bevictorΰµÂADLab£ºMSCÎļþµÄÔÚҰʹÓÃÇéÐÎÓëºÚ¿Í¹¥»÷Ô˶¯ÆÊÎö
Ðû²¼Ê±¼ä 2024-09-14Ò»¡¢±³ ¾°
2024Äê6ÔÂ22ÈÕ£¬£¬Ò»¸öʹÓÃMSCÃûÌõÄÐÂÐ͹¥»÷ÊÖÒյĶñÒâÑù±¾·ºÆðÔÚVTƽ̨ÉÏ£¬£¬´ËʱʹÓÃÕâÖÖÊÖÒյĶñÒâÑù±¾ÔÚVTÉϾùÏÔʾΪÁã¼ì²âÂÊ¡£¡£ÕâÖÖÊÖÒÕ±»ElasticÑо¿ÍŶÓÃüÃûΪ¡°GrimResource¡±£¬£¬Æäͨ¹ý¶ñÒâ¹¹½¨µÄMSCÎļþÔÚMicrosoftÖÎÀí¿ØÖÆÌ¨ÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£bevictorΰµÂADLabÔÚÒÔºóµÄÁ½¸öÔÂʱ¼äÖУ¬£¬Ò»Á¬¹Ø×¢Ê¹ÓÃÕâÖÖʹÓÃÊÖ·¨µÄ¹¥»÷£¬£¬Í¨¹ý¼à²âµÄЧ¹ûÆÊÎö·¢Ã÷£º×Ô¸ÃÊÖÒÕ¹ûÕæºó£¬£¬Í¬À๥»÷ѸËÙÔöÌí£¬£¬µ½ÏÖÔÚΪֹÄܹ»¼à²âµ½µÄÓÐÓù¥»÷¼°Æä¹¥»÷Ñù±¾ÓÐ100¶àÆð¡£¡£²¢ÇÒÓÐÔ½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓʹÓøÃÊÖÒÕÔÚÈ«Çò¹æÄ£ÄÚ¾ÙÐÐÍøÂç¹¥»÷£¬£¬°üÀ¨Kimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£¡£ÏÖÔÚÒÑ·¢Ã÷µÄÄ¿µÄÓÐÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¼ÒµÄÕþ¸®»ú¹¹ºÍÆóÒµ£¬£¬Éæ¼°Õþ¸®¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£¡£
ÕâЩ¹¥»÷ÆÕ±éͨ¹ýMSCÎļþ×÷Ϊ¶ñÒâpayload£¬£¬Í¨¹ýÖÖÖÖ·½·¨·¢Ë͸øÄ¿µÄ²¢ÓÕʹĿµÄ·¿ª¸ÃÎļþ¡£¡£ÓÉÓÚMSCÃûÌõĹ¥»÷ÎļþÊÇÒ»ÖÖÏà¶ÔÓÐÊýµÄÎļþÀàÐÍ£¨´ó¶¼±»¹¥»÷Õß¿ÉÄÜÊìϤ.exe¡¢.docµÈ³£¼ûµÄ¿ÉÖ´ÐÐÎļþÀ©Õ¹Ãû£¬£¬µ«²¢²»Ïàʶ.mscÎļþ£¬£¬Òò´Ë¿ÉÄÜÔÚÏÖʵ¹¥»÷Öб¬·¢ÆæÐ§£©£¬£¬²¢ÇÒÏÖÔÚ·À»¤ÏµÍ³Ò²ÏÊÓжԴËÀàÎļþµÄÕë¶ÔÐÔ¼ì²â£¬£¬ÒÔÊǺڿÍʹÓøÃÊÖÒÕʵÏÖ¹¥»÷µÄÀÖ³ÉÂʸߣ¬£¬±»¼ì²âºÍ·¢Ã÷µÄ¼¸Âʵͣ¬£¬¾ÍÏÖÔÚÎÒÃÇÊӲ쵽¹¥»÷ÓÕ¶ü£¬£¬ÓаüÀ¨È磺¡°¡¶**ÂÛ̳¡·ÍâÉóר¼ÒÔ¼Ç뺯ÓëÎÄÕÂÆÀÉ󵥡±¡¢£º¡°ÄäÃûÉó¸åר¼Ò»ØÖ´ (УÍâ) ¡±¡¢¡°ÊÊÓÃÓÚÄϺ£µÄÁ½ÖÖÖ´·¨ÖƶÈÑо¿ (¸å¼þ)¡±¡¢¡°ÃÀ¹úÕ½ÂÔËõ¶Ì¶ÔÖж«µØÔµÕþÖεÄÓ°Ï족¡¢¡°****ÍøÂç´ó»á¡±µÈ¼«¾ßÒýÓÕÐԵĹ¥»÷£¬£¬Ò»µ©µã»÷ÆäÖеÄMSCÎļþ£¬£¬Æäϵͳ±ã»á±»Ö²ÈëÇÔÃÜľÂí£¬£¬µ¼ÖÂÖ÷ÒªÃô¸ÐÊý¾Ý±»ÇÔÈ¡¡£¡£
ͨ¹ýÎÒÃǶԹ¥»÷µÄ×·ËÝ·¢Ã÷ÔçÔÚ2024Äê4Ô£¬£¬Kimusuky APT×éÖ¯¾Í×îÏÈʹÓÃMSCÎļþÀ´¶ÔÆäÄ¿µÄʵÑéÁË´ó×ڵĹ¥»÷£¬£¬µ«ÆäʹÓÃÊÖ·¨ÓëGrimResourceÊÖÒÕÓÐËù²î±ð¡£¡£ÓÉÓÚMSCÑù±¾µÄ¹ûÕæÊ¹ÓúÍÊÖÒÕÑݱäÉд¦ÓÚÉú³¤³õÆÚ£¬£¬Òò´ËÓйع¥»÷Ñù±¾ºÍÊÖ·¨µÄת±äÖµµÃÒýÆðÒ»Á¬¹Ø×¢¡£¡£±ðµÄ£¬£¬OutflankÓÚ8ÔÂ13ÈÕ·¢ÎijÆGrimResourceÊÖÒÕÔ´ÓÚÆäÎäÆ÷¿â£¬£¬ÆäÔÚ¹¥·ÀÑÝÁ·Öб»·ÀÊØ·½ÉÏ´«µ½¹«¹²É³Ïä¡£¡£
¶þ¡¢½üÆÚÔÚÒ°¹¥»÷Ô˶¯ÆÊÎö
ͨ¹ý¶ÔÏÖÔÚÍøÂçµ½µÄ100Óà¸öMSCÑù±¾µÄÆÊÎö£¬£¬ÎÒÃÇ·¢Ã÷×îÔçµÄʹÓÃÑù±¾·ºÆðÔÚ2024Äê4ÔÂ5ÈÕ£¬£¬ËùÓÐÑù±¾ÖУ¬£¬·ºÆðÔÚ4-5ÔµĹ¥»÷Ñù±¾Ö÷ÒªÊôÓÚKimusuky×éÖ¯¡£¡£6Ôº󣬣¬Ëæ×ÅGrimResourceÊÖÒյĹûÕæ£¬£¬MSCÃûÌõÄÑù±¾ÊýÄ¿ÒÔÔÂΪµ¥Î»³ÊÏÔ×ŵĵÝÔö¹ØÏµ£¬£¬Åú×¢ºÚ¿ÍÃÇÕýÆð¾¢Ê¹ÓúͲâÊÔÏà¹Ø¹¥»÷ÊÖÒÕ²¢×ª»¯ÎªÏÖʵ¹¥»÷¡£¡£ÒÔÏÂÊǽü¼¸¸öÔ²¶»ñµ½µÄMSCÃûÌõĹ¥»÷Ñù±¾ÊýĿͼ¡£¡£

ͼ1 MSC¹¥»÷Ñù±¾ÊýĿͳ¼ÆÍ¼£¨µ¥Î»:Ô£©
ÔÚÕâÅú¹¥»÷Ñù±¾ÖУ¬£¬ÆäÖÐһЩÊÇ»ùÓÚ¿ªÔ´ÏîÄ¿±àÒëµÄÑù±¾£¨ÈçÏÂͼÖÐͼ±êΪ¡°ÑÛ¾¦¡±µÄÑù±¾¼´Îª¿ªÔ´ÏîÄ¿MSC_DropperÌìÉú£©£¬£¬ÕâÀàÑù±¾¿ÉÄÜÊDz¿·Ö¹¥»÷ÕßÕýÔÚÆð¾¢µØ¾ÙÐÐÊÖÒÕ×¼±¸ºÍÃâɱ²âÊÔ¡£¡£Í¬Ê±£¬£¬Ò»Ð©ÕæÊµµÄ¹¥»÷Ô˶¯Ò²Ô½À´Ô½ÆµÈԵطºÆð£¬£¬ÔÚÏÖʵ¹¥»÷ÖÐÑù±¾Í¨³£»£»£»£»£»á°Ñͼ±êαװ³ÉWORD¡¢PDF¡¢MP4µÈÖÖÖÖ³£¼ûµÄÎļþÃûÌÃÓÃÒÔÒÉ»óÊܺ¦Ä¿µÄ£¬£¬ÏÂͼÊDz¿·ÖÑù±¾¼°Í¼±êʾÀý¡£¡£

ͼ2 ²¶»ñMSCÑù±¾Ê¾Àý
´ÓÖÐÎÒÃÇ·¢Ã÷ÁËÊýÆðÕë¶ÔÈ«Çò¶à¸ö¹ú¼ÒºÍµØÇøµÄ¹¥»÷Ô˶¯£¬£¬Ä¿µÄÖ÷Òª°üÀ¨Öйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȣ¬£¬¹¥»÷µÄÄ¿µÄÐÐÒµÔòÉæ¼°Õþ¸®¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£¡£ÆäÖУ¬£¬Õë¶ÔÖйúµÄAPT¹¥»÷Ô˶¯ÔÚ½üÆÚ×îÏÈÏÔ×ÅÔö¶à¡£¡£ÔÚ7Ô³õÆÚ£¬£¬Óйع¥»÷Ö÷ÒªÒÔ¡°Ò×·ÒëÖúÊÖ¡±¡¢¡±¶¶Òôǧ·ÛÆóÒµºÅ¡±¡¢¡°½ÌÓýÐÐÒµÊý¾Ý¡±µÈΪÓÕ¶üµÄºÚ²ú×éÖ¯¹¥»÷ΪÖ÷¡£¡£¶øÔÚ8ÔÂÖ®ºó£¬£¬×îÏÈÂ½Ðø·ºÆðÁ˶àÆðÒÔÕþÖÎÒéÌ⡢ר¼ÒÔ¼Çë¡¢¾Û»áÈճ̡¢Í¶Ëß½¨Òé¡¢¾Ù±¨ÖÊÁϵÈÕë¶ÔÕþ¸®×éÖ¯»ò¿ÆÑв¿·ÖµÄÕë¶ÔÐÔ¹¥»÷£¬£¬ÐèÒªÒýÆð¸ß¶ÈСÐÄ£¬£¬²¿·ÖÓÕ¶üÎĵµÈçÏÂËùʾ¡£¡£

ͼ3 Ö÷ÌâΪ¡°×¨¼ÒÔ¼Ç뺯¡±ÀàµÄÓÕ¶üÎĵµ

ͼ4 Ö÷ÌâΪ¡°Õþ²ßÖÆ¶ÈÑо¿¡±ÀàµÄÓÕ¶üÎĵµ
ͼ5 Ö÷ÌâΪ¡°****ÍøÂç´ó»á¡±µÄÓÕ¶üÎĵµ
ͼ6 Õë¶ÔË®ÀûÊðµÄÓÕ¶üÎĵµ
³ýÁËÕë¶ÔÖйúÒÔÍ⣬£¬º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȶà¹úÒ²½ÓÁ¬ÔâÓöµ½Ê¹ÓÃMSCÎļþµÄ¹¥»÷Ô˶¯£¬£¬ÆäÖÐÓÈÒÔº«¹úÔâÊܵĹ¥»÷×î¶à£¬£¬Õâ¿ÉÄÜÓëkimsuky×éÖ¯µÄ¹¥»÷Ä¿µÄÇãÏòÓйأ¬£¬²¿·Ö¹¥»÷Ô˶¯ÓÕ¶üÈçÏÂËùʾ¡£¡£

ͼ7 Õë¶Ôº«¹úµÄÓÕ¶üÎĵµ

ͼ8 Õë¶ÔÔ½ÄÏʯÓ͹«Ë¾µÄÓÕ¶üÎĵµ
ÔÚÕë¶ÔÕâÅúÑù±¾¾ÙÐÐÉîÈëÆÊÎöºó£¬£¬ÎÒÃÇ·¢Ã÷Á˹¥»÷ÕßʹÓõĶà¸ö»ù´¡ÉèÊ©£¬£¬°üÀ¨¶à½×¶ÎÏÂÔØÐ§ÀÍÆ÷ºÍC2ЧÀÍÆ÷µÈ£¬£¬ÆäÖд󲿷ֶ¼½ÓÄÉÁËÔÆÐ§ÀÍÀ´×ÌÈÅËÝÔ´×·×Ù£¬£¬ÆäÖÐһЩЧÀÍÆ÷¹éÊôÓÚÃÀ¹ú¡¢ÈÕ±¾¡¢Èðµä¡¢·¨¹ú¡¢ÐÂ¼ÓÆÂµÈ¹ú¼Ò¡£¡£²¿·ÖÑù±¾¼°C2ЧÀÍÆ÷ÈçÏÂËùʾ¡£¡£
±í1 ¶ñÒâЧÀÍÆ÷µØµã
ͬʱ£¬£¬ÎÒÃÇÒ²²¶»ñµ½Á˲¿·ÖÑù±¾µÄͶµÝURLµØµãÈçϱíËùʾ¡£¡£
Èý¡¢MSCÎļþʹÓÃÊÖÒÕÔÀíÆÊÎö
MSC(Microsoft Snap-In Control)Îļþ£¬£¬ÊÇ΢ÈíÖÎÀí¿ØÖÆÌ¨(MMC)ÓÃÀ´Ìí¼Ó/ɾ³ýµÄǶÈëʽÖÎÀíµ¥Î»Îļþ, ÖÎÀíԱͨ¹ý½¨Éè¿ØÖÆÌ¨¿ÉÒÔÖÎÀíÅÌËã»úµÄÖÖÖÖÉèÖ㬣¬Ìí¼ÓÖÖÖÖ¹¦Ð§ÈçÓû§ÕË»§ÖÎÀí¡¢ÏµÍ³Ð§ÀÍ¡¢×°±¸Çý¶¯³ÌÐòµÈ£¬£¬È»ºó¿ÉÒÔ½«ÕâЩÖÎÀíµ¥Î»µÄ×Ô½ç˵ÉèÖÃÒÔXMLµÄÐÎʽÉúÑĵ½´ÅÅÌÉÏ£¬£¬¼´MSCÃûÌᣡ£WindowsÖг£¼ûµÄ×°±¸ÖÎÀíÆ÷¡¢´ÅÅÌÖÎÀíÆ÷¡¢×éÕ½ÂÔÖÎÀíÆ÷µÈ¶¼ÊÇMSCÃûÌÃÎļþ¡£¡£ÈçÏÂͼÊÇ×Ô½ç˵MSCÎļþµÄÖÎÀíµ¥Î»Ê¹Ãü°å½çÃæ£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý±à³ÌµÄ·½·¨ÓëMMC¾ÙÐн»»¥£¬£¬´Ó¶ø½á¹¹×Ô½ç˵µÄ½çÃæºÍÄÚÈÝ¡£¡£
ͼ9 MSCÎļþÖÎÀíµ¥Î»Ê¹Ãü°å
ͼ10 MSCÎļþÊÖÒÕʹÓÃÁ÷³Ìͼ
ͼ11 ʹÓ÷½·¨Ò»
ͼ12 ¿ØÖÆÌ¨Ê¹Ãü°åÖ´ÐÐí§ÒâÏÂÁîʾÀý

ͼ13 ʹÃü°åÖ´ÐÐí§ÒâÏÂÁîXML
½«ActiveX¹¤¾ß¼ÓÔØµ½¡°ActiveX¿Ø¼þ¡±ÖÎÀíµ¥Î»ÖС£¡£
½«HTMLÎļþ¼ÓÔØµ½¡°Á´½Óµ½WebµØµã¡±ÖÎÀíµ¥Î»ÖС£¡£
ÔÚHTMLÎļþÖУ¬£¬Ê¹ÓÃJavaScriptÓë¼ÓÔØµÄActiveX¹¤¾ß¾ÙÐн»»¥¡£¡£²¢Í¨¹ý MSXMLÒªÁ죬£¬´¥·¢XSLת»»À´Ö´ÐÐJScript´úÂë¡£¡£
×îºó´ÓJScript´úÂëÖÐŲÓÃϵͳº¯Êý£¬£¬»òÕßͨ¹ý DotNetToJScript Ö´ÐÐ.NET´úÂë¡£¡£
Ê×ÏÈ£¬£¬ÔÚMMC³ÌÐòÖУ¬£¬¹¥»÷Õß¿ÉÒÔ×Ô½ç˵²åÈëActiveX¿Ø¼þ¡£¡£Í¨¹ýÎļþ±à¼Æ÷·¿ª½¨ÉèµÄMSCÎļþʱ£¬£¬¿ÉÒÔ¿´µ½½¨ÉèµÄActiveX¿Ø¼þ´æ´¢ÔÚXMLµÄStringTableÖС£¡£
ͼ14 ²åÈëActiveX¿Ø¼þ¹¤¾ß
µ«ÈôÊÇÏëÀֳɼÓÔØ¹¤¾ß£¬£¬¾ÍÒªÈÆ¹ýActiveX ¿Ø¼þµÄÇå¾²ÖÒÑÔ¡£¡£¹¥»÷Õß½ÓÄÉÁËÒ»ÖÖÇÉÃîµÄÒªÁ죬£¬Í¨¹ýMicrosoft Internet Explorerä¯ÀÀÆ÷×é¼þ»á¼ûexternal ¹¤¾ß£¬£¬´Ó¶øÓëMMC¿ØÖÆÌ¨µÄÆäËûÔªËØ¾ÙÐн»»¥£¬£¬ÕâÊÇ΢Èí¹Ù·½Ö§³ÖµÄÒ»ÖÖ·½·¨¡£¡£ÈçÏÂͼÖУ¬£¬scopeNamespaceºÍdocObject¼´ÊÇͨ¹ýexternal.Document»ñÈ¡ÏÖÓй¤¾ß£¬£¬¶ø·Ç½¨ÉèеÄActiveX¹¤¾ß£¬£¬½ø¶øÈƹýÁËÖ±½Ó½¨ÉèActiveX¿Ø¼þʱµÄÇå¾²ÏÞÖÆ¡£¡£
ͼ15 GrimResourceÊÖÒÕʹÓôúÂë
XSLTÊÇÒ»ÖÖÓÃÓÚ½«XMLÎĵµ×ª»»ÎªÆäËûÎĵµÃûÌõÄÓïÑÔ£¬£¬XSLTÑùʽ±í£¨XSL£©Ôò½ç˵ÁËÔõÑù½«Ò»¸öXMLÎĵµ×ª»»ÎªÆäËûÐÎʽ¡£¡£Î¢ÈíÖ§³ÖMSXML XSLTʹÓÃ
ͼ16 ¾ç±¾ÖеÄ
ËÄ¡¢°¸ÀýÆÊÎö
bevictorΰµÂADLab½ÓÁ¬²¶»ñµ½Á˶àÆðʹÓÃMSCÎļþÕë¶ÔÈ«ÇòÄ¿µÄµÄ¹¥»÷Ô˶¯¡£¡£ÆäÖÐÒÑ·¢Ã÷Õë¶ÔÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¼ÒµÄÕþ¸®»ú¹¹ºÍÆóÒµµÄ¹¥»÷£¬£¬Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓÕýÔÚʹÓÃÏà¹ØÊÖÒÕÔÚÈ«Çò¹æÄ£ÄÚ¾ÙÐÐÍøÂç¹¥»÷£¬£¬°üÀ¨Kimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£¡£ÔÚÖî¶àµÄ¹¥»÷°¸ÀýÖУ¬£¬ÎÒÃÇѡȡÁËÔÚÊÖÒÕ²ãÃæ½ÏÓдú±íÐÔÇÒÏà¶ÔÃô¸ÐµÄÁ½À๥»÷Ñù±¾×÷Ϊ´Ë´ÎµÄÆÊÎö°¸Àý£¬£¬Ê¹ÓÃGrimResourceÊÖÒÕÕë¶ÔÖйúµÄ¹¥»÷Ô˶¯£¬£¬ÒÔ¼°Kimsuky×é֯ʹÓÃMMC¿ØÖÆÌ¨Ê¹Ãü°åÕë¶Ôº«¹úµÄ×îй¥»÷Ô˶¯¡£¡£ÏÂÃæÎÒÃǽ«¶ÔѡȡµÄÁ½¸ö°¸Àý¾ÙÐÐÉîÈëµÄÆÊÎö¡£¡£
4.1 ÒÔÕþÖλ°ÌâΪÓÕ¶üÕë¶ÔÖйúµÄ¹¥»÷Ô˶¯
´Ë°¸ÀýʹÓõÄÊÇGrimResourceÊÖÒÕ£¬£¬µ±Êܺ¦Õßµã»÷ÔËÐÐmscÎļþʱ£¬£¬mmc.exe»áÖ´ÐÐÑù±¾ÖеÄjs´úÂ룬£¬¼Ì¶øÖ´ÐÐǶÈëÔÚxmlÖеÄVBScript´úÂë¡£¡£ÆäÖУ¬£¬ÒýÖÂVBA´úÂëµÄÖ´ÐеÄÒªº¦µãÊÇtransforNode(xsl)ÒªÁìµÄŲÓᣡ£
ͼ17 ÒýÖÂVBA´úÂëÖ´ÐеÄÒªº¦µã
transforNodeÒªÁì³£ÓÃÓÚ½«Ò»¸öXMLÎĵµÍ¨¹ýXSLTÑùʽ±í£¨×÷Ϊ²ÎÊý£©×ª»»ÎªÆäËûÎĵµÃûÌᣡ£ÈôÊÇXSLTÑùʽ±íÖк¬ÓÐ
ͼ18 XSLTÑùʽ±íÄÚÈÝ
±»Ö´ÐеÄVBScript´úÂëͨ¹ý×Ô½ç˵±àÂëÏ¢ÕùÂë¡¢×Ö·û´®Æ´½Ó¡¢ÌØÊâ×Ö·û»ìÏý±àÂëµÈ»ìÏýÊÖÒÕ£¬£¬Äܹ»ÓÐÓõØÒþ²ØÆäÕæÊµÂß¼ºÍ¶ñÒâÐÐΪ£¬£¬Í¬Ê±ÔöÌíÁËÆÊÎöÖ°Ô±¾ÙÐÐÄæÏòÆÊÎöµÄʱ¼ä±¾Ç®¡£¡£ÏÂͼչʾÁËÔÚÊ״νâÂëÖ®ºóµÄ²¿·Ö´úÂë¿é£¬£¬Äܹ»¿´µ½´úÂëÖÐÒÀÈ»±£´æ×ÅÆäËû»ìÏý¡£¡£

ͼ19 »ìÏýµÄVBScript´úÂë
ÎÒÃǼÌÐø¶Ô´úÂë¾ÙÐÐÈ¥»ìÏýÒÔ¼°º¯ÊýÖØÃüÃû´¦Öóͷ£ºó£¬£¬¿ÉÒÔ¿´µ½¾ç±¾ÏÈÊÇÉèÖÃÎļþ·¾¶ºÍĿ¼½á¹¹£¬£¬ÔÙ´ÓXML½á¹¹ÖÐÌáÈ¡Êý¾Ý¾ÙÐÐbase64½âÂë²¢ÉúÑÄΪָ¶¨Îļþ£¨ÓÕ¶üÎĵµ£©£¬£¬×îºó·¿ª¸ÃÎļþ¡£¡£
ͼ20 ÊÍ·ÅÓÕ¶üÎĵµ
ÔÚ±¾°¸ÀýÖУ¬£¬ÓÃÓÚÒÉ»óÊܺ¦ÕßµÄÊÇÈý¸öαװ³ÉWordµÄÓÕ¶üMSCÎļþ£¬£¬ÏêϸÄÚÈÝÈçÏÂͼËùʾ¡£¡£
ͼ21 ÓÕ¶üÎĵµÊ¾ÀýÒ»
ͼ22 ÓÕ¶üÎĵµÊ¾Àý¶þ

ͼ23 ÓÕ¶üÎĵµÊ¾ÀýÈý
½Ó×ÅÌáȡϢÕùÂëÆäËûbase64Êý¾Ý£¬£¬ÔÙ½«½âÂëºóµÄÊý¾ÝÉúÑÄΪ×îÖÕµÄWarp.exeºÍ7z.dll¿ÉÖ´ÐÐÎļþ¡£¡£Ëæºó½«¡° t 8.8.8.8¡±×÷Ϊ²ÎÊý£¨×Ô¶¯¼ÓÔØÍ¬Ä¿Â¼Ï¡°7z.dll¡±µÄËùÐèÌõ¼þ£©Æô¶¯Warp.exe³ÌÐò¡£¡£
ͼ24 ÌìÉú²¢Ö´ÐÐwarp.exe³ÌÐò
¾Éó²é£¬£¬¡°Warp.exe¡±¾ßÓÐ ¡°Lenovo (Beijing) Co., Ltd.¡±µÄÕýµ±Êý×ÖÊðÃû£¬£¬ÆäÔÎļþÃûΪ¡°7zwrap.exe¡±¡£¡£ÏêϸÐÅÏ¢ÈçÏÂͼËùʾ¡£¡£
ͼ25 ¡°Warp.exe¡±ÏêϸÐÅÏ¢
µ±¶ñÒâ¡°7z.dll¡±Îļþ±»¡°Wrap.exe¡±ÀֳɼÓÔØºó£¬£¬Æä»áÔÚÄÚ´æÖжÔÖ¸¶¨Ãü¾Ý¾ÙÐнâÃÜ¡£¡£¾ÄÚ´æÌØÕ÷ɨÃèºó£¬£¬ÅжÏ×îÖÕ±»¼ÓÔØÖ´ÐеÄÊÇCobaltStrike£¬£¬ÎÒÃÇÌáÈ¡³öµÄCSÉèÖÃÐÅÏ¢ÈçÏÂͼËùʾ¡£¡£
4.2 ÒÔѧÊõÑݽ²ÎªÓÕ¶üÕë¶Ôº«¹úµÄ¹¥»÷Ô˶¯
¸Ã°¸ÀýÊÇKimsuky APTºÚ¿Í×éÖ¯ÔÚ½ñÄêËùÒýÈëµÄÒ»ÖÖÐµĹ¥»÷Õ½ÂÔ£¬£¬¹¥»÷Õßͨ¹ýXMLµÄÉèÖÃÊôÐÔ½«MSC¶ñÒâÎļþµÄͼ±êÉèÖÃΪWordͼ±ê£¬£¬½èÒÔαװ³ÉWORDÎĵµÀ´ÒÉ»óÊܺ¦Õß¡£¡£
ͼ27 αװµÄWordͼ±ê
µ±Êܺ¦Õßµã»÷MSCÎļþʱ£¬£¬Óû§ÕË»§¿ØÖÆ£¨UAC£©»áµ¯³öÇëÇóȨÏÞÑ¡Ôñ£¬£¬ÈôÊÇÑ¡[ÊÇ]£¬£¬Ôò»áͨ¹ýÖ´ÐÐmscÅþÁ¬³ÌÐòmmc.exe£¬£¬Õ¹Ê¾¹¥»÷Õß¶¨ÖƵÄÃûΪ¡°?????.docx¡±µÄMicrosoftÖÎÀí¿ØÖÆÌ¨½çÃæ¡£¡£ÏêϸÈçÏÂͼËùʾ¡£¡£
ͼ28 ¡°?????.docx¡±µÄMicrosoftÖÎÀí¿ØÖÆÌ¨½çÃæ
±í3 ÌØÊâ·ûºÅÄÚÈÝÆÊÎö
ͼ29 º¬ÓÐÌØÊâ·ûºÅµÄcmd²ÎÊýÏÂÁîÐÐÄÚÈÝ
ͨ¹ý¸Ã·ûºÅËù¶ÔÓ¦µÄÆÊÎö¾ÙÐÐÌæ»»ºó£¬£¬»ñµÃÁËÈçÏÂͼËùʾµÄÅú´¦Öóͷ£ÏÂÁî¡£¡£¸Ã´®Åú´¦Öóͷ£ÏÂÁîÔòÊÇÖ´ÐÐMSCºóµÄÖÎÀí¿ØÖÆÌ¨¸ùʹÃü´°¿ÚµÄÏÂÁîÐвÎÊý¡£¡£¸Ã¶ÎÏÂÁîµÄÖ÷Òª¹¦Ð§ÊÇ´ÓÖ¸¶¨URLÏÂÔØÃûΪ¡°Grieco Kavanagh Passive Supporters.docx¡±µÄÓÃÓÚαװµÄÓÕ¶üÎĵµ£¬£¬ÒÔ¼°ºóÐø½×¶ÎµÄ¡°pest.exe¡±ºÍ¡°pest.exe.manifest¡±Îļþ¡£¡£³ý´ËÖ®Í⣬£¬Æä»¹»á½¨ÉèÒ»¸öÃûΪ¡°TemporaryClearStatesesf¡±µÄÍýÏëʹÃü£¬£¬Ã¿58·ÖÖÓÖ´ÐÐÒ»´Î¡°%appdata%\pest.exe¡±Îļþ¡£¡£ÄÚÈÝÈçÏÂͼËùʾ¡£¡£
ͼ30 cmd²ÎÊýÏÂÁîÐÐÄÚÈÝ
Éó²é¡°pest.exe¡±³ÌÐòÏêϸÐÅÏ¢£¬£¬·¢Ã÷¸Ã³ÌÐòµÄÊý×ÖÊðÃûÃû³ÆÎª¡°Adersoft¡±£¬£¬ÔʼÎļþÃûΪ¡°launcher.exe¡±¡£¡£¸Ã³ÌÐòΪVBSEdit£¨ÓÉAdersoft¹«Ë¾³öÆ·µÄÒ»¿îСÇɶøÇ¿º·µÄVBScript±à¼¹¤¾ß£©¾ç±¾Æô¶¯Æ÷¡£¡£
ͼ31 ¡°pest.exe¡±³ÌÐòÏêϸÐÅÏ¢
ͼ32 ¡°pest.exe¡±³ÌÐòÖ´Ðб¨´í
¡°pest.exe.manifest¡±ÎļþÄÚÈÝÊÇXMLÃûÌ㬣¬¶ñÒâ´úÂë°üÀ¨ÔÚ¡°¡±±êǩ֮¼ä¡£¡£¸ÃÎļþµÄÖ÷Òª¹¦Ð§ÊÇÓÉÒ»¶Î¾base64±àÂëµÄVBScript´úÂëÀ´ÊµÏÖ¡£¡£²¿·Ö´úÂëÈçÏÂͼËùʾ¡£¡£
ͼ33 base64±àÂëµÄVBScript´úÂë
ͼ34 batÎļþ²Ù×÷´úÂë
ÈôÊÇ¡°sim.sid¡±Îļþ²»±£´æ£¬£¬ÔòÏòÖ¸¶¨µÄGoogle driveÁ´½Ó·¢ËÍHTTPÇëÇ󣬣¬²¢»ñÈ¡ÏìÓ¦ÄÚÈÝ¡£¡£
ͼ35 ÏòGoogle drive¹²ÏíÁ´½Ó·¢ËÍÇëÇó
ÀֳɻñÈ¡ºó£¬£¬´ÓÎüÊÕµ½µÄÄÚÈÝÖÐÌáÈ¡base64±àÂëµÄÊý¾Ý£¨ÔÚ"pprbstart--"ºÍ"--pprbend"±êǩ֮¼ä£©£¬£¬×îºóÌæ»»ÌØÊâ×Ö·û²¢½«½âÂëºóµÄÊý¾ÝдÈëÖÁ¡±%appdata%\Microsoft\sif.bat"¡£¡£
ͼ36 ÆÊÎöÏìÓ¦ÄÚÈÝ
Îå¡¢×Ü ½á
±¾ÎÄÕë¶ÔÎÒÃǽüÆÚ²¶»ñµ½µÄһϵÁлùÓÚÐÂÐÍMSCÎļþµÄ¹¥»÷Ô˶¯¾ÙÐÐÁËÆÊÎö£¬£¬ÖصãÏÈÈÝÁËÏÖÔÚMSCÎļþÔÚҰʹÓõÄÁ½ÖÖʹÓÃÊÖÒÕÔÀí£¬£¬Åû¶½üÆÚʹÓÃMSCÎļþµÄ¶àÆðÃô¸Ð¹¥»÷Ô˶¯£¬£¬²¢Õë¶ÔÆäÖеÄÁ½¸ö°¸Àý¾ÙÐÐÁËÉîÈëÆÊÎö¡£¡£´Ó½ü¼¸¸öÔÂMSCÎļþÏà¹Ø¹¥»÷µÄ»îÔ¾Ç÷ÊÆÀ´¿´£¬£¬¹¥»÷Ô˶¯Éæ¼°µ½Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²ú×éÖ¯ÒÔ¼°ºì¶ÓµÈ£¬£¬ÓÈÆäÊǽüÆÚÕë¶ÔÕþÖΡ¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÁìÓòµÄAPT¹¥»÷×îÏÈÏÔÖøÔö¶à£¬£¬ÐèÒªÒýÆðÏà¹ØÕþÆóºÍСÎÒ˽¼ÒÓû§µÄÖØµã¹Ø×¢¡£¡£
bevictorΰµÂÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨ÉèÓÚ1999Ä꣬£¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£¡£×èÖ¹ÏÖÔÚ£¬£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Çå¾²Îó²î5000Óà¸ö£¬£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç»ù´¡Çå¾²Ñо¿¡¢Êý¾ÝÇå¾²Ñо¿¡¢5GÇå¾²Ñо¿¡¢È˹¤ÖÇÄÜÇå¾²Ñо¿¡¢Òƶ¯Çå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢³µÁªÍøÇå¾²Ñо¿¡¢¹¤¿ØÇå¾²Ñо¿¡¢ÐÅ´´Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡¢ÎÞÏßÇå¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·Àϵͳ½¨Éè¡£¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇ徲ЧÀ͵ȡ£¡£