡¢±³ ¾°
2024Äê6ÔÂ22ÈÕ£¬Ò»¸öÀûÓÃMSC¸ñʽµÄÐÂÐ͹¥»÷¼¼ÊõµÄ¶ñÒâÑù±¾·ºÆðÔÚVTƽ̨ÉÏ£¬´ËʱÀûÓÃÕâÖÖ¼¼ÊõµÄ¶ñÒâÑù±¾ÔÚVTÉϾùÏÔʾΪÁã¼ì²âÂÊ¡£ÕâÖÖ¼¼Êõ±»ElasticÑо¿ÍŶÓÃüÃûΪ¡°GrimResource¡±£¬Æäͨ¹ý¶ñÒâ¹¹½¨µÄMSCÎļþÔÚMicrosoft¹ÜÀí¿ØÖÆ̨ÖÐÖ´ÐÐÈÎÒâ´úÂë¡£¶«Éƽ̨ADLabÔÚ½ñºóµÄÁ½¸öÔÂʱ¼äÖУ¬Á¬Ðø¹ØעʹÓÃÕâÖÖÀûÓÃÊÖ·¨µÄ¹¥»÷£¬Í¨¹ý¼à²âµÄ½á¹û·ÖÎö·¢ÏÖ£º×Ըü¼Êõ¹ûÈ»ºó£¬Í¬À๥»÷ѸËÙÔö¼Ó£¬µ½Ä¿Ç°ÎªÖ¹Äܹ»¼à²âµ½µÄÓÐЧ¹¥»÷¼°Æä¹¥»÷Ñù±¾ÓÐ100¶àÆ𡣶øÇÒÓÐÔ½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓÀûÓøü¼ÊõÔÚÈ«Çò·¶Î§ÄÚ½øÐÐÍøÂç¹¥»÷£¬°üÂÞKimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£Ä¿Ç°ÒÑ·¢ÏÖµÄÄ¿±êÓÐÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¼ÒµÄÕþ¸®»ú¹¹ºÍÆóÒµ£¬Éæ¼°Õþ¸®¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£
ÕâЩ¹¥»÷ÆÕ±éͨ¹ýMSCÎļþ×÷Ϊ¶ñÒâpayload£¬Í¨¹ýÖÖÖÖ·½Ê½·¢Ë͸øÄ¿±ê²¢ÓÕʹĿ±ê´ò¿ª¸ÃÎļþ¡£ÓÉÓÚMSC¸ñʽµÄ¹¥»÷ÎļþÊÇÒ»ÖÖÏà¶Ôº±¼ûµÄÎļþÀàÐÍ£¨¶àÊý±»¹¥»÷Õß¿ÉÄÜÊìϤ.exe¡¢.docµÈ³£¼ûµÄ¿ÉÖ´ÐÐÎļþÀ©Õ¹Ãû£¬µ«²¢²»Á˽â.mscÎļþ£¬Òò´Ë¿ÉÄÜÔÚʵ¼Ê¹¥»÷Öз¢ÉúÆæЧ£©£¬¶øÇÒÄ¿Ç°·À»¤ÏµÍ³Ò²ÏÊÓжԴËÀàÎļþµÄÕë¶ÔÐÔ¼ì²â£¬ËùÒÔºÚ¿ÍÀûÓøü¼ÊõʵÏÖ¹¥»÷µÄÀÖ³ÉÂʸߣ¬±»¼ì²âºÍ·¢Ïֵļ¸Âʵͣ¬¾ÍÄ¿Ç°ÎÒÃÇÊӲ쵽¹¥»÷ÓÕ¶ü£¬ÓаüÂÞÈ磺¡°¡¶**ÂÛ̳¡·ÍâÉóר¼ÒÑûÇ뺯ÓëÎÄÕÂÆÀÉ󵥡±¡¢£º¡°ÄäÃûÉó¸åר¼Ò»ØÖ´ (УÍâ) ¡±¡¢¡°ÊÊÓÃÓÚÄϺ£µÄÁ½ÖÖÖ´·¨ÖƶÈÑо¿ (¸å¼þ)¡±¡¢¡°ÃÀ¹úÕ½ÂÔÊÕËõ¶ÔÖж«µØÔµÕþÖεÄÓ°Ï족¡¢¡°****ÍøÂç´ó»á¡±µÈ¼«¾ßÒýÓÕÐԵĹ¥»÷£¬Ò»µ©µã»÷ÆäÖеÄMSCÎļþ£¬Æäϵͳ±ã»á±»Ö²ÈëÇÔÃÜľÂí£¬µ¼ÖÂÖØÒªÃô¸ÐÊý¾Ý±»ÇÔÈ¡¡£
ͨ¹ýÎÒÃǶԹ¥»÷µÄ×·ËÝ·¢ÏÖÔçÔÚ2024Äê4Ô£¬Kimusuky APT×éÖ¯¾Í¿ªÊ¼ÀûÓÃMSCÎļþÀ´¶ÔÆäÄ¿±êʵʩÁË´óÁ¿µÄ¹¥»÷£¬µ«ÆäÀûÓÃÊÖ·¨ÓëGrimResource¼¼ÊõÓÐËù²îÒì¡£ÓÉÓÚMSCÑù±¾µÄ¹ûÈ»ÀûÓúͼ¼ÊõÑݱäÉд¦ÓÚÉú³¤³õÆÚ£¬Òò´ËÓйع¥»÷Ñù±¾ºÍÊÖ·¨µÄ±ä»¯ÖµµÃÒýÆðÁ¬Ðø¹Ø×¢¡£´ËÍ⣬OutflankÓÚ8ÔÂ13ÈÕ·¢ÎijÆGrimResource¼¼ÊõÔ´ÓÚÆäÎäÆ÷¿â£¬ÆäÔÚ¹¥·ÀÑÝÁ·Öб»·ÀÊØ·½ÉÏ´«µ½¹«¹²É³Ïä¡£
¶þ¡¢½üÆÚÔÚÒ°¹¥»÷»î¶¯·ÖÎö
ͨ¹ý¶ÔÄ¿Ç°ÊÕ¼¯µ½µÄ100Óà¸öMSCÑù±¾µÄ·ÖÎö£¬ÎÒÃÇ·¢ÏÖ×îÔçµÄÀûÓÃÑù±¾·ºÆðÔÚ2024Äê4ÔÂ5ÈÕ£¬ËùÓÐÑù±¾ÖУ¬·ºÆðÔÚ4-5ÔµĹ¥»÷Ñù±¾Ö÷ÒªÊôÓÚKimusuky×éÖ¯¡£6Ôºó£¬Ëæ×ÅGrimResource¼¼ÊõµÄ¹ûÈ»£¬MSC¸ñʽµÄÑù±¾ÊýÁ¿ÒÔÔÂΪµ¥Ôª³ÊÃ÷ÏԵĵÝÔö¹Øϵ£¬±íÃ÷ºÚ¿ÍÃÇÕý»ý¼«ÀûÓúͲâÊÔÏà¹Ø¹¥»÷¼¼Êõ²¢×ª»¯ÎªÊµ¼Ê¹¥»÷¡£ÒÔÏÂÊǽü¼¸¸öÔ²¶×½µ½µÄMSC¸ñʽµÄ¹¥»÷Ñù±¾ÊýÁ¿Í¼¡£

ͼ1 MSC¹¥»÷Ñù±¾ÊýÁ¿Í³¼Æͼ£¨µ¥Ôª:Ô£©
ÔÚÕâÅú¹¥»÷Ñù±¾ÖУ¬ÆäÖÐһЩÊÇ»ùÓÚ¿ªÔ´ÏîÄ¿±àÒëµÄÑù±¾£¨ÈçÏÂͼÖÐͼ±êΪ¡°ÑÛ¾¦¡±µÄÑù±¾¼´Îª¿ªÔ´ÏîÄ¿MSC_DropperÉú³É£©£¬ÕâÀàÑù±¾¿ÉÄÜÊDz¿ÃŹ¥»÷ÕßÕýÔÚ»ý¼«µØ½øÐм¼Êõ×¼±¸ºÍÃâɱ²âÊÔ¡£Í¬Ê±£¬Ò»Ð©ÕæʵµÄ¹¥»÷»î¶¯Ò²Ô½À´Ô½Æµ·±µØ·ºÆð£¬ÔÚʵ¼Ê¹¥»÷ÖÐÑù±¾Í¨³£»á°Ñͼ±êαװ³ÉWORD¡¢PDF¡¢MP4µÈÖÖÖÖ³£¼ûµÄÎļþ¸ñʽÓÃÒÔÃÔ»óÊܺ¦Ä¿±ê£¬ÏÂͼÊDz¿ÃÅÑù±¾¼°Í¼±êʾÀý¡£

ͼ2 ²¶×½MSCÑù±¾Ê¾Àý
´ÓÖÐÎÒÃÇ·¢ÏÖÁËÊýÆðÕë¶ÔÈ«Çò¶à¸ö¹ú¼ÒºÍµØÓòµÄ¹¥»÷»î¶¯£¬Ä¿±êÖ÷Òª°üÂÞÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȣ¬¹¥»÷µÄÄ¿±êÐÐÒµÔòÉæ¼°Õþ¸®¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£ÆäÖУ¬Õë¶ÔÖйúµÄAPT¹¥»÷»î¶¯ÔÚ½üÆÚ¿ªÊ¼Ã÷ÏÔÔö¶à¡£ÔÚ7Ô³õÆÚ£¬Óйع¥»÷Ö÷ÒªÒÔ¡°Ò×·ÒëÖúÊÖ¡±¡¢¡±¶¶Òôǧ·ÛÆóÒµºÅ¡±¡¢¡°½ÌÓýÐÐÒµÊý¾Ý¡±µÈΪÓÕ¶üµÄºÚ²ú×éÖ¯¹¥»÷ΪÖ÷¡£¶øÔÚ8ÔÂÖ®ºó£¬¿ªÊ¼Â½Ðø·ºÆðÁ˶àÆðÒÔÕþÖÎÒéÌ⡢ר¼ÒÑûÇë¡¢»áÒéÈճ̡¢Í¶Ëß½¨Òé¡¢¾Ù±¨ÖÊÁϵÈÕë¶ÔÕþ¸®×éÖ¯»ò¿ÆÑв¿ÃŵÄÕë¶ÔÐÔ¹¥»÷£¬ÐèÒªÒýÆð¸ß¶È¾¯Ì裬²¿ÃÅÓÕ¶üÎĵµÈçÏÂËùʾ¡£

ͼ3 Ö÷ÌâΪ¡°×¨¼ÒÑûÇ뺯¡±ÀàµÄÓÕ¶üÎĵµ

ͼ4 Ö÷ÌâΪ¡°Õþ²ßÖƶÈÑо¿¡±ÀàµÄÓÕ¶üÎĵµ
ͼ5 Ö÷ÌâΪ¡°****ÍøÂç´ó»á¡±µÄÓÕ¶üÎĵµ
ͼ6 Õë¶ÔË®ÀûÊðµÄÓÕ¶üÎĵµ
³ýÁËÕë¶ÔÖйúÒÔÍ⣬º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȶà¹úÒ²½ÓÁ¬ÔâÓöµ½ÀûÓÃMSCÎļþµÄ¹¥»÷»î¶¯£¬ÆäÖÐÓÈÒÔº«¹úÔâÊܵĹ¥»÷×î¶à£¬Õâ¿ÉÄÜÓëkimsuky×éÖ¯µÄ¹¥»÷Ä¿±êÇãÏòÓйأ¬²¿ÃŹ¥»÷»î¶¯ÓÕ¶üÈçÏÂËùʾ¡£

ͼ7 Õë¶Ôº«¹úµÄÓÕ¶üÎĵµ

ͼ8 Õë¶ÔÔ½ÄÏʯÓ͹«Ë¾µÄÓÕ¶üÎĵµ
ÔÚÕë¶ÔÕâÅúÑù±¾½øÐÐÉîÈë·ÖÎöºó£¬ÎÒÃÇ·¢ÏÖÁ˹¥»÷ÕßʹÓõĶà¸ö»ù´¡ÉèÊ©£¬°üÂÞ¶à½×¶ÎÏÂÔØ·þÎñÆ÷ºÍC2·þÎñÆ÷µÈ£¬ÆäÖдó²¿ÃŶ¼½ÓÄÉÁËÔÆ·þÎñÀ´×ÌÈÅËÝÔ´×·×Ù£¬ÆäÖÐһЩ·þÎñÆ÷¹éÊôÓÚÃÀ¹ú¡¢ÈÕ±¾¡¢Èðµä¡¢·¨¹ú¡¢Ð¼ÓƵȹú¼Ò¡£²¿ÃÅÑù±¾¼°C2·þÎñÆ÷ÈçÏÂËùʾ¡£
±í1 ¶ñÒâ·þÎñÆ÷µØÖ·
ͬʱ£¬ÎÒÃÇÒ²²¶×½µ½Á˲¿ÃÅÑù±¾µÄͶµÝURLµØÖ·ÈçϱíËùʾ¡£
Èý¡¢MSCÎļþÀûÓü¼ÊõÔÀí·ÖÎö
MSC(Microsoft Snap-In Control)Îļþ£¬ÊÇ΢Èí¹ÜÀí¿ØÖÆ̨(MMC)ÓÃÀ´Ìí¼Ó/ɾ³ýµÄǶÈëʽ¹ÜÀíµ¥ÔªÎļþ, ¹ÜÀíԱͨ¹ý´´½¨¿ØÖÆ̨¿ÉÒÔ¹ÜÀí¼ÆËã»úµÄÖÖÖÖÉèÖã¬Ìí¼ÓÖÖÖÖ¹¦Ð§ÈçÓû§ÕË»§¹ÜÀí¡¢ÏµÍ³·þÎñ¡¢É豸Çý¶¯·¨Ê½µÈ£¬È»ºó¿ÉÒÔ½«ÕâЩ¹ÜÀíµ¥ÔªµÄ×Ô½ç˵ÅäÖÃÒÔXMLµÄÐÎʽÉú´æµ½´ÅÅÌÉÏ£¬¼´MSC¸ñʽ¡£WindowsÖг£¼ûµÄÉ豸¹ÜÀíÆ÷¡¢´ÅÅ̹ÜÀíÆ÷¡¢×é¼Æı¹ÜÀíÆ÷µÈ¶¼ÊÇMSC¸ñʽÎļþ¡£ÈçÏÂͼÊÇ×Ô½ç˵MSCÎļþµÄ¹ÜÀíµ¥ÔªÈÎÎñ°å½çÃ棬¹¥»÷Õß¿ÉÒÔͨ¹ý±à³ÌµÄ·½Ê½ÓëMMC½øÐн»»¥£¬´Ó¶ø½á¹¹×Ô½ç˵µÄ½çÃæºÍÄÚÈÝ¡£
ͼ9 MSCÎļþ¹ÜÀíµ¥ÔªÈÎÎñ°å
ͼ10 MSCÎļþ¼¼ÊõÀûÓÃÁ÷³Ìͼ
ͼ11 ÀûÓ÷½Ê½Ò»
ͼ12 ¿ØÖÆ̨ÈÎÎñ°åÖ´ÐÐÈÎÒâÃüÁîʾÀý

ͼ13 ÈÎÎñ°åÖ´ÐÐÈÎÒâÃüÁîXML
½«ActiveX¹¤¾ß¼ÓÔص½¡°ActiveX¿Ø¼þ¡±¹ÜÀíµ¥ÔªÖС£
½«HTMLÎļþ¼ÓÔص½¡°Á´½Óµ½WebµØÖ·¡±¹ÜÀíµ¥ÔªÖС£
ÔÚHTMLÎļþÖУ¬Ê¹ÓÃJavaScriptÓë¼ÓÔصÄActiveX¹¤¾ß½øÐн»»¥¡£²¢Í¨¹ý MSXMLÒªÁ죬´¥·¢XSLת»»À´Ö´ÐÐJScript´úÂë¡£
×îºó´ÓJScript´úÂëÖе÷ÓÃϵͳº¯Êý£¬»òÕßͨ¹ý DotNetToJScript Ö´ÐÐ.NET´úÂë¡£
Ê×ÏÈ£¬ÔÚMMC·¨Ê½ÖУ¬¹¥»÷Õß¿ÉÒÔ×Ô½ç˵²åÈëActiveX¿Ø¼þ¡£Í¨¹ýÎļþ±à¼Æ÷´ò¿ª´´½¨µÄMSCÎļþʱ£¬¿ÉÒÔ¿´µ½´´½¨µÄActiveX¿Ø¼þ´æ´¢ÔÚXMLµÄStringTableÖС£
ͼ14 ²åÈëActiveX¿Ø¼þ¹¤¾ß
µ«Èç¹ûÏëÀֳɼÓÔع¤¾ß£¬¾ÍÒªÈƹýActiveX ¿Ø¼þµÄÄþ¾²¾¯¸æ¡£¹¥»÷Õß½ÓÄÉÁËÒ»ÖÖÇÉÃîµÄÒªÁ죬ͨ¹ýMicrosoft Internet Explorerä¯ÀÀÆ÷×é¼þ·ÃÎÊexternal ¹¤¾ß£¬´Ó¶øÓëMMC¿ØÖÆ̨µÄÆäËûÔªËؽøÐн»»¥£¬ÕâÊÇ΢Èí¹Ù·½Ö§³ÖµÄÒ»ÖÖ·½Ê½¡£ÈçÏÂͼÖУ¬scopeNamespaceºÍdocObject¼´ÊÇͨ¹ýexternal.Document»ñÈ¡ÏÖÓй¤¾ß£¬¶ø·Ç´´½¨ÐµÄActiveX¹¤¾ß£¬½ø¶øÈƹýÁËÖ±½Ó´´½¨ActiveX¿Ø¼þʱµÄÄþ¾²ÏÞÖÆ¡£
ͼ15 GrimResource¼¼ÊõÀûÓôúÂë
XSLTÊÇÒ»ÖÖÓÃÓÚ½«XMLÎĵµ×ª»»ÎªÆäËûÎĵµ¸ñʽµÄÓïÑÔ£¬XSLTÑùʽ±í£¨XSL£©Ôò½ç˵ÁËÈçºÎ½«Ò»¸öXMLÎĵµ×ª»»ÎªÆäËûÐÎʽ¡£Î¢ÈíÖ§³ÖMSXML XSLTʹÓÃ
ͼ16 ½Å±¾ÖеÄ
ËÄ¡¢°¸Àý·ÖÎö
¶«Éƽ̨ADLab½ÓÁ¬²¶×½µ½Á˶àÆðÀûÓÃMSCÎļþÕë¶ÔÈ«ÇòÄ¿±êµÄ¹¥»÷»î¶¯¡£ÆäÖÐÒÑ·¢ÏÖÕë¶ÔÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¼ÒµÄÕþ¸®»ú¹¹ºÍÆóÒµµÄ¹¥»÷£¬Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓÕýÔÚÀûÓÃÏà¹Ø¼¼ÊõÔÚÈ«Çò·¶Î§ÄÚ½øÐÐÍøÂç¹¥»÷£¬°üÂÞKimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£ÔÚÖî¶àµÄ¹¥»÷°¸ÀýÖУ¬ÎÒÃÇÑ¡È¡ÁËÔÚ¼¼Êõ²ãÃæ½ÏÓдú±íÐÔÇÒÏà¶ÔÃô¸ÐµÄÁ½À๥»÷Ñù±¾×÷Ϊ´Ë´ÎµÄ·ÖÎö°¸Àý£¬ÀûÓÃGrimResource¼¼ÊõÕë¶ÔÖйúµÄ¹¥»÷»î¶¯£¬ÒÔ¼°Kimsuky×éÖ¯ÀûÓÃMMC¿ØÖÆ̨ÈÎÎñ°åÕë¶Ôº«¹úµÄ×îй¥»÷»î¶¯¡£ÏÂÃæÎÒÃǽ«¶ÔÑ¡È¡µÄÁ½¸ö°¸Àý½øÐÐÉîÈëµÄ·ÖÎö¡£
4.1 ÒÔÕþÖλ°ÌâΪÓÕ¶üÕë¶ÔÖйúµÄ¹¥»÷»î¶¯
´Ë°¸ÀýÀûÓõÄÊÇGrimResource¼¼Êõ£¬µ±Êܺ¦Õßµã»÷ÔËÐÐmscÎļþʱ£¬mmc.exe»áÖ´ÐÐÑù±¾ÖеÄjs´úÂ룬¼Ì¶øÖ´ÐÐǶÈëÔÚxmlÖеÄVBScript´úÂë¡£ÆäÖУ¬ÒýÖÂVBA´úÂëµÄÖ´ÐеÄÒªº¦µãÊÇtransforNode(xsl)ÒªÁìµÄµ÷Óá£
ͼ17 ÒýÖÂVBA´úÂëÖ´ÐеÄÒªº¦µã
transforNodeÒªÁì³£ÓÃÓÚ½«Ò»¸öXMLÎĵµÍ¨¹ýXSLTÑùʽ±í£¨×÷Ϊ²ÎÊý£©×ª»»ÎªÆäËûÎĵµ¸ñʽ¡£Èç¹ûXSLTÑùʽ±íÖк¬ÓÐ
ͼ18 XSLTÑùʽ±íÄÚÈÝ
±»Ö´ÐеÄVBScript´úÂëͨ¹ý×Ô½ç˵±àÂëºÍ½âÂë¡¢×Ö·û´®Æ´½Ó¡¢ÌØÊâ×Ö·û»ìºÏ±àÂëµÈ»ìÏý¼¼Êõ£¬Äܹ»ÓÐЧµØÒþ²ØÆäÕæʵÂß¼ºÍ¶ñÒâÐÐΪ£¬Í¬Ê±Ôö¼ÓÁË·ÖÎöÈËÔ±½øÐÐÄæÏò·ÖÎöµÄʱ¼ä³É±¾¡£ÏÂͼչʾÁËÔÚÊ״νâÂëÖ®ºóµÄ²¿ÃÅ´úÂë¿é£¬Äܹ»¿´µ½´úÂëÖÐÒÀÈ»´æÔÚ×ÅÆäËû»ìÏý¡£

ͼ19 »ìÏýµÄVBScript´úÂë
ÎÒÃǼÌÐø¶Ô´úÂë½øÐÐÈ¥»ìÏýÒÔ¼°º¯ÊýÖØÃüÃû´¦Öú󣬿ÉÒÔ¿´µ½½Å±¾ÏÈÊÇÉèÖÃÎļþ·¾¶ºÍĿ¼½á¹¹£¬ÔÙ´ÓXML½á¹¹ÖÐÌáÈ¡Êý¾Ý½øÐÐbase64½âÂë²¢Éú´æΪָ¶¨Îļþ£¨ÓÕ¶üÎĵµ£©£¬×îºó´ò¿ª¸ÃÎļþ¡£
ͼ20 ÊÍ·ÅÓÕ¶üÎĵµ
ÔÚ±¾°¸ÀýÖУ¬ÓÃÓÚÃÔ»óÊܺ¦ÕßµÄÊÇÈý¸öαװ³ÉWordµÄÓÕ¶üMSCÎļþ£¬¾ßÌåÄÚÈÝÈçÏÂͼËùʾ¡£
ͼ21 ÓÕ¶üÎĵµÊ¾ÀýÒ»
ͼ22 ÓÕ¶üÎĵµÊ¾Àý¶þ

ͼ23 ÓÕ¶üÎĵµÊ¾ÀýÈý
½Ó×ÅÌáÈ¡ºÍ½âÂëÆäËûbase64Êý¾Ý£¬ÔÙ½«½âÂëºóµÄÊý¾ÝÉú´æΪ×îÖÕµÄWarp.exeºÍ7z.dll¿ÉÖ´ÐÐÎļþ¡£Ëæºó½«¡° t 8.8.8.8¡±×÷Ϊ²ÎÊý£¨×Ô¶¯¼ÓÔØͬĿ¼Ï¡°7z.dll¡±µÄËùÐèÌõ¼þ£©Æô¶¯Warp.exe·¨Ê½¡£
ͼ24 Éú³É²¢Ö´ÐÐwarp.exe·¨Ê½
¾¼ì²ì£¬¡°Warp.exe¡±¾ßÓÐ ¡°Lenovo (Beijing) Co., Ltd.¡±µÄºÏ·¨Êý×ÖÇ©Ãû£¬ÆäÔÎļþÃûΪ¡°7zwrap.exe¡±¡£¾ßÌåÐÅÏ¢ÈçÏÂͼËùʾ¡£
ͼ25 ¡°Warp.exe¡±ÏêϸÐÅÏ¢
µ±¶ñÒâ¡°7z.dll¡±Îļþ±»¡°Wrap.exe¡±ÀֳɼÓÔغó£¬Æä»áÔÚÄÚ´æÖжÔÖ¸¶¨Êý¾Ý½øÐнâÃÜ¡£¾ÄÚ´æÌØÕ÷ɨÃèºó£¬Åж¨×îÖÕ±»¼ÓÔØÖ´ÐеÄÊÇCobaltStrike£¬ÎÒÃÇÌáÈ¡³öµÄCSÅäÖÃÐÅÏ¢ÈçÏÂͼËùʾ¡£
4.2 ÒÔѧÊõÑݽ²ÎªÓÕ¶üÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯
¸Ã°¸ÀýÊÇKimsuky APTºÚ¿Í×éÖ¯ÔÚ½ñÄêËùÒýÈëµÄÒ»ÖÖÐµĹ¥»÷¼Æı£¬¹¥»÷Õßͨ¹ýXMLµÄÉèÖÃÊôÐÔ½«MSC¶ñÒâÎļþµÄͼ±êÉèÖÃΪWordͼ±ê£¬½èÒÔαװ³ÉWORDÎĵµÀ´ÃÔ»óÊܺ¦Õß¡£
ͼ27 αװµÄWordͼ±ê
µ±Êܺ¦Õßµã»÷MSCÎļþʱ£¬Óû§ÕË»§¿ØÖÆ£¨UAC£©»áµ¯³öÇëÇóȨÏÞÑ¡Ôñ£¬Èç¹ûÑ¡[ÊÇ]£¬Ôò»áͨ¹ýÖ´ÐÐmscÁ¬½Ó·¨Ê½mmc.exe£¬Õ¹Ê¾¹¥»÷Õ߶¨ÖƵÄÃûΪ¡°?????.docx¡±µÄMicrosoft¹ÜÀí¿ØÖÆ̨½çÃæ¡£¾ßÌåÈçÏÂͼËùʾ¡£
ͼ28 ¡°?????.docx¡±µÄMicrosoft¹ÜÀí¿ØÖÆ̨½çÃæ
±í3 ÌØÊâ·ûºÅÄÚÈݽâÎö
ͼ29 º¬ÓÐÌØÊâ·ûºÅµÄcmd²ÎÊýÃüÁîÐÐÄÚÈÝ
ͨ¹ý¸Ã·ûºÅËù¶ÔÓ¦µÄ½âÎö½øÐÐÌæ»»ºó£¬µÃµ½ÁËÈçÏÂͼËùʾµÄÅú´¦ÖÃÃüÁî¡£¸Ã´®Åú´¦ÖÃÃüÁîÔòÊÇÖ´ÐÐMSCºóµÄ¹ÜÀí¿ØÖÆ̨¸ùÈÎÎñ´°¿ÚµÄÃüÁîÐвÎÊý¡£¸Ã¶ÎÃüÁîµÄÖ÷Òª¹¦Ð§ÊÇ´ÓÖ¸¶¨URLÏÂÔØÃûΪ¡°Grieco Kavanagh Passive Supporters.docx¡±µÄÓÃÓÚαװµÄÓÕ¶üÎĵµ£¬ÒÔ¼°ºóÐø½×¶ÎµÄ¡°pest.exe¡±ºÍ¡°pest.exe.manifest¡±Îļþ¡£³ý´ËÖ®Í⣬Æ仹»á´´½¨Ò»¸öÃûΪ¡°TemporaryClearStatesesf¡±µÄ¼Æ»®ÈÎÎñ£¬Ã¿58·ÖÖÓÖ´ÐÐÒ»´Î¡°%appdata%\pest.exe¡±Îļþ¡£ÄÚÈÝÈçÏÂͼËùʾ¡£
ͼ30 cmd²ÎÊýÃüÁîÐÐÄÚÈÝ
¼ì²ì¡°pest.exe¡±·¨Ê½ÏêϸÐÅÏ¢£¬·¢Ïָ÷¨Ê½µÄÊý×ÖÇ©ÃûÃû³ÆΪ¡°Adersoft¡±£¬ÔʼÎļþÃûΪ¡°launcher.exe¡±¡£¸Ã·¨Ê½ÎªVBSEdit£¨ÓÉAdersoft¹«Ë¾³öÆ·µÄÒ»¿îСÇɶøÇ¿º·µÄVBScript±à¼¹¤¾ß£©½Å±¾Æô¶¯Æ÷¡£
ͼ31 ¡°pest.exe¡±·¨Ê½ÏêϸÐÅÏ¢
ͼ32 ¡°pest.exe¡±·¨Ê½Ö´Ðб¨´í
¡°pest.exe.manifest¡±ÎļþÄÚÈÝÊÇXML¸ñʽ£¬¶ñÒâ´úÂë°üÂÞÔÚ¡°¡±±êÇ©Ö®¼ä¡£¸ÃÎļþµÄÖ÷Òª¹¦Ð§ÊÇÓÉÒ»¶Î¾base64±àÂëµÄVBScript´úÂëÀ´ÊµÏÖ¡£²¿ÃÅ´úÂëÈçÏÂͼËùʾ¡£
ͼ33 base64±àÂëµÄVBScript´úÂë
ͼ34 batÎļþ²Ù×÷´úÂë
Èç¹û¡°sim.sid¡±Îļþ²»´æÔÚ£¬ÔòÏòÖ¸¶¨µÄGoogle driveÁ´½Ó·¢ËÍHTTPÇëÇ󣬲¢»ñÈ¡ÏìÓ¦ÄÚÈÝ¡£
ͼ35 ÏòGoogle drive¹²ÏíÁ´½Ó·¢ËÍÇëÇó
ÀֳɻñÈ¡ºó£¬´Ó½ÓÊÕµ½µÄÄÚÈÝÖÐÌáÈ¡base64±àÂëµÄÊý¾Ý£¨ÔÚ"pprbstart--"ºÍ"--pprbend"±êÇ©Ö®¼ä£©£¬×îºóÌæ»»ÌØÊâ×Ö·û²¢½«½âÂëºóµÄÊý¾ÝдÈëÖÁ¡±%appdata%\Microsoft\sif.bat"¡£
ͼ36 ½âÎöÏìÓ¦ÄÚÈÝ
Îå¡¢×Ü ½á
±¾ÎÄÕë¶ÔÎÒÃǽüÆÚ²¶×½µ½µÄһϵÁлùÓÚÐÂÐÍMSCÎļþµÄ¹¥»÷»î¶¯½øÐÐÁË·ÖÎö£¬Öصã½éÉÜÁËÄ¿Ç°MSCÎļþÔÚҰʹÓõÄÁ½ÖÖÀûÓü¼ÊõÔÀí£¬Åû¶½üÆÚÀûÓÃMSCÎļþµÄ¶àÆðÃô¸Ð¹¥»÷»î¶¯£¬²¢Õë¶ÔÆäÖеÄÁ½¸ö°¸Àý½øÐÐÁËÉîÈë·ÖÎö¡£´Ó½ü¼¸¸öÔÂMSCÎļþÏà¹Ø¹¥»÷µÄ»îÔ¾Ç÷ÊÆÀ´¿´£¬¹¥»÷»î¶¯Éæ¼°µ½Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²ú×éÖ¯ÒÔ¼°ºì¶ÓµÈ£¬ÓÈÆäÊǽüÆÚÕë¶ÔÕþÖΡ¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÁìÓòµÄAPT¹¥»÷¿ªÊ¼ÏÔÖøÔö¶à£¬ÐèÒªÒýÆðÏà¹ØÕþÆóºÍ¸öÈËÓû§µÄÖصã¹Ø×¢¡£
¶«Éƽ̨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØÖÁÄ¿Ç°£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´5000Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç»ù´¡Äþ¾²Ñо¿¡¢Êý¾ÝÄþ¾²Ñо¿¡¢5GÄþ¾²Ñо¿¡¢È˹¤ÖÇÄÜÄþ¾²Ñо¿¡¢Òƶ¯Äþ¾²Ñо¿¡¢ÎïÁªÍøÄþ¾²Ñо¿¡¢³µÁªÍøÄþ¾²Ñо¿¡¢¹¤¿ØÄþ¾²Ñо¿¡¢ÐÅ´´Äþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡¢ÎÞÏßÄþ¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·ÀÌåϵ½¨Éè¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£