¶«É­Æ½Ì¨ADLab£ºMSCÎļþµÄÔÚÒ°ÀûÓÃÇé¿öÓëºÚ¿Í¹¥»÷»î¶¯·ÖÎö

Ðû²¼Ê±¼ä 2024-09-14

Ò»¡¢±³ ¾°


2024Äê6ÔÂ22ÈÕ£¬Ò»¸öÀûÓÃMSC¸ñʽµÄÐÂÐ͹¥»÷¼¼ÊõµÄ¶ñÒâÑù±¾·ºÆðÔÚVTƽ̨ÉÏ£¬´ËʱÀûÓÃÕâÖÖ¼¼ÊõµÄ¶ñÒâÑù±¾ÔÚVTÉϾùÏÔʾΪÁã¼ì²âÂÊ¡£ÕâÖÖ¼¼Êõ±»ElasticÑо¿ÍŶÓÃüÃûΪ¡°GrimResource¡±£¬Æäͨ¹ý¶ñÒâ¹¹½¨µÄMSCÎļþÔÚMicrosoft¹ÜÀí¿ØÖÆ̨ÖÐÖ´ÐÐÈÎÒâ´úÂë¡£¶«É­Æ½Ì¨ADLabÔÚ½ñºóµÄÁ½¸öÔÂʱ¼äÖУ¬Á¬Ðø¹ØעʹÓÃÕâÖÖÀûÓÃÊÖ·¨µÄ¹¥»÷£¬Í¨¹ý¼à²âµÄ½á¹û·ÖÎö·¢ÏÖ£º×Ըü¼Êõ¹ûÈ»ºó£¬Í¬À๥»÷ѸËÙÔö¼Ó£¬µ½Ä¿Ç°ÎªÖ¹Äܹ»¼à²âµ½µÄÓÐЧ¹¥»÷¼°Æä¹¥»÷Ñù±¾ÓÐ100¶àÆ𡣶øÇÒÓÐÔ½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓÀûÓøü¼ÊõÔÚÈ«Çò·¶Î§ÄÚ½øÐÐÍøÂç¹¥»÷£¬°üÂÞKimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£Ä¿Ç°ÒÑ·¢ÏÖµÄÄ¿±êÓÐÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¼ÒµÄÕþ¸®»ú¹¹ºÍÆóÒµ£¬Éæ¼°Õþ¸®¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£


ÕâЩ¹¥»÷ÆÕ±éͨ¹ýMSCÎļþ×÷Ϊ¶ñÒâpayload£¬Í¨¹ýÖÖÖÖ·½Ê½·¢Ë͸øÄ¿±ê²¢ÓÕʹĿ±ê´ò¿ª¸ÃÎļþ¡£ÓÉÓÚMSC¸ñʽµÄ¹¥»÷ÎļþÊÇÒ»ÖÖÏà¶Ôº±¼ûµÄÎļþÀàÐÍ£¨¶àÊý±»¹¥»÷Õß¿ÉÄÜÊìϤ.exe¡¢.docµÈ³£¼ûµÄ¿ÉÖ´ÐÐÎļþÀ©Õ¹Ãû£¬µ«²¢²»Á˽â.mscÎļþ£¬Òò´Ë¿ÉÄÜÔÚʵ¼Ê¹¥»÷Öз¢ÉúÆæЧ£©£¬¶øÇÒÄ¿Ç°·À»¤ÏµÍ³Ò²ÏÊÓжԴËÀàÎļþµÄÕë¶ÔÐÔ¼ì²â£¬ËùÒÔºÚ¿ÍÀûÓøü¼ÊõʵÏÖ¹¥»÷µÄÀÖ³ÉÂʸߣ¬±»¼ì²âºÍ·¢Ïֵļ¸ÂʵÍ£¬¾ÍÄ¿Ç°ÎÒÃÇÊӲ쵽¹¥»÷ÓÕ¶ü£¬ÓаüÂÞÈ磺¡°¡¶**ÂÛ̳¡·ÍâÉóר¼ÒÑûÇ뺯ÓëÎÄÕÂÆÀÉ󵥡±¡¢£º¡°ÄäÃûÉó¸åר¼Ò»ØÖ´ (УÍâ) ¡±¡¢¡°ÊÊÓÃÓÚÄϺ£µÄÁ½ÖÖÖ´·¨ÖƶÈÑо¿ (¸å¼þ)¡±¡¢¡°ÃÀ¹úÕ½ÂÔÊÕËõ¶ÔÖж«µØÔµÕþÖεÄÓ°Ï족¡¢¡°****ÍøÂç´ó»á¡±µÈ¼«¾ßÒýÓÕÐԵĹ¥»÷£¬Ò»µ©µã»÷ÆäÖеÄMSCÎļþ£¬Æäϵͳ±ã»á±»Ö²ÈëÇÔÃÜľÂí£¬µ¼ÖÂÖØÒªÃô¸ÐÊý¾Ý±»ÇÔÈ¡¡£


ͨ¹ýÎÒÃǶԹ¥»÷µÄ×·ËÝ·¢ÏÖÔçÔÚ2024Äê4Ô£¬Kimusuky APT×éÖ¯¾Í¿ªÊ¼ÀûÓÃMSCÎļþÀ´¶ÔÆäÄ¿±êʵʩÁË´óÁ¿µÄ¹¥»÷£¬µ«ÆäÀûÓÃÊÖ·¨ÓëGrimResource¼¼ÊõÓÐËù²îÒì¡£ÓÉÓÚMSCÑù±¾µÄ¹ûÈ»ÀûÓúͼ¼ÊõÑݱäÉд¦ÓÚÉú³¤³õÆÚ£¬Òò´ËÓйع¥»÷Ñù±¾ºÍÊÖ·¨µÄ±ä»¯ÖµµÃÒýÆðÁ¬Ðø¹Ø×¢¡£´ËÍ⣬OutflankÓÚ8ÔÂ13ÈÕ·¢ÎijÆGrimResource¼¼ÊõÔ´ÓÚÆäÎäÆ÷¿â£¬ÆäÔÚ¹¥·ÀÑÝÁ·Öб»·ÀÊØ·½ÉÏ´«µ½¹«¹²É³Ïä¡£


MSC(Microsoft Snap-In Control)Îļþ£¬ÊÇ΢Èí¹ÜÀí¿ØÖÆ̨(MMC)ÓÃÀ´Ìí¼Ó/ɾ³ýµÄǶÈëʽ¹ÜÀíµ¥ÔªÎļþ, ÓÉÓÚ´ËÀàÎļþÄܹ»Ö´ÐÐÃüÁîºÍ½Å±¾£¬Òò´Ë¹¥»÷ÕßÄܹ»½èÖúMSCÎļþÔÚÄ¿±êϵͳÉÏÖ´ÐÐÖÖÖÖ¶ñÒâÈÎÎñ¡£×Ô΢ÈíĬÈÏÏÞÖÆÀ´×Ô»¥ÁªÍøµÄOfficeºêÎĵµºó£¬LNK¡¢MSI¡¢ISOµÈÆäËûÀàÐ͵ĶñÒâÀûÓÃÊýÁ¿¾Í¿ªÊ¼´ó·ùÔö¼Ó£¬´Ë´ÎзºÆðµÄGrimResource¼¼ÊõÒ²ÀíËùËäÈ»³ÉΪÁ˺ڿÍÃǵÄг裬Ïà¹ØMSCÑù±¾ÊýÁ¿×Ô4ÔÂÒÔÀ´³Ê¸ßËÙÔö³¤Ì¬ÊÆ¡£Òò´Ë£¬¶«É­Æ½Ì¨ADLabÕë¶Ô½üÆÚ²¶×½µ½µÄMSCÑù±¾½øÐÐÁËÉîÈëµÄ·ÖÎö£¬±¾ÎĽ«Ö÷Òª½éÉÜÄ¿Ç°MSCÎļþÔÚÒ°ÀûÓü¼ÊõµÄÏà¹ØÔ­Àí£¬Åû¶½üÆÚÀûÓÃMSCÎļþµÄ¶àÆð¹¥»÷»î¶¯£¬²¢ÖصãÕë¶ÔÆäÖеÄÁ½¸ö°¸Àý½øÐÐÉîÈë·ÖÎö¡£

¶þ¡¢½üÆÚÔÚÒ°¹¥»÷»î¶¯·ÖÎö



ͨ¹ý¶ÔÄ¿Ç°ÊÕ¼¯µ½µÄ100Óà¸öMSCÑù±¾µÄ·ÖÎö£¬ÎÒÃÇ·¢ÏÖ×îÔçµÄÀûÓÃÑù±¾·ºÆðÔÚ2024Äê4ÔÂ5ÈÕ£¬ËùÓÐÑù±¾ÖУ¬·ºÆðÔÚ4-5ÔµĹ¥»÷Ñù±¾Ö÷ÒªÊôÓÚKimusuky×éÖ¯¡£6Ôºó£¬Ëæ×ÅGrimResource¼¼ÊõµÄ¹ûÈ»£¬MSC¸ñʽµÄÑù±¾ÊýÁ¿ÒÔÔÂΪµ¥Ôª³ÊÃ÷ÏԵĵÝÔö¹Øϵ£¬±íÃ÷ºÚ¿ÍÃÇÕý»ý¼«ÀûÓúͲâÊÔÏà¹Ø¹¥»÷¼¼Êõ²¢×ª»¯ÎªÊµ¼Ê¹¥»÷¡£ÒÔÏÂÊǽü¼¸¸öÔ²¶×½µ½µÄMSC¸ñʽµÄ¹¥»÷Ñù±¾ÊýÁ¿Í¼¡£


ͼƬ1.png

ͼ1 MSC¹¥»÷Ñù±¾ÊýÁ¿Í³¼Æͼ£¨µ¥Ôª:Ô£©


ÔÚÕâÅú¹¥»÷Ñù±¾ÖУ¬ÆäÖÐһЩÊÇ»ùÓÚ¿ªÔ´ÏîÄ¿±àÒëµÄÑù±¾£¨ÈçÏÂͼÖÐͼ±êΪ¡°ÑÛ¾¦¡±µÄÑù±¾¼´Îª¿ªÔ´ÏîÄ¿MSC_DropperÉú³É£©£¬ÕâÀàÑù±¾¿ÉÄÜÊDz¿ÃŹ¥»÷ÕßÕýÔÚ»ý¼«µØ½øÐм¼Êõ×¼±¸ºÍÃâɱ²âÊÔ¡£Í¬Ê±£¬Ò»Ð©ÕæʵµÄ¹¥»÷»î¶¯Ò²Ô½À´Ô½Æµ·±µØ·ºÆð£¬ÔÚʵ¼Ê¹¥»÷ÖÐÑù±¾Í¨³£»á°Ñͼ±êαװ³ÉWORD¡¢PDF¡¢MP4µÈÖÖÖÖ³£¼ûµÄÎļþ¸ñʽÓÃÒÔÃÔ»óÊܺ¦Ä¿±ê£¬ÏÂͼÊDz¿ÃÅÑù±¾¼°Í¼±êʾÀý¡£


ͼƬ2.png

ͼ2 ²¶×½MSCÑù±¾Ê¾Àý


´ÓÖÐÎÒÃÇ·¢ÏÖÁËÊýÆðÕë¶ÔÈ«Çò¶à¸ö¹ú¼ÒºÍµØÓòµÄ¹¥»÷»î¶¯£¬Ä¿±êÖ÷Òª°üÂÞÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢ÃɹŵÈ£¬¹¥»÷µÄÄ¿±êÐÐÒµÔòÉæ¼°Õþ¸®¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£ÆäÖУ¬Õë¶ÔÖйúµÄAPT¹¥»÷»î¶¯ÔÚ½üÆÚ¿ªÊ¼Ã÷ÏÔÔö¶à¡£ÔÚ7Ô³õÆÚ£¬Óйع¥»÷Ö÷ÒªÒÔ¡°Ò×·­ÒëÖúÊÖ¡±¡¢¡±¶¶Òôǧ·ÛÆóÒµºÅ¡±¡¢¡°½ÌÓýÐÐÒµÊý¾Ý¡±µÈΪÓÕ¶üµÄºÚ²ú×éÖ¯¹¥»÷ΪÖ÷¡£¶øÔÚ8ÔÂÖ®ºó£¬¿ªÊ¼Â½Ðø·ºÆðÁ˶àÆðÒÔÕþÖÎÒéÌ⡢ר¼ÒÑûÇë¡¢»áÒéÈճ̡¢Í¶Ëß½¨Òé¡¢¾Ù±¨ÖÊÁϵÈÕë¶ÔÕþ¸®×éÖ¯»ò¿ÆÑв¿ÃŵÄÕë¶ÔÐÔ¹¥»÷£¬ÐèÒªÒýÆð¸ß¶È¾¯Ì裬²¿ÃÅÓÕ¶üÎĵµÈçÏÂËùʾ¡£


ͼƬ3.png

ͼ3 Ö÷ÌâΪ¡°×¨¼ÒÑûÇ뺯¡±ÀàµÄÓÕ¶üÎĵµ


ͼƬ4.png

ͼ4 Ö÷ÌâΪ¡°Õþ²ßÖƶÈÑо¿¡±ÀàµÄÓÕ¶üÎĵµ


ͼƬ5.png

ͼ5 Ö÷ÌâΪ¡°****ÍøÂç´ó»á¡±µÄÓÕ¶üÎĵµ


ͼƬ6.png

ͼ6 Õë¶ÔË®ÀûÊðµÄÓÕ¶üÎĵµ


³ýÁËÕë¶ÔÖйúÒÔÍ⣬º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȶà¹úÒ²½ÓÁ¬ÔâÓöµ½ÀûÓÃMSCÎļþµÄ¹¥»÷»î¶¯£¬ÆäÖÐÓÈÒÔº«¹úÔâÊܵĹ¥»÷×î¶à£¬Õâ¿ÉÄÜÓëkimsuky×éÖ¯µÄ¹¥»÷Ä¿±êÇãÏòÓйØ£¬²¿ÃŹ¥»÷»î¶¯ÓÕ¶üÈçÏÂËùʾ¡£


ͼƬ7.png

ͼ7 Õë¶Ôº«¹úµÄÓÕ¶üÎĵµ


ͼƬ8.png

ͼ8 Õë¶ÔÔ½ÄÏʯÓ͹«Ë¾µÄÓÕ¶üÎĵµ


ÔÚÕë¶ÔÕâÅúÑù±¾½øÐÐÉîÈë·ÖÎöºó£¬ÎÒÃÇ·¢ÏÖÁ˹¥»÷ÕßʹÓõĶà¸ö»ù´¡ÉèÊ©£¬°üÂÞ¶à½×¶ÎÏÂÔØ·þÎñÆ÷ºÍC2·þÎñÆ÷µÈ£¬ÆäÖдó²¿ÃŶ¼½ÓÄÉÁËÔÆ·þÎñÀ´×ÌÈÅËÝÔ´×·×Ù£¬ÆäÖÐһЩ·þÎñÆ÷¹éÊôÓÚÃÀ¹ú¡¢ÈÕ±¾¡¢Èðµä¡¢·¨¹ú¡¢Ð¼ÓƵȹú¼Ò¡£²¿ÃÅÑù±¾¼°C2·þÎñÆ÷ÈçÏÂËùʾ¡£


±í1 ¶ñÒâ·þÎñÆ÷µØÖ·

±í1-1.png

±í1-2.png


ͬʱ£¬ÎÒÃÇÒ²²¶×½µ½Á˲¿ÃÅÑù±¾µÄͶµÝURLµØÖ·ÈçϱíËùʾ¡£


±í2 Ñù±¾Í¶µÝURL

±í2-1.png

±í2-2.png


Èý¡¢MSCÎļþÀûÓü¼ÊõÔ­Àí·ÖÎö


MSC(Microsoft Snap-In Control)Îļþ£¬ÊÇ΢Èí¹ÜÀí¿ØÖÆ̨(MMC)ÓÃÀ´Ìí¼Ó/ɾ³ýµÄǶÈëʽ¹ÜÀíµ¥ÔªÎļþ, ¹ÜÀíԱͨ¹ý´´½¨¿ØÖÆ̨¿ÉÒÔ¹ÜÀí¼ÆËã»úµÄÖÖÖÖÉèÖã¬Ìí¼ÓÖÖÖÖ¹¦Ð§ÈçÓû§ÕË»§¹ÜÀí¡¢ÏµÍ³·þÎñ¡¢É豸Çý¶¯·¨Ê½µÈ£¬È»ºó¿ÉÒÔ½«ÕâЩ¹ÜÀíµ¥ÔªµÄ×Ô½ç˵ÅäÖÃÒÔXMLµÄÐÎʽÉú´æµ½´ÅÅÌÉÏ£¬¼´MSC¸ñʽ¡£WindowsÖг£¼ûµÄÉ豸¹ÜÀíÆ÷¡¢´ÅÅ̹ÜÀíÆ÷¡¢×é¼Æı¹ÜÀíÆ÷µÈ¶¼ÊÇMSC¸ñʽÎļþ¡£ÈçÏÂͼÊÇ×Ô½ç˵MSCÎļþµÄ¹ÜÀíµ¥ÔªÈÎÎñ°å½çÃ棬¹¥»÷Õß¿ÉÒÔͨ¹ý±à³ÌµÄ·½Ê½ÓëMMC½øÐн»»¥£¬´Ó¶ø½á¹¹×Ô½ç˵µÄ½çÃæºÍÄÚÈÝ¡£


ͼƬ9.png

ͼ9 MSCÎļþ¹ÜÀíµ¥ÔªÈÎÎñ°å


ÎÒÃÇÔÚ½øÒ»²½Õë¶ÔÕâÅúÑùÌìÖ°Îöºó£¬·¢ÏÖÄ¿Ç°MSC¸ñʽÎļþµÄÔÚÒ°ÀûÓ÷½Ê½Ö÷ÒªÓÐÁ½ÖÖ¡£ÔÚÊܺ¦ÕßĬÈÏ¿ªÆôÓû§ÕË»§¿ØÖÆ£¨UAC£©µÄÇé¿öÏ£¬µÚÒ»ÖÖÀûÓ÷½Ê½ÐèÒªÓëÊܺ¦Õß½»»¥Á½´Î£¨Ö÷ÒªÓÉKimusuky×é֯ʹÓã©£»ÁíÒ»ÖÖÖ»Ðè½»»¥Ò»´Î(GrimResource¼¼Êõ)£¬Ïà¹Ø¼¼ÊõÀûÓÃÁ÷³ÌͼÈçÏÂËùʾ¡£

ͼƬ10.png

ͼ10 MSCÎļþ¼¼ÊõÀûÓÃÁ÷³Ìͼ


ÀûÓ÷½Ê½Ò»£ºÔÚÊܺ¦Õß´ò¿ªMSCÎļþºó£¬Ê×Ïȵ¯³öUAC¿ØÖÆÑ¡ÏÈç¹ûÑ¡ÔñÊÇ£¬Ôò¼ÌÐøµ¯³ö¹¥»÷Õ߶¨ÖƵÄMicrosoft¹ÜÀí¿ØÖÆ̨½çÃæÓÕµ¼Ä¿±ê£¬Ò»µ©Êܺ¦Õß¼ÌÐøµã»÷open´ò¿ªÎĵµ¼´»áÖÐÕУ¬Ö´ÐÐcmdÃüÁî¡¢powershell½Å±¾µÈºóÐøÀûÓý׶Ρ£

ͼƬ11.png

ͼ11 ÀûÓ÷½Ê½Ò»


¶ÔÓÚ´ËÀàÑù±¾£¬¹¥»÷Õßͨ¹ý±à¼­MSCÎļþµÄ½çÃæαÔìUIÍâ¹Û£¬´Ó¶øÓÕÆ­Êܺ¦Õßµã»÷¿ØÖÆ̨ÈÎÎñ°åÉϵÄÁ´½Ó£¬¶ø²»»á·¢Éú»³ÒÉ¡£ÕâÖÖÀûÓ÷½Ê½½èÖúÁËMMCÖеĿØÖÆ̨ÈÎÎñ°åʵʩ¹¥»÷£¬¿ØÖÆ̨ÈÎÎñ°åÊÇÔÚMMC1.2ÖÐÒýÈëµÄ£¬¹¥»÷Õß¿ÉÒÔ½èÖú¿ØÖÆ̨ÈÎÎñ°åÀ´Ö´ÐÐÖÖÖÖÈÎÎñ£¬ÀýÈç´ò¿ªÊôÐÔÒ³¡¢Ö´Ðв˵¥ÃüÁî¡¢ÔËÐÐÃüÁîÐкʹò¿ªÍøÒ³µÈ£¬Ä¿Ç°Ö÷Òª·¢ÏÖKimsuky×éÖ¯ÔÚ´óÁ¿Ê¹ÓôËÀ๥»÷·½Ê½£¬Ïà¹ØÀûÓÃÑù±¾µÄ×îÔç·ºÆðʱ¼äÊÇÔÚ½ñÄê4ÔÂ5ÈÕ£¬ÀûÓÃʾÀýÈçÏÂͼËùʾ¡£

ͼƬ12.png

ͼ12 ¿ØÖÆ̨ÈÎÎñ°åÖ´ÐÐÈÎÒâÃüÁîʾÀý


ͼƬ13.png

ͼ13 ÈÎÎñ°åÖ´ÐÐÈÎÒâÃüÁîXML


ÀûÓ÷½Ê½¶þ£ºGrimResource¼¼Êõ£¬¸Ã¼¼ÊõÀûÓÃapds.dllÖеÄXSS©¶´£¬Í¨¹ýMSCÎļþµÄStringTable²¿ÃÅÒýÓÃÒ×Êܹ¥»÷µÄAPDS×ÊÔ´£¬´Ó¶øʵÏÖǶÈëÔÚMSCÎļþÖеÄJS´úÂëÈÎÒâÖ´ÐУ¬×îºóÖ´ÐÐXMLÖеĽű¾´úÂë¡£Ïà½ÏÓÚÀûÓ÷½Ê½Ò»£¬Æä¾ßÓÐ×îÉÙµÄÄþ¾²¾¯¸æ£¬ÎÞÒÉÄܹ»Ê¹µÃ¹¥»÷µÄÀÖ³ÉÂÊ´ó´óÌá¸ß¡£Í¬Ê±£¬¶ÔÓںܶàΪÁË·½±ã¶øĬÈÏÈ¡ÏûUAC֪ͨµÄÊܺ¦ÕßÀ´Ëµ¸üÊÇÄܵ½´ïÎÞ½»»¥¼´¿ÉÖ´ÐеÄЧ¹û¡£
¼¼ÊõÀûÓÃÒªº¦µã£º


  • ½«ActiveX¹¤¾ß¼ÓÔص½¡°ActiveX¿Ø¼þ¡±¹ÜÀíµ¥ÔªÖС£

  • ½«HTMLÎļþ¼ÓÔص½¡°Á´½Óµ½WebµØÖ·¡±¹ÜÀíµ¥ÔªÖС£

  • ÔÚHTMLÎļþÖУ¬Ê¹ÓÃJavaScriptÓë¼ÓÔصÄActiveX¹¤¾ß½øÐн»»¥¡£²¢Í¨¹ý MSXMLÒªÁ죬´¥·¢XSLת»»À´Ö´ÐÐJScript´úÂë¡£

  • ×îºó´ÓJScript´úÂëÖе÷ÓÃϵͳº¯Êý£¬»òÕßͨ¹ý DotNetToJScript Ö´ÐÐ.NET´úÂë¡£


Ê×ÏÈ£¬ÔÚMMC·¨Ê½ÖУ¬¹¥»÷Õß¿ÉÒÔ×Ô½ç˵²åÈëActiveX¿Ø¼þ¡£Í¨¹ýÎļþ±à¼­Æ÷´ò¿ª´´½¨µÄMSCÎļþʱ£¬¿ÉÒÔ¿´µ½´´½¨µÄActiveX¿Ø¼þ´æ´¢ÔÚXMLµÄStringTableÖС£


ͼƬ14.png

ͼ14 ²åÈëActiveX¿Ø¼þ¹¤¾ß


µ«Èç¹ûÏëÀֳɼÓÔع¤¾ß£¬¾ÍÒªÈƹýActiveX ¿Ø¼þµÄÄþ¾²¾¯¸æ¡£¹¥»÷Õß½ÓÄÉÁËÒ»ÖÖÇÉÃîµÄÒªÁ죬ͨ¹ýMicrosoft Internet Explorerä¯ÀÀÆ÷×é¼þ·ÃÎÊexternal ¹¤¾ß£¬´Ó¶øÓëMMC¿ØÖÆ̨µÄÆäËûÔªËؽøÐн»»¥£¬ÕâÊÇ΢Èí¹Ù·½Ö§³ÖµÄÒ»ÖÖ·½Ê½¡£ÈçÏÂͼÖУ¬scopeNamespaceºÍdocObject¼´ÊÇͨ¹ýexternal.Document»ñÈ¡ÏÖÓй¤¾ß£¬¶ø·Ç´´½¨ÐµÄActiveX¹¤¾ß£¬½ø¶øÈƹýÁËÖ±½Ó´´½¨ActiveX¿Ø¼þʱµÄÄþ¾²ÏÞÖÆ¡£


ͼƬ15.png

ͼ15 GrimResource¼¼ÊõÀûÓôúÂë


ͬʱ£¬¹¥»÷ÕßÀûÓÃÁËapds.dllµÄÒ»¸öXSS©¶´£¬´Ó¶ø¿ÉÒÔÖ´ÐÐConsole RootÖеÄJscript£¬½ø¶øÔÙÖ´ÐÐXMLÖеĽű¾¡£ÕâÆäÖл¹Éæ¼°µ½Ò»¸ö¼¼ÇÉ£¬¼´ÀûÓÃMSXML£¨Microsoft.XMLDOM / {2933BF90-7B36-11D2-B20E-00C04F983E60} £©Ö´ÐÐXSLÎļþÖÐǶÈëµÄ½Å±¾¡£

XSLTÊÇÒ»ÖÖÓÃÓÚ½«XMLÎĵµ×ª»»ÎªÆäËûÎĵµ¸ñʽµÄÓïÑÔ£¬XSLTÑùʽ±í£¨XSL£©Ôò½ç˵ÁËÈçºÎ½«Ò»¸öXMLÎĵµ×ª»»ÎªÆäËûÐÎʽ¡£Î¢ÈíÖ§³ÖMSXML XSLTʹÓÃÔªËؼ°ÆäÊôÐÔimplements-prefixʵÏÖ²¢À©Õ¹º¯ÊýÒÔÌṩ½Å±¾¼¶Ö§³Ö¡£Òò´Ë£¬¹¥»÷Õßͨ¹ýMSXMLµÄ·½Ê½¼´¿ÉÖ´ÐÐXSLÎļþÖÐǶÈëµÄ½Å±¾£¬Èçµ÷Óú¯Êý XML.transformNode(xsl)£¬¼´¿ÉÖ´ÐÐǶÈëµÄ½Å±¾¼°ºóÐøµÄ¶ñÒâÀûÓÃÄ£¿é£¬½âÂë½Å±¾ÖеıêÇ©ÈçÏÂͼËùʾ¡£


ͼƬ16.png

ͼ16 ½Å±¾ÖеÄ



ËÄ¡¢°¸Àý·ÖÎö


¶«É­Æ½Ì¨ADLab½ÓÁ¬²¶×½µ½Á˶àÆðÀûÓÃMSCÎļþÕë¶ÔÈ«ÇòÄ¿±êµÄ¹¥»÷»î¶¯¡£ÆäÖÐÒÑ·¢ÏÖÕë¶ÔÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¼ÒµÄÕþ¸®»ú¹¹ºÍÆóÒµµÄ¹¥»÷£¬Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓÕýÔÚÀûÓÃÏà¹Ø¼¼ÊõÔÚÈ«Çò·¶Î§ÄÚ½øÐÐÍøÂç¹¥»÷£¬°üÂÞKimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£ÔÚÖî¶àµÄ¹¥»÷°¸ÀýÖУ¬ÎÒÃÇÑ¡È¡ÁËÔÚ¼¼Êõ²ãÃæ½ÏÓдú±íÐÔÇÒÏà¶ÔÃô¸ÐµÄÁ½À๥»÷Ñù±¾×÷Ϊ´Ë´ÎµÄ·ÖÎö°¸Àý£¬ÀûÓÃGrimResource¼¼ÊõÕë¶ÔÖйúµÄ¹¥»÷»î¶¯£¬ÒÔ¼°Kimsuky×éÖ¯ÀûÓÃMMC¿ØÖÆ̨ÈÎÎñ°åÕë¶Ôº«¹úµÄ×îй¥»÷»î¶¯¡£ÏÂÃæÎÒÃǽ«¶ÔÑ¡È¡µÄÁ½¸ö°¸Àý½øÐÐÉîÈëµÄ·ÖÎö¡£


4.1 ÒÔÕþÖλ°ÌâΪÓÕ¶üÕë¶ÔÖйúµÄ¹¥»÷»î¶¯


´Ë°¸ÀýÀûÓõÄÊÇGrimResource¼¼Êõ£¬µ±Êܺ¦Õßµã»÷ÔËÐÐmscÎļþʱ£¬mmc.exe»áÖ´ÐÐÑù±¾ÖеÄjs´úÂ룬¼Ì¶øÖ´ÐÐǶÈëÔÚxmlÖеÄVBScript´úÂë¡£ÆäÖУ¬ÒýÖÂVBA´úÂëµÄÖ´ÐеÄÒªº¦µãÊÇtransforNode(xsl)ÒªÁìµÄµ÷Óá£


ͼƬ17.png

ͼ17 ÒýÖÂVBA´úÂëÖ´ÐеÄÒªº¦µã


transforNodeÒªÁì³£ÓÃÓÚ½«Ò»¸öXMLÎĵµÍ¨¹ýXSLTÑùʽ±í£¨×÷Ϊ²ÎÊý£©×ª»»ÎªÆäËûÎĵµ¸ñʽ¡£Èç¹ûXSLTÑùʽ±íÖк¬ÓлòÔªËØʱ£¬ÄÇôԪËØÖеĽű¾Ôò»áÔÚת»»¹ý³ÌÖб»Ö´ÐС£


ͼƬ18.png

ͼ18 XSLTÑùʽ±íÄÚÈÝ


±»Ö´ÐеÄVBScript´úÂëͨ¹ý×Ô½ç˵±àÂëºÍ½âÂë¡¢×Ö·û´®Æ´½Ó¡¢ÌØÊâ×Ö·û»ìºÏ±àÂëµÈ»ìÏý¼¼Êõ£¬Äܹ»ÓÐЧµØÒþ²ØÆäÕæʵÂß¼­ºÍ¶ñÒâÐÐΪ£¬Í¬Ê±Ôö¼ÓÁË·ÖÎöÈËÔ±½øÐÐÄæÏò·ÖÎöµÄʱ¼ä³É±¾¡£ÏÂͼչʾÁËÔÚÊ״νâÂëÖ®ºóµÄ²¿ÃÅ´úÂë¿é£¬Äܹ»¿´µ½´úÂëÖÐÒÀÈ»´æÔÚ×ÅÆäËû»ìÏý¡£


ͼƬ19.png

ͼ19 »ìÏýµÄVBScript´úÂë


ÎÒÃǼÌÐø¶Ô´úÂë½øÐÐÈ¥»ìÏýÒÔ¼°º¯ÊýÖØÃüÃû´¦Öú󣬿ÉÒÔ¿´µ½½Å±¾ÏÈÊÇÉèÖÃÎļþ·¾¶ºÍĿ¼½á¹¹£¬ÔÙ´ÓXML½á¹¹ÖÐÌáÈ¡Êý¾Ý½øÐÐbase64½âÂë²¢Éú´æΪָ¶¨Îļþ£¨ÓÕ¶üÎĵµ£©£¬×îºó´ò¿ª¸ÃÎļþ¡£


ͼƬ20.png

ͼ20 ÊÍ·ÅÓÕ¶üÎĵµ


ÔÚ±¾°¸ÀýÖУ¬ÓÃÓÚÃÔ»óÊܺ¦ÕßµÄÊÇÈý¸öαװ³ÉWordµÄÓÕ¶üMSCÎļþ£¬¾ßÌåÄÚÈÝÈçÏÂͼËùʾ¡£


ͼƬ21.png

ͼ21 ÓÕ¶üÎĵµÊ¾ÀýÒ»


ͼƬ22.png

ͼ22 ÓÕ¶üÎĵµÊ¾Àý¶þ


ͼƬ23.png

ͼ23 ÓÕ¶üÎĵµÊ¾ÀýÈý


½Ó×ÅÌáÈ¡ºÍ½âÂëÆäËûbase64Êý¾Ý£¬ÔÙ½«½âÂëºóµÄÊý¾ÝÉú´æΪ×îÖÕµÄWarp.exeºÍ7z.dll¿ÉÖ´ÐÐÎļþ¡£Ëæºó½«¡° t 8.8.8.8¡±×÷Ϊ²ÎÊý£¨×Ô¶¯¼ÓÔØͬĿ¼Ï¡°7z.dll¡±µÄËùÐèÌõ¼þ£©Æô¶¯Warp.exe·¨Ê½¡£


ͼƬ24.png

ͼ24 Éú³É²¢Ö´ÐÐwarp.exe·¨Ê½


¾­¼ì²ì£¬¡°Warp.exe¡±¾ßÓÐ ¡°Lenovo (Beijing) Co., Ltd.¡±µÄºÏ·¨Êý×ÖÇ©Ãû£¬ÆäÔ­ÎļþÃûΪ¡°7zwrap.exe¡±¡£¾ßÌåÐÅÏ¢ÈçÏÂͼËùʾ¡£


ͼƬ25.png

ͼ25 ¡°Warp.exe¡±ÏêϸÐÅÏ¢


µ±¶ñÒâ¡°7z.dll¡±Îļþ±»¡°Wrap.exe¡±ÀֳɼÓÔغó£¬Æä»áÔÚÄÚ´æÖжÔÖ¸¶¨Êý¾Ý½øÐнâÃÜ¡£¾­ÄÚ´æÌØÕ÷ɨÃèºó£¬Åж¨×îÖÕ±»¼ÓÔØÖ´ÐеÄÊÇCobaltStrike£¬ÎÒÃÇÌáÈ¡³öµÄCSÅäÖÃÐÅÏ¢ÈçÏÂͼËùʾ¡£



ͼƬ26.png

ͼ26 CSÅäÖÃÐÅÏ¢


4.2 ÒÔѧÊõÑݽ²ÎªÓÕ¶üÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯


¸Ã°¸ÀýÊÇKimsuky APTºÚ¿Í×éÖ¯ÔÚ½ñÄêËùÒýÈëµÄÒ»ÖÖÐµĹ¥»÷¼Æı£¬¹¥»÷Õßͨ¹ýXMLµÄÉèÖÃÊôÐÔ½«MSC¶ñÒâÎļþµÄͼ±êÉèÖÃΪWordͼ±ê£¬½èÒÔαװ³ÉWORDÎĵµÀ´ÃÔ»óÊܺ¦Õß¡£


ͼƬ27.png

ͼ27 αװµÄWordͼ±ê


µ±Êܺ¦Õßµã»÷MSCÎļþʱ£¬Óû§ÕË»§¿ØÖÆ£¨UAC£©»áµ¯³öÇëÇóȨÏÞÑ¡Ôñ£¬Èç¹ûÑ¡[ÊÇ]£¬Ôò»áͨ¹ýÖ´ÐÐmscÁ¬½Ó·¨Ê½mmc.exe£¬Õ¹Ê¾¹¥»÷Õ߶¨ÖƵÄÃûΪ¡°?????.docx¡±µÄMicrosoft¹ÜÀí¿ØÖÆ̨½çÃæ¡£¾ßÌåÈçÏÂͼËùʾ¡£


ͼƬ28.png

ͼ28 ¡°?????.docx¡±µÄMicrosoft¹ÜÀí¿ØÖÆ̨½çÃæ


´úÂëÖаüÂÞÒ»¶Îcmd²ÎÊýÃüÁîÐУ¬ÆäÖÐʹÓÃÁËÈý¸öÍøÒ³ä¯ÀÀÆ÷¿Éʶ´ËÍâHTMLÌØÊâ·ûºÅ£¬ÆäËù¶ÔÓ¦µÄ½âÎöÄÚÈÝÈçϱíËùʾ¡£


±í3 ÌØÊâ·ûºÅÄÚÈݽâÎö

±í3.png


ͼƬ29.png

ͼ29 º¬ÓÐÌØÊâ·ûºÅµÄcmd²ÎÊýÃüÁîÐÐÄÚÈÝ


ͨ¹ý¸Ã·ûºÅËù¶ÔÓ¦µÄ½âÎö½øÐÐÌæ»»ºó£¬µÃµ½ÁËÈçÏÂͼËùʾµÄÅú´¦ÖÃÃüÁî¡£¸Ã´®Åú´¦ÖÃÃüÁîÔòÊÇÖ´ÐÐMSCºóµÄ¹ÜÀí¿ØÖÆ̨¸ùÈÎÎñ´°¿ÚµÄÃüÁîÐвÎÊý¡£¸Ã¶ÎÃüÁîµÄÖ÷Òª¹¦Ð§ÊÇ´ÓÖ¸¶¨URLÏÂÔØÃûΪ¡°Grieco Kavanagh Passive Supporters.docx¡±µÄÓÃÓÚαװµÄÓÕ¶üÎĵµ£¬ÒÔ¼°ºóÐø½×¶ÎµÄ¡°pest.exe¡±ºÍ¡°pest.exe.manifest¡±Îļþ¡£³ý´ËÖ®Í⣬Æ仹»á´´½¨Ò»¸öÃûΪ¡°TemporaryClearStatesesf¡±µÄ¼Æ»®ÈÎÎñ£¬Ã¿58·ÖÖÓÖ´ÐÐÒ»´Î¡°%appdata%\pest.exe¡±Îļþ¡£ÄÚÈÝÈçÏÂͼËùʾ¡£


ͼƬ30.png

ͼ30 cmd²ÎÊýÃüÁîÐÐÄÚÈÝ


¼ì²ì¡°pest.exe¡±·¨Ê½ÏêϸÐÅÏ¢£¬·¢Ïָ÷¨Ê½µÄÊý×ÖÇ©ÃûÃû³ÆΪ¡°Adersoft¡±£¬Ô­Ê¼ÎļþÃûΪ¡°launcher.exe¡±¡£¸Ã·¨Ê½ÎªVBSEdit£¨ÓÉAdersoft¹«Ë¾³öÆ·µÄÒ»¿îСÇɶøÇ¿º·µÄVBScript±à¼­¹¤¾ß£©½Å±¾Æô¶¯Æ÷¡£


ͼƬ31.png

ͼ31 ¡°pest.exe¡±·¨Ê½ÏêϸÐÅÏ¢


ÔÚ¡°pest.exe¡±·¨Ê½Æô¶¯Ê±£¬»áĬÈϼÓÔØ¡°pest.exe.manifest¡±Îļþ£¬. manifestÎļþÊÇWindowsÓ¦Ó÷¨Ê½Çåµ¥ÎļþµÄÒ»²¿ÃÅ£¬³£ÓÃÓÚÖ¸¶¨Ó¦Ó÷¨Ê½µÄÔËÐÐʱÌõ¼þºÍ»·¾³±äÁ¿µÈ¡£¹¥»÷ÕßÀûÓô˷¨Ê½µÄÔËÐлúÖƽ«¶ñÒâ´úÂëдÈëÖÁÇåµ¥ÎļþÖУ¬ÄÇôµ±¡°pest.exe¡±·¨Ê½ÔËÐÐʱ¶ñÒâ´úÂë±ã¿É±»×Ô¶¯¼ÓÔØÖ´ÐС£


ͼƬ32.png

ͼ32 ¡°pest.exe¡±·¨Ê½Ö´Ðб¨´í


 ¡°pest.exe.manifest¡±ÎļþÄÚÈÝÊÇXML¸ñʽ£¬¶ñÒâ´úÂë°üÂÞÔÚ¡°¡±±êÇ©Ö®¼ä¡£¸ÃÎļþµÄÖ÷Òª¹¦Ð§ÊÇÓÉÒ»¶Î¾­base64±àÂëµÄVBScript´úÂëÀ´ÊµÏÖ¡£²¿ÃÅ´úÂëÈçÏÂͼËùʾ¡£


ͼƬ33.png

ͼ33 base64±àÂëµÄVBScript´úÂë


½âÂëºóÎÒÃÇ¿ÉÒÔ¿´µ½£¬¶ñÒâ´úÂëÊ×ÏÈ»áÅжÏ"%appdata%\ Microsoft \"Ŀ¼ÏÂÊÇ·ñ´æÔÚ¡°sim.sid¡±Îļþ¡£Èô´æÔÚÇÒСÓÚ9×Ö½Ú£¬Ôòɾ³ý¸ÃÎļþ²¢Í˳ö½Å±¾£»·ñÔò£¬½«¡°sim.sid¡±Òƶ¯ÖÁ¡±%appdata%\Microsoft\sif.bat"²¢ÔËÐÐbatÎļþ£¬Ö´ÐÐÍê³Éºóɾ³ý×ÔÉíÎļþ¡£


ͼƬ34.png

ͼ34 batÎļþ²Ù×÷´úÂë


Èç¹û¡°sim.sid¡±Îļþ²»´æÔÚ£¬ÔòÏòÖ¸¶¨µÄGoogle driveÁ´½Ó·¢ËÍHTTPÇëÇ󣬲¢»ñÈ¡ÏìÓ¦ÄÚÈÝ¡£


ͼƬ35.png

ͼ35 ÏòGoogle drive¹²ÏíÁ´½Ó·¢ËÍÇëÇó


ÀֳɻñÈ¡ºó£¬´Ó½ÓÊÕµ½µÄÄÚÈÝÖÐÌáÈ¡base64±àÂëµÄÊý¾Ý£¨ÔÚ"pprbstart--"ºÍ"--pprbend"±êÇ©Ö®¼ä£©£¬×îºóÌæ»»ÌØÊâ×Ö·û²¢½«½âÂëºóµÄÊý¾ÝдÈëÖÁ¡±%appdata%\Microsoft\sif.bat"¡£


ͼƬ36.png

ͼ36 ½âÎöÏìÓ¦ÄÚÈÝ


½ØÖ¹·ÖÎöʱ¸ÃGoogle drive¹²ÏíÁ´½ÓÒÑʧЧ£¬ÔÝʱÎÞ·¨»ñÈ¡µ½ºóÐø½×¶ÎµÄ¹¥»÷Ñù±¾£¬·ÖÎöÖÁ´Ë½áÊø¡£


Îå¡¢×Ü ½á


±¾ÎÄÕë¶ÔÎÒÃǽüÆÚ²¶×½µ½µÄһϵÁлùÓÚÐÂÐÍMSCÎļþµÄ¹¥»÷»î¶¯½øÐÐÁË·ÖÎö£¬Öصã½éÉÜÁËÄ¿Ç°MSCÎļþÔÚҰʹÓõÄÁ½ÖÖÀûÓü¼ÊõÔ­Àí£¬Åû¶½üÆÚÀûÓÃMSCÎļþµÄ¶àÆðÃô¸Ð¹¥»÷»î¶¯£¬²¢Õë¶ÔÆäÖеÄÁ½¸ö°¸Àý½øÐÐÁËÉîÈë·ÖÎö¡£´Ó½ü¼¸¸öÔÂMSCÎļþÏà¹Ø¹¥»÷µÄ»îÔ¾Ç÷ÊÆÀ´¿´£¬¹¥»÷»î¶¯Éæ¼°µ½Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²ú×éÖ¯ÒÔ¼°ºì¶ÓµÈ£¬ÓÈÆäÊǽüÆÚÕë¶ÔÕþÖΡ¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÁìÓòµÄAPT¹¥»÷¿ªÊ¼ÏÔÖøÔö¶à£¬ÐèÒªÒýÆðÏà¹ØÕþÆóºÍ¸öÈËÓû§µÄÖصã¹Ø×¢¡£


ͬʱ£¬MSCÎļþµÄ¹ûÈ»ÀûÓúͼ¼ÊõÑݱäÉд¦ÓÚÉú³¤³õÆÚ£¬¾¡¹ÜÄ¿Ç°Ö»ÊÇ·¢ÏÖÁËÁ½ÖÖÔÚÒ°ÀûÓ÷½Ê½£¬µ«MMC×Ô¼º´æÔÚ²»ÉÙÄþ¾²Òþ»¼£¬Î´À´Ëæןü¶à¹¥·ÀÑо¿ÈËÔ±µÄÉîÈëÍÚ¾ò£¬¿ÉÄ᷺ܻÆð¸ü¶à»ùÓÚMSC»òÊÇÆäËüWindows×é¼þµÄÐÂÐͶñÒâÀûÓü¼Êõ£¬¶«É­Æ½Ì¨ADLabÒ²½«Á¬Ðø×·×ÙÏà¹Ø¼¼ÊõµÄÉú³¤Ñݽø£¬¼°Ê±Åû¶ÓйØÍþв»î¶¯¡£


¶«É­Æ½Ì¨»ý¼«·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨Á¢ÓÚ1999Ä꣬ÊÇÖйúÄþ¾²ÐÐÒµ×îÔ罨Á¢µÄ¹¥·À¼¼ÊõÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPP¼Æ»®ºËÐijÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£½ØÖÁÄ¿Ç°£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Äþ¾²Â©¶´5000Óà¸ö£¬Á¬Ðø±£³Ö¹ú¼ÊÍøÂçÄþ¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç»ù´¡Äþ¾²Ñо¿¡¢Êý¾ÝÄþ¾²Ñо¿¡¢5GÄþ¾²Ñо¿¡¢È˹¤ÖÇÄÜÄþ¾²Ñо¿¡¢Òƶ¯Äþ¾²Ñо¿¡¢ÎïÁªÍøÄþ¾²Ñо¿¡¢³µÁªÍøÄþ¾²Ñо¿¡¢¹¤¿ØÄþ¾²Ñо¿¡¢ÐÅ´´Äþ¾²Ñо¿¡¢ÔÆÄþ¾²Ñо¿¡¢ÎÞÏßÄþ¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·ÀÌåϵ½¨Éè¡£Ñо¿½á¹ûÓ¦ÓÃÓÚ²úÎïºËÐļ¼ÊõÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÄþ¾²·þÎñµÈ¡£



adlab.jpg