GA»Æ½ð¼×ADLab£ºMSCÎļþµÄÔÚÒ°ÀûÓÃÇé¿öÓëºÚ¿Í¹¥»÷»î¶¯·ÖÎö

°ä²¼¹¦·ò 2024-09-14

Ò»¡¢±³ ¾°


2024Äê6ÔÂ22ÈÕ£¬Ò»¸öÀûÓÃMSCÌåʽµÄÐÂÐ͹¥»÷¼¼ÊõµÄ¶ñÒâÑù±¾³Ê´Ë¿ÌVTƽ̨ÉÏ£¬´ËʱÀûÓÃÕâÖÖ¼¼ÊõµÄ¶ñÒâÑù±¾ÔÚVTÉϾùÏÔʾΪÁã¼ì²âÂÊ¡£ÕâÖÖ¼¼Êõ±»Elastic×êÑÐÍŶӶ¨ÃûΪ¡°GrimResource¡±£¬Æäͨ¹ý¶ñÒâ¹¹½¨µÄMSCÎļþÔÚMicrosoftÖÎÀí½ÚÔį̀ÖÐÖ´ÐÐËÁÒâ´úÂë¡£GA»Æ½ð¼×ADLabÔÚ¶ûºóµÄÁ½¸öÔ¹¦·òÖУ¬³ÖÐø¹Ø×¢Ê¹ÓÃÕâÖÖÀûÓÃÊÖ·¨µÄ¹¥»÷£¬Í¨¹ý¼à²âµÄÁ˾ַÖÎö·¢ÏÖ£º×Ըü¼Êõ¹«¿ªºó£¬Í¬À๥»÷Ѹ¿ìÔö³¤£¬µ½Ä¿Ç°ÎªÖ¹¿ÉÄܼà²âµ½µÄÓÐЧ¹¥»÷¼°Æä¹¥»÷Ñù±¾ÓÐ100¶àÆð¡£²¢ÇÒÓÐÔ½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓÀûÓøü¼ÊõÔÚÈ«ÇòÁìÓòÄÚ½øÐÐÍøÂç¹¥»÷£¬Ô̺¬Kimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£Ä¿Ç°ÒÑ·¢ÏÖµÄÖ¸±êÓÐÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¶ÈÈ·µ±¾Ö»ú¹¹ºÍÆóÒµ£¬Éæ¼°µ±¾Ö¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£


ÕâЩ¹¥»÷ÆÕ±éͨ¹ýMSCÎļþ×÷Ϊ¶ñÒâpayload£¬Í¨¹ý¸÷À෽ʽ·¢Ë͸øÖ¸±ê²¢ÓÕʹָ±ê´ò¿ª¸ÃÎļþ¡£ÓÉÓÚMSCÌåʽµÄ¹¥»÷ÎļþÊÇÒ»ÖÖÏà¶Ôº±¼ûµÄÎļþÀàÐÍ£¨ÎÞÊý±»¹¥»÷Õß¿ÉÄÜÊìϤ.exe¡¢.docµÈ³£¼ûµÄ¿ÉÖ´ÐÐÎļþÀ©´óÃû£¬µ«²¢²»Ïàʶ.mscÎļþ£¬Òò¶ø¿ÉÄÜÔÚÏÖʵ¹¥»÷ÖвúÉúÆæÐ§£©£¬²¢ÇÒĿǰ·À»¤ÏµÍ³Ò²ÏÊÓжԴËÀàÎļþµÄÕë¶ÔÐÔ¼ì²â£¬ËùÒÔºÚ¿ÍÀûÓøü¼ÊõʵÏÖ¹¥»÷µÄ³É¹¦Âʸߣ¬±»¼ì²âºÍ·¢Ïֵļ¸ÂʵÍ£¬¾ÍĿǰÎÒÃǹ۲쵽¹¥»÷µö¶ü£¬ÓÐÔ̺¬È磺¡°¡¶**ÂÛ̳¡·±íÉóר¼ÒÔ¼Ç뺯ÓëÎÄÕÂÆÀÉ󵥡±¡¢£º¡°ÄäÃûÉó¸åר¼Ò»ØÖ´ (У±í) ¡±¡¢¡°ºÏÓÃÓÚÄϺ£µÄÁ½ÖÖ˾·¨Ôì¶È×êÑÐ (¸å¼þ)¡±¡¢¡°ÃÀ¹úÕ½ÊõÊÕËõ¶ÔÖж«µØÔµÕþÖεÄÓ°Ï족¡¢¡°****ÍøÂç´ó»á¡±µÈ¼«¾ßÒýÓÕÐԵĹ¥»÷£¬Ò»µ©µã»÷ÆäÖеÄMSCÎļþ£¬Æäϵͳ±ã»á±»Ö²ÈëÇÔÃÜľÂí£¬µ¼Ö³ÁÒªÃô¸ÐÊý¾Ý±»ÇÔÈ¡¡£


ͨ¹ýÎÒÃǶԹ¥»÷µÄ×·Òä·¢ÏÖÔçÔÚ2024Äê4Ô£¬Kimusuky APT×éÖ¯¾ÍÆðÍ·ÀûÓÃMSCÎļþÀ´¶ÔÆäÖ¸±êÖ´ÐÐÁË´óÁ¿µÄ¹¥»÷£¬µ«ÆäÀûÓÃÊÖ·¨ÓëGrimResource¼¼ÊõÓÐËù·ÖÆç¡£ÓÉÓÚMSCÑù±¾µÄ¹«¿ªÀûÓúͼ¼ÊõÑݱäÉд¦ÓÚ·¢Õ¹³õÆÚ£¬Òò¶øÓйع¥»÷Ñù±¾ºÍÊÖ·¨µÄ±ä¶¯ÖµµÃÒýÆð³ÖÐø¹Ø×¢¡£´Ë±í£¬OutflankÓÚ8ÔÂ13ÈÕ·¢ÎijÆGrimResource¼¼ÊõÔ´ÓÚÆä±øÆ÷¿â£¬ÆäÔÚ¹¥·ÀÑÝÁ·Öб»·ÀÊØ·½ÉÏ´«µ½¹«¹²É³Ïä¡£


MSC(Microsoft Snap-In Control)Îļþ£¬ÊÇ΢ÈíÖÎÀí½ÚÔį̀(MMC)ÓÃÀ´Ôö³¤/ɾ³ýµÄǶÈëʽÖÎÀíµ¥ÔªÎļþ, ÓÉÓÚ´ËÀàÎļþ¿ÉÄÜÖ´ÐкÅÁîºÍ¾ç±¾£¬Òò¶ø¹¥»÷Õß¿ÉÄܽèÖúMSCÎļþÔÚÖ¸±êϵͳÉÏÖ´Ðи÷Àà¶ñÒ⹤×÷¡£×Ô΢ÈíĬÈÏÏÞ¶ÈÀ´×Ô»¥ÁªÍøµÄOfficeºêÎĵµºó£¬LNK¡¢MSI¡¢ISOµÈÆäËûÀàÐ͵ĶñÒâÀûÓÃÊýÁ¿¾ÍÆðÍ·´ó·ùÔö³¤£¬Õâ´ÎгöÏÖµÄGrimResource¼¼ÊõÒ²Ìì¾­µØÒå³ÉΪÁ˺ڿÍÃǵÄг裬ÓйØMSCÑù±¾ÊýÁ¿×Ô4ÔÂÒÔÀ´³Ê¸ß¿ìÔö³¤Ì¬ÊÆ¡£Òò¶ø£¬GA»Æ½ð¼×ADLabÕë¶Ô½üÆÚ²¶»ñµ½µÄMSCÑù±¾½øÐÐÁËÉî¿ÌµÄ·ÖÎö£¬±¾ÎĽ«ÖØÒª½éÉÜĿǰMSCÎļþÔÚÒ°ÀûÓü¼ÊõµÄÓйصÀÀí£¬Åû¶½üÆÚÀûÓÃMSCÎļþµÄ¶àÆð¹¥»÷»î¶¯£¬²¢³ÁµãÕë¶ÔÆäÖеÄÁ½¸ö°¸Àý½øÐÐÉî¿Ì·ÖÎö¡£

¶þ¡¢½üÆÚÔÚÒ°¹¥»÷»î¶¯·ÖÎö



ͨ¹ý¶ÔÄ¿Ç°ÍøÂçµ½µÄ100Óà¸öMSCÑù±¾µÄ·ÖÎö£¬ÎÒÃÇ·¢ÏÖ×îÔçµÄÀûÓÃÑù±¾³Ê´Ë¿Ì2024Äê4ÔÂ5ÈÕ£¬ËùÓÐÑù±¾ÖУ¬³Ê´Ë¿Ì4-5ÔµĹ¥»÷Ñù±¾ÖØÒªÊôÓÚKimusuky×éÖ¯¡£6Ôºó£¬Ëæ×ÅGrimResource¼¼ÊõµÄ¹«¿ª£¬MSCÌåʽµÄÑù±¾ÊýÁ¿ÒÔÔÂΪµ¥Ôª³ÊÏÔÖøµÄµÝÔö¹ØÏµ£¬Åú×¢ºÚ¿ÍÃÇÕý»ý¼«ÀûÓúͲâÊÔÓйع¥»÷¼¼Êõ²¢×ª»¯ÎªÏÖʵ¹¥»÷¡£ÒÔÏÂÊǽü¼¸¸öÔ²¶»ñµ½µÄMSCÌåʽµÄ¹¥»÷Ñù±¾ÊýÁ¿Í¼¡£


ͼƬ1.png

ͼ1 MSC¹¥»÷Ñù±¾ÊýÁ¿Í³¼ÆÍ¼£¨µ¥Ôª:Ô£©


ÔÚÕâÅú¹¥»÷Ñù±¾ÖУ¬ÆäÖÐһЩÊÇ»ùÓÚ¿ªÔ´ÏîÄ¿±àÒëµÄÑù±¾£¨ÈçÏÂͼÖÐͼ±êΪ¡°ÑÛ¾¦¡±µÄÑù±¾¼´Îª¿ªÔ´ÏîÄ¿MSC_DropperÌìÉú£©£¬ÕâÀàÑù±¾¿ÉÄÜÊDz¿ÃŹ¥»÷ÕßÔÚ»ý¼«µØ½øÐм¼Êõ³ï±¸ºÍÃâɱ²âÊÔ¡£Í¬Ê±£¬Ò»Ð©ÕæÊµµÄ¹¥»÷»î¶¯Ò²Ô½À´Ô½ÆµÈԵسöÏÖ£¬ÔÚÏÖʵ¹¥»÷ÖÐÑù±¾Í¨³£»á°Ñͼ±ê¼Ù×°³ÉWORD¡¢PDF¡¢MP4µÈ¸÷Àà³£¼ûµÄÎļþÌåʽÓÃÒԹƻóÊܺ¦Ö¸±ê£¬ÏÂͼÊDz¿ÃÅÑù±¾¼°Í¼±êʾÀý¡£


ͼƬ2.png

ͼ2 ²¶»ñMSCÑù±¾Ê¾Àý


´ÓÖÐÎÒÃÇ·¢ÏÖÁËÊýÆðÕë¶ÔÈ«Çò¶à¸ö¹ú¶ÈºÍµØÓòµÄ¹¥»÷»î¶¯£¬Ö¸±êÖØÒªÔ̺¬Öйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢ÃɹŵÈ£¬¹¥»÷µÄÖ¸±êÐÐÒµÔòÉæ¼°µ±¾Ö¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£ÆäÖУ¬Õë¶ÔÖйúµÄAPT¹¥»÷»î¶¯ÔÚ½üÆÚÆðÍ·ÏÔÖøÔö¶à¡£ÔÚ7Ô³õÆÚ£¬Óйع¥»÷ÖØÒªÒÔ¡°Ò×·­Ò븱ÊÖ¡±¡¢¡±¶¶Òôǧ·ÛÆóÒµºÅ¡±¡¢¡°½ÌÓýÐÐÒµÊý¾Ý¡±µÈΪµö¶üµÄºÚ²ú×éÖ¯¹¥»÷ΪÖ÷¡£¶øÔÚ8ÔÂÖ®ºó£¬ÆðÍ·Â½Ðø³öÏÖÁ˶àÆðÒÔÕþÖÎÒéÌ⡢ר¼ÒÔ¼Çë¡¢»áÒéÈճ̡¢Í¶Ëß½¨Òé¡¢¾Ù±¨×ÊÁϵÈÕë¶Ôµ±¾Ö×éÖ¯»ò¿ÆÑв¿ÃŵÄÕë¶ÔÐÔ¹¥»÷£¬±ØÒªÒýÆð¸ß¶È¾¯Ì裬²¿Ãŵö¶üÎĵµÈçÏÂËùʾ¡£


ͼƬ3.png

ͼ3 Ö÷ÌâΪ¡°×¨¼ÒÔ¼Ç뺯¡±ÀàµÄµö¶üÎĵµ


ͼƬ4.png

ͼ4 Ö÷ÌâΪ¡°Õþ²ßÔì¶È×êÑÓ×±ÀàµÄµö¶üÎĵµ


ͼƬ5.png

ͼ5 Ö÷ÌâΪ¡°****ÍøÂç´ó»á¡±µÄµö¶üÎĵµ


ͼƬ6.png

ͼ6 Õë¶ÔË®ÀûÊðµÄµö¶üÎĵµ


³ýÁËÕë¶ÔÖйúÒÔ±í£¬º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȶà¹úÒ²½ÓÁ¬Ôâ·êµ½ÀûÓÃMSCÎļþµÄ¹¥»÷»î¶¯£¬ÆäÖÐÓÈÒÔº«¹úÔâ·êµÄ¹¥»÷×î¶à£¬Õâ¿ÉÄÜÓëkimsuky×éÖ¯µÄ¹¥»÷Ö¸±êÆ«²îÓйØ£¬²¿ÃŹ¥»÷»î¶¯µö¶üÈçÏÂËùʾ¡£


ͼƬ7.png

ͼ7 Õë¶Ôº«¹úµÄµö¶üÎĵµ


ͼƬ8.png

ͼ8 Õë¶ÔÔ½ÄÏʯÓ͹«Ë¾µÄµö¶üÎĵµ


ÔÚÕë¶ÔÕâÅúÑù±¾½øÐÐÉî¿Ì·ÖÎöºó£¬ÎÒÃÇ·¢ÏÖÁ˹¥»÷ÕßʹÓõĶà¸ö»ù´¡ÉèÊ©£¬Ô̺¬¶à½×¶ÎÏÂÔØ·þÎñÆ÷ºÍC2·þÎñÆ÷µÈ£¬ÆäÖдó²¿ÃŶ¼Ñ¡È¡ÁËÔÆ·þÎñÀ´×ÌÈÅËÝÔ´×·×Ù£¬ÆäÖÐһЩ·þÎñÆ÷¹éÊôÓÚÃÀ¹ú¡¢ÈÕ±¾¡¢Èðµä¡¢·¨¹ú¡¢ÐÂ¼ÓÆÂµÈ¹ú¶È¡£²¿ÃÅÑù±¾¼°C2·þÎñÆ÷ÈçÏÂËùʾ¡£


±í1 ¶ñÒâ·þÎñÆ÷µØÖ·

±í1-1.png

±í1-2.png


ͬʱ£¬ÎÒÃÇÒ²²¶»ñµ½Á˲¿ÃÅÑù±¾µÄͶµÝURLµØÖ·ÈçϱíËùʾ¡£


±í2 Ñù±¾Í¶µÝURL

±í2-1.png

±í2-2.png


Èý¡¢MSCÎļþÀûÓü¼ÊõµÀÀí·ÖÎö


MSC(Microsoft Snap-In Control)Îļþ£¬ÊÇ΢ÈíÖÎÀí½ÚÔį̀(MMC)ÓÃÀ´Ôö³¤/ɾ³ýµÄǶÈëʽÖÎÀíµ¥ÔªÎļþ, ÖÎÀíԱͨ¹ý´´½¨½ÚÔį̀Äܹ»ÖÎÀíÍÆËã»úµÄ¸÷ÀàÉèÖã¬Ôö³¤¸÷ÀàÖ°ÄÜÈçÓû§ÕË»§ÖÎÀí¡¢ÏµÍ³·þÎñ¡¢É豸Çý¶¯·¨Ê½µÈ£¬¶øºóÄܹ»½«ÕâЩÖÎÀíµ¥ÔªµÄ×Ô½ç˵ÅäÖÃÒÔXMLµÄ´ó¾Ö±£Áôµ½´ÅÅÌÉÏ£¬¼´MSCÌåʽ¡£WindowsÖг£¼ûµÄÉ豸ÖÎÀíÆ÷¡¢´ÅÅÌÖÎÀíÆ÷¡¢×éÕ½ÊõÖÎÀíÆ÷µÈ¶¼ÊÇMSCÌåʽÎļþ¡£ÈçÏÂͼÊÇ×Ô½ç˵MSCÎļþµÄÖÎÀíµ¥Ôª¹¤×÷°å½çÃæ£¬¹¥»÷ÕßÄܹ»Í¨¹ý±à³ÌµÄ·½Ê½ÓëMMC½øÐн»»¥£¬´Ó¶ø»ú¹Ø×Ô½ç˵µÄ½çÃæºÍÄÚÈÝ¡£


ͼƬ9.png

ͼ9 MSCÎļþÖÎÀíµ¥Ôª¹¤×÷°å


ÎÒÃÇÔÚ½øÒ»²½Õë¶ÔÕâÅúÑù±¾·ÖÎöºó£¬·¢ÏÖĿǰMSCÌåʽÎļþµÄÔÚÒ°ÀûÓ÷½Ê½ÖØÒªÓÐÁ½ÖÖ¡£ÔÚÊܺ¦ÕßĬÈÏ¿ªÆôÓû§ÕË»§½ÚÔ죨UAC£©µÄÇé¿öÏ£¬µÚÒ»ÖÖÀûÓ÷½Ê½±ØÒªÓëÊܺ¦Õß½»»¥Á½´Î£¨ÖØÒªÓÉKimusuky×é֯ʹÓã©£»ÁíÒ»ÖÖÖ»Ðè½»»¥Ò»´Î(GrimResource¼¼Êõ)£¬Óйؼ¼ÊõÀûÓÃÁ÷³ÌͼÈçÏÂËùʾ¡£

ͼƬ10.png

ͼ10 MSCÎļþ¼¼ÊõÀûÓÃÁ÷³Ìͼ


ÀûÓ÷½Ê½Ò»£ºÔÚÊܺ¦Õß´ò¿ªMSCÎļþºó£¬Ê×Ïȵ¯³öUAC½ÚÔìÑ¡ÏÈôÊÇÑ¡ÔñÊÇ£¬Ôò³ÖÐøµ¯³ö¹¥»÷Õß¶¨ÔìµÄMicrosoftÖÎÀí½ÚÔį̀½çÃæÓÕµ¼Ö¸±ê£¬Ò»µ©Êܺ¦Õß³ÖÐøµã»÷open´ò¿ªÎĵµ¼´»áÖÐÕУ¬Ö´ÐÐcmdºÅÁî¡¢powershell¾ç±¾µÈºóÐøÀûÓý׶Ρ£

ͼƬ11.png

ͼ11 ÀûÓ÷½Ê½Ò»


¶ÔÓÚ´ËÀàÑù±¾£¬¹¥»÷Õßͨ¹ý±à×ëMSCÎļþµÄ½çÃæÎ±ÔìUI±í¹Û£¬´Ó¶øÓÕÆ­Êܺ¦Õßµã»÷½ÚÔį̀¹¤×÷°åÉϵÄÁ´½Ó£¬¶ø²»»á²úÉúÒÉ»ó¡£ÕâÖÖÀûÓ÷½Ê½½èÖúÁËMMCÖеĽÚÔį̀¹¤×÷°åÖ´Ðй¥»÷£¬½ÚÔį̀¹¤×÷°åÊÇÔÚMMC1.2ÖÐÒýÈëµÄ£¬¹¥»÷ÕßÄܹ»½èÖú½ÚÔį̀¹¤×÷°åÀ´Ö´Ðи÷À๤×÷£¬ÀýÈç´ò¿ªÊôÐÔÒ³¡¢Ö´Ðв˵¥ºÅÁî¡¢ÔËÐкÅÁîÐкʹò¿ªÍøÒ³µÈ£¬Ä¿Ç°ÖØÒª·¢ÏÖKimsuky×éÖ¯ÔÚ´óÁ¿Ê¹ÓôËÀ๥»÷·½Ê½£¬ÓйØÀûÓÃÑù±¾µÄ×îÔç³öÏÖ¹¦·òÊÇÔÚ½ñÄê4ÔÂ5ÈÕ£¬ÀûÓÃʾÀýÈçÏÂͼËùʾ¡£

ͼƬ12.png

ͼ12 ½ÚÔį̀¹¤×÷°åÖ´ÐÐËÁÒâºÅÁîʾÀý


ͼƬ13.png

ͼ13 ¹¤×÷°åÖ´ÐÐËÁÒâºÅÁîXML


ÀûÓ÷½Ê½¶þ£ºGrimResource¼¼Êõ£¬¸Ã¼¼ÊõÀûÓÃapds.dllÖеÄXSS·ì϶£¬Í¨¹ýMSCÎļþµÄStringTable²¿ÃÅÒýÓÃÒ×Êܹ¥»÷µÄAPDS×ÊÔ´£¬´Ó¶øÊµÏÖǶÈëÔÚMSCÎļþÖеÄJS´úÂëËÁÒâÖ´ÐУ¬×îºóÖ´ÐÐXMLÖеľ籾´úÂë¡£Ïà½ÏÓÚÀûÓ÷½Ê½Ò»£¬ÆäÓµÓÐÖÁÉٵݲȫÖҸ棬ÎÞÒÉ¿ÉÄÜʹµÃ¹¥»÷µÄ³É¹¦ÂÊ´ó´óÌá¸ß¡£Í¬Ê±£¬¶ÔÓںöàΪÁË·½±ã¶øÄ¬ÈÏÈ¡µÞUAC֪ͨµÄÊܺ¦ÕßÀ´Ëµ¸üÊÇÄÜ´ïµ½ÎÞ½»»¥¼´¿ÉÖ´ÐеijÉЧ¡£
¼¼ÊõÀûÓùؼüµã£º


  • ½«ActiveX¶ÔÏó¼ÓÔØµ½¡°ActiveX¿Ø¼þ¡±ÖÎÀíµ¥ÔªÖС£

  • ½«HTMLÎļþ¼ÓÔØµ½¡°Á´½Óµ½WebµØÖ·¡±ÖÎÀíµ¥ÔªÖС£

  • ÔÚHTMLÎļþÖУ¬Ê¹ÓÃJavaScriptÓë¼ÓÔØµÄActiveX¶ÔÏó½øÐн»»¥¡£²¢Í¨¹ý MSXML²½Ö裬´¥·¢XSLת»»À´Ö´ÐÐJScript´úÂë¡£

  • ×îºó´ÓJScript´úÂëÖÐŲÓÃϵͳº¯Êý£¬»òÕßͨ¹ý DotNetToJScript Ö´ÐÐ.NET´úÂë¡£


Ê×ÏÈ£¬ÔÚMMC·¨Ê½ÖУ¬¹¥»÷ÕßÄܹ»×Ô½ç˵²åÈëActiveX¿Ø¼þ¡£Í¨¹ýÎļþ±à×ëÆ÷´ò¿ª´´½¨µÄMSCÎļþʱ£¬Äܹ»¿´µ½´´½¨µÄActiveX¿Ø¼þ´æ´¢ÔÚXMLµÄStringTableÖС£


ͼƬ14.png

ͼ14 ²åÈëActiveX¿Ø¼þ¶ÔÏó


µ«ÈôÊÇÏë³É¹¦¼ÓÔØ¶ÔÏ󣬾ÍÒªÈÆ¹ýActiveX ¿Ø¼þµÄ°²È«ÖҸ档¹¥»÷ÕßѡȡÁËÒ»ÖÖÆæÃîµÄ²½Ö裬ͨ¹ýMicrosoft Internet Explorerä¯ÀÀÆ÷×é¼þ½Ó¼ûexternal ¶ÔÏ󣬴ӶøÓëMMC½ÚÔį̀µÄÆäËûÔªËØ½øÐн»»¥£¬ÕâÊÇ΢Èí¹Ù·½Ö§³ÖµÄÒ»ÖÖ·½Ê½¡£ÈçÏÂͼÖУ¬scopeNamespaceºÍdocObject¼´ÊÇͨ¹ýexternal.Document»ñÈ¡ÏÖÓжÔÏ󣬶ø·Ç´´½¨ÐµÄActiveX¶ÔÏ󣬽ø¶øÈƹýÁËÖ±½Ó´´½¨ActiveX¿Ø¼þʱµÄ°²È«ÏÞ¶È¡£


ͼƬ15.png

ͼ15 GrimResource¼¼ÊõÀûÓôúÂë


ͬʱ£¬¹¥»÷ÕßÀûÓÃÁËapds.dllµÄÒ»¸öXSS·ì϶£¬´Ó¶øÄܹ»Ö´ÐÐConsole RootÖеÄJscript£¬½ø¶øÔÙÖ´ÐÐXMLÖеľ籾¡£ÕâÆäÖл¹Éæ¼°µ½Ò»¸ö¼¼ÇÉ£¬¼´ÀûÓÃMSXML£¨Microsoft.XMLDOM / {2933BF90-7B36-11D2-B20E-00C04F983E60} £©Ö´ÐÐXSLÎļþÖÐǶÈëµÄ¾ç±¾¡£

XSLTÊÇÒ»ÖÖÓÃÓÚ½«XMLÎĵµ×ª»»ÎªÆäËûÎĵµÌåʽµÄ˵»°£¬XSLTÐÎ×´±í£¨XSL£©Ôò½ç˵ÁËÈôºÎ½«Ò»¸öXMLÎĵµ×ª»»ÎªÆäËû´ó¾Ö¡£Î¢ÈíÖ§³ÖMSXML XSLTʹÓÃÔªËØ¼°ÆäÊôÐÔimplements-prefixʵÏÖ²¢À©´óº¯ÊýÒÔÌṩ¾ç±¾¼¶Ö§³Ö¡£Òò¶ø£¬¹¥»÷Õßͨ¹ýMSXMLµÄ·½Ê½¼´¿ÉÖ´ÐÐXSLÎļþÖÐǶÈëµÄ¾ç±¾£¬ÈçŲÓú¯Êý XML.transformNode(xsl)£¬¼´¿ÉÖ´ÐÐǶÈëµÄ¾ç±¾¼°ºóÐøµÄ¶ñÒâÀûÓÃÄ £¿é£¬½âÂë¾ç±¾ÖеıêÇ©ÈçÏÂͼËùʾ¡£


ͼƬ16.png

ͼ16 ¾ç±¾ÖеÄ



ËÄ¡¢°¸Àý·ÖÎö


GA»Æ½ð¼×ADLab½ÓÁ¬²¶»ñµ½Á˶àÆðÀûÓÃMSCÎļþÕë¶ÔÈ«ÇòÖ¸±êµÄ¹¥»÷»î¶¯¡£ÆäÖÐÒÑ·¢ÏÖÕë¶ÔÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¶ÈÈ·µ±¾Ö»ú¹¹ºÍÆóÒµµÄ¹¥»÷£¬Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓÔÚÀûÓÃÓйؼ¼ÊõÔÚÈ«ÇòÁìÓòÄÚ½øÐÐÍøÂç¹¥»÷£¬Ô̺¬Kimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£ÔÚÖî¶àµÄ¹¥»÷°¸ÀýÖУ¬ÎÒÃǰÎÈ¡ÁËÔÚ¼¼Êõ²ãÃæ½ÏÓдú±íÐÔÇÒÏà¶ÔÃô¸ÐµÄÁ½À๥»÷Ñù±¾×÷ΪÕâ´ÎµÄ·ÖÎö°¸Àý£¬ÀûÓÃGrimResource¼¼ÊõÕë¶ÔÖйúµÄ¹¥»÷»î¶¯£¬ÒÔ¼°Kimsuky×éÖ¯ÀûÓÃMMC½ÚÔį̀¹¤×÷°åÕë¶Ôº«¹úµÄ×îй¥»÷»î¶¯¡£ÏÂÃæÎÒÃǽ«¶Ô°ÎÈ¡µÄÁ½¸ö°¸Àý½øÐÐÉî¿ÌµÄ·ÖÎö¡£


4.1 ÒÔÕþÖλ°ÌâΪµö¶üÕë¶ÔÖйúµÄ¹¥»÷»î¶¯


´Ë°¸ÀýÀûÓõÄÊÇGrimResource¼¼Êõ£¬µ±Êܺ¦Õßµã»÷ÔËÐÐmscÎļþʱ£¬mmc.exe»áÖ´ÐÐÑù±¾ÖеÄjs´úÂ룬¼Ì¶øÖ´ÐÐǶÈëÔÚxmlÖеÄVBScript´úÂë¡£ÆäÖУ¬ÒýÖÂVBA´úÂëµÄÖ´ÐеĹؼüµãÊÇtransforNode(xsl)²½ÖèµÄŲÓá£


ͼƬ17.png

ͼ17 ÒýÖÂVBA´úÂëÖ´ÐеĹؼüµã


transforNode²½Öè³£ÓÃÓÚ½«Ò»¸öXMLÎĵµÍ¨¹ýXSLTÐÎ×´±í£¨×÷Ϊ²ÎÊý£©×ª»»ÎªÆäËûÎĵµÌåʽ¡£ÈôÊÇXSLTÐÎ×´±íÖк¬ÓлòÔªËØÊ±£¬ÄÇÃ´ÔªËØÖеľ籾Ôò»áÔÚת»»¹ý³ÌÖб»Ö´ÐС£


ͼƬ18.png

ͼ18 XSLTÐÎ×´±íÄÚÈÝ


±»Ö´ÐеÄVBScript´úÂëͨ¹ý×Ô½ç˵±àÂëºÍ½âÂë¡¢×Ö·û´®Æ´½Ó¡¢ÌØÊâ×Ö·û»ìºÏ±àÂëµÈ»ìºÏ¼¼Êõ£¬¿ÉÄÜÓÐЧµØ°µ²ØÆäÕæÊµÂß¼­ºÍ¶ñÒâÐÐΪ£¬Í¬Ê±Ôö³¤ÁË·ÖÎöÈËÔ±½øÐÐÄæÏò·ÖÎöµÄ¹¦·ò³É±¾¡£ÏÂͼչʾÁËÔÚ³õ´Î½âÂëÖ®ºóµÄ²¿ÃÅ´úÂë¿é£¬¿ÉÄÜ¿´µ½´úÂëÖÐÒÀÈ»´æÔÚ×ÅÆäËû»ìºÏ¡£


ͼƬ19.png

ͼ19 »ìºÏµÄVBScript´úÂë


ÎÒÃdzÖÐø¶Ô´úÂë½øÐÐÈ¥»ìºÏÒÔ¼°º¯Êý³Á¶¨Ãû´¦Öúó£¬Äܹ»¿´µ½¾ç±¾ÏÈÊÇÉèÖÃÎļþõè¾¶ºÍĿ¼½á¹¹£¬ÔÙ´ÓXML½á¹¹ÖÐÌáÈ¡Êý¾Ý½øÐÐbase64½âÂë²¢±£ÁôΪָ¶¨Îļþ£¨µö¶üÎĵµ£©£¬×îºó´ò¿ª¸ÃÎļþ¡£


ͼƬ20.png

ͼ20 ¿ªÊ͵ö¶üÎĵµ


ÔÚ±¾°¸ÀýÖУ¬ÓÃÓڹƻóÊܺ¦ÕßµÄÊÇÈý¸ö¼Ù×°³ÉWordµÄµö¶üMSCÎļþ£¬¾ßÌåÄÚÈÝÈçÏÂͼËùʾ¡£


ͼƬ21.png

ͼ21 µö¶üÎĵµÊ¾ÀýÒ»


ͼƬ22.png

ͼ22 µö¶üÎĵµÊ¾Àý¶þ


ͼƬ23.png

ͼ23 µö¶üÎĵµÊ¾ÀýÈý


½Ó×ÅÌáÈ¡ºÍ½âÂëÆäËûbase64Êý¾Ý£¬ÔÙ½«½âÂëºóµÄÊý¾Ý±£ÁôΪ×îÖÕµÄWarp.exeºÍ7z.dll¿ÉÖ´ÐÐÎļþ¡£Ëæºó½«¡° t 8.8.8.8¡±×÷Ϊ²ÎÊý£¨×Ô¶¯¼ÓÔØÍ¬Ä¿Â¼Ï¡°7z.dll¡±µÄËùÐèǰÌᣩÆô¶¯Warp.exe·¨Ê½¡£


ͼƬ24.png

ͼ24 ÌìÉú²¢Ö´ÐÐwarp.exe·¨Ê½


¾­²é¿´£¬¡°Warp.exe¡±ÓµÓÐ ¡°Lenovo (Beijing) Co., Ltd.¡±µÄºÏ·¨Êý×ÖÊðÃû£¬ÆäÔ­ÎļþÃûΪ¡°7zwrap.exe¡±¡£¾ßÌåÐÅÏ¢ÈçÏÂͼËùʾ¡£


ͼƬ25.png

ͼ25 ¡°Warp.exe¡±¾ßÌåÐÅÏ¢


µ±¶ñÒâ¡°7z.dll¡±Îļþ±»¡°Wrap.exe¡±³É¹¦¼ÓÔØºó£¬Æä»áÔÚÄÚ´æÖжÔÖ¸¶¨Êý¾Ý½øÐнâÃÜ¡£¾­ÄÚ´æÌصãɨÃèºó£¬Åж¨×îÖÕ±»¼ÓÔØÖ´ÐеÄÊÇCobaltStrike£¬ÎÒÃÇÌáÈ¡³öµÄCSÅäÏàÐÅÏ¢ÈçÏÂͼËùʾ¡£



ͼƬ26.png

ͼ26 CSÅäÏàÐÅÏ¢


4.2 ÒÔѧÊõÑݽ²Îªµö¶üÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯


¸Ã°¸ÀýÊÇKimsuky APTºÚ¿Í×éÖ¯ÔÚ½ñÄêËùÒýÈëµÄÒ»ÖÖÐµĹ¥»÷Õ½Êõ£¬¹¥»÷Õßͨ¹ýXMLµÄÉèÖÃÊôÐÔ½«MSC¶ñÒâÎļþµÄͼ±êÉèÖÃΪWordͼ±ê£¬½èÒÔ¼Ù×°³ÉWORDÎĵ·´¹Æ»óÊܺ¦Õß¡£


ͼƬ27.png

ͼ27 ¼Ù×°µÄWordͼ±ê


µ±Êܺ¦Õßµã»÷MSCÎļþʱ£¬Óû§ÕË»§½ÚÔ죨UAC£©»áµ¯³öÒªÇóȨÏÞÑ¡Ôñ£¬ÈôÊÇÑ¡[ÊÇ]£¬Ôò»áͨ¹ýÖ´ÐÐmscÏνӷ¨Ê½mmc.exe£¬Õ¹Ê¾¹¥»÷Õß¶¨ÔìµÄÃûΪ¡°?????.docx¡±µÄMicrosoftÖÎÀí½ÚÔį̀½çÃæ¡£¾ßÌåÈçÏÂͼËùʾ¡£


ͼƬ28.png

ͼ28 ¡°?????.docx¡±µÄMicrosoftÖÎÀí½ÚÔį̀½çÃæ


´úÂëÖÐÔ̺¬Ò»¶Îcmd²ÎÊýºÅÁîÐУ¬ÆäÖÐʹÓÃÁËÈý¸öÍøÒ³ä¯ÀÀÆ÷¿Éʶ´ËÍâHTMLÌØÊâ·ûºÅ£¬ÆäËù¶ÔÓ¦µÄ½âÎöÄÚÈÝÈçϱíËùʾ¡£


±í3 ÌØÊâ·ûºÅÄÚÈݽâÎö

±í3.png


ͼƬ29.png

ͼ29 º¬ÓÐÌØÊâ·ûºÅµÄcmd²ÎÊýºÅÁîÐÐÄÚÈÝ


ͨ¹ý¸Ã·ûºÅËù¶ÔÓ¦µÄ½âÎö½øÐдúÌæºó£¬µÃµ½ÁËÈçÏÂͼËùʾµÄÅú´¦ÖúÅÁî¡£¸Ã´®Åú´¦ÖúÅÁîÔòÊÇÖ´ÐÐMSCºóµÄÖÎÀí½ÚÔį̀¸ù¹¤×÷´°¿ÚµÄºÅÁîÐвÎÊý¡£¸Ã¶ÎºÅÁîµÄÖØÒªÖ°ÄÜÊÇ´ÓÖ¸¶¨URLÏÂÔØÃûΪ¡°Grieco Kavanagh Passive Supporters.docx¡±µÄÓÃÓÚ¼Ù×°µÄµö¶üÎĵµ£¬ÒÔ¼°ºóÐø½×¶ÎµÄ¡°pest.exe¡±ºÍ¡°pest.exe.manifest¡±Îļþ¡£³ý´ËÖ®±í£¬Æä»¹»á´´½¨Ò»¸öÃûΪ¡°TemporaryClearStatesesf¡±µÄ´òË㹤×÷£¬Ã¿58·ÖÖÓÖ´ÐÐÒ»´Î¡°%appdata%\pest.exe¡±Îļþ¡£ÄÚÈÝÈçÏÂͼËùʾ¡£


ͼƬ30.png

ͼ30 cmd²ÎÊýºÅÁîÐÐÄÚÈÝ


²é¿´¡°pest.exe¡±·¨Ê½¾ßÌåÐÅÏ¢£¬·¢Ïָ÷¨Ê½µÄÊý×ÖÊðÃûÃû³ÆÎª¡°Adersoft¡±£¬Ô­Ê¼ÎļþÃûΪ¡°launcher.exe¡±¡£¸Ã·¨Ê½ÎªVBSEdit£¨ÓÉAdersoft¹«Ë¾³öÆ·µÄÒ»¿îÓ×ÇɶøÇ¿º·µÄVBScript±à×빤¾ß£©¾ç±¾Æô¶¯Æ÷¡£


ͼƬ31.png

ͼ31 ¡°pest.exe¡±·¨Ê½¾ßÌåÐÅÏ¢


ÔÚ¡°pest.exe¡±·¨Ê½Æô¶¯Ê±£¬»áĬÈϼÓÔØ¡°pest.exe.manifest¡±Îļþ£¬. manifestÎļþÊÇWindowsÀûÓ÷¨Ê½Çåµ¥ÎļþµÄÒ»²¿ÃÅ£¬³£ÓÃÓÚÖ¸¶¨ÀûÓ÷¨Ê½µÄÔËÐÐʱǰÌáºÍ»·¾³±äÁ¿µÈ¡£¹¥»÷ÕßÀûÓô˷¨Ê½µÄÔËÐлúÔ콫¶ñÒâ´úÂëдÈëÖÁÇåµ¥ÎļþÖУ¬ÄÇôµ±¡°pest.exe¡±·¨Ê½ÔËÐÐʱ¶ñÒâ´úÂë±ã¿É±»×Ô¶¯¼ÓÔØÖ´ÐС£


ͼƬ32.png

ͼ32 ¡°pest.exe¡±·¨Ê½Ö´Ðб¨´í


 ¡°pest.exe.manifest¡±ÎļþÄÚÈÝÊÇXMLÌåʽ£¬¶ñÒâ´úÂëÔ̺¬ÔÚ¡°¡±±êǩ֮¼ä¡£¸ÃÎļþµÄÖØÒªÖ°ÄÜÊÇÓÉÒ»¶Î¾­base64±àÂëµÄVBScript´úÂëÀ´ÊµÏÖ¡£²¿ÃÅ´úÂëÈçÏÂͼËùʾ¡£


ͼƬ33.png

ͼ33 base64±àÂëµÄVBScript´úÂë


½âÂëºóÎÒÃÇÄܹ»¿´µ½£¬¶ñÒâ´úÂëÊ×ÏÈ»áÅжÏ"%appdata%\ Microsoft \"Ŀ¼ÏÂÊÇ·ñ´æÔÚ¡°sim.sid¡±Îļþ¡£Èô´æÔÚÇÒÓ×ÓÚ9×Ö½Ú£¬Ôòɾ³ý¸ÃÎļþ²¢Í˳ö¾ç±¾£»²»È»£¬½«¡°sim.sid¡±Òƶ¯ÖÁ¡±%appdata%\Microsoft\sif.bat"²¢ÔËÐÐbatÎļþ£¬Ö´ÐÐʵÏÖºóɾ³ý×ÔÉíÎļþ¡£


ͼƬ34.png

ͼ34 batÎļþ²Ù×÷´úÂë


ÈôÊÇ¡°sim.sid¡±Îļþ²»´æÔÚ£¬ÔòÏòÖ¸¶¨µÄGoogle driveÁ´½Ó·¢ËÍHTTPÒªÇ󣬲¢»ñÈ¡ÏìÓ¦ÄÚÈÝ¡£


ͼƬ35.png

ͼ35 ÏòGoogle drive¹²ÏíÁ´½Ó·¢ËÍÒªÇó


³É¹¦»ñÈ¡ºó£¬´Ó½Ó¹Üµ½µÄÄÚÈÝÖÐÌáÈ¡base64±àÂëµÄÊý¾Ý£¨ÔÚ"pprbstart--"ºÍ"--pprbend"±êǩ֮¼ä£©£¬×îºó´úÌæÌØÊâ×Ö·û²¢½«½âÂëºóµÄÊý¾ÝдÈëÖÁ¡±%appdata%\Microsoft\sif.bat"¡£


ͼƬ36.png

ͼ36 ½âÎöÏìÓ¦ÄÚÈÝ


½ØÖ¹·ÖÎöʱ¸ÃGoogle drive¹²ÏíÁ´½ÓÒÑʧЧ£¬ÁÙʱÎÞ·¨»ñÈ¡µ½ºóÐø½×¶ÎµÄ¹¥»÷Ñù±¾£¬·ÖÎöÖÁ´ËʵÏÖ¡£


Îå¡¢×Ü ½á


±¾ÎÄÕë¶ÔÎÒÃǽüÆÚ²¶»ñµ½µÄһϵÁлùÓÚÐÂÐÍMSCÎļþµÄ¹¥»÷»î¶¯½øÐÐÁË·ÖÎö£¬³Áµã½éÉÜÁËĿǰMSCÎļþÔÚҰʹÓõÄÁ½ÖÖÀûÓü¼ÊõµÀÀí£¬Åû¶½üÆÚÀûÓÃMSCÎļþµÄ¶àÆðÃô¸Ð¹¥»÷»î¶¯£¬²¢Õë¶ÔÆäÖеÄÁ½¸ö°¸Àý½øÐÐÁËÉî¿Ì·ÖÎö¡£´Ó½ü¼¸¸öÔÂMSCÎļþÓйع¥»÷µÄ»îÔ¾Ç÷ÏòÀ´¿´£¬¹¥»÷»î¶¯Éæ¼°µ½Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²ú×éÖ¯ÒÔ¼°ºì¶ÓµÈ£¬ÓÈÆäÊǽüÆÚÕë¶ÔÕþÖΡ¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÁìÓòµÄAPT¹¥»÷ÆðÍ·ÏÔÖøÔö¶à£¬±ØÒªÒýÆðÓйØÕþÆóºÍÓ×ÎÒÓû§µÄ³Áµã¹Ø×¢¡£


ͬʱ£¬MSCÎļþµÄ¹«¿ªÀûÓúͼ¼ÊõÑݱäÉд¦ÓÚ·¢Õ¹³õÆÚ£¬Ö»¹ÜĿǰֻÊÇ·¢ÏÖÁËÁ½ÖÖÔÚÒ°ÀûÓ÷½Ê½£¬µ«MMC×ÔÉí´æÔÚ²»ÉÙ°²È«Òþ»¼£¬½«À´Ëæ×Ÿü¶à¹¥·À×êÑÐÈËÔ±µÄÉî¿ÌÍÚ¾ò£¬¿ÉÄÜ»á³öÏÖ¸ü¶à»ùÓÚMSC»òÊÇÆäËüWindows×é¼þµÄÐÂÐͶñÒâÀûÓü¼Êõ£¬GA»Æ½ð¼×ADLabÒ²½«³ÖÐø×·×ÙÓйؼ¼ÊõµÄ·¢Õ¹Ñݽø£¬ÊµÊ±Åû¶ÓйØÍþв»î¶¯¡£


GA»Æ½ð¼×»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Ä꣬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¸ÅÏëÊ×ÍÆÕß¡£½ØÖÁĿǰ£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶5000Óà¸ö£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑÓ×¢Êý¾Ý°²È«×êÑÓ×¢5G°²È«×êÑÓ×¢ÈËΪÖÇÄܰ²È«×êÑÓ×¢ÒÆ¶¯°²È«×êÑÓ×¢ÎïÁªÍø°²È«×êÑÓ×¢³µÁªÍø°²È«×êÑÓ×¢¹¤¿Ø°²È«×êÑÓ×¢ÐÅ´´°²È«×êÑÓ×¢ÔÆ°²È«×êÑÓ×¢ÎÞÏß°²È«×êÑÓ×¢¸ß¼¶Íþв×êÑÓ×¢¹¥·Àϵͳ½¨Éè¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑÓ×¢¹ú¶È³Áµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨Òµ°²È«·þÎñµÈ¡£



adlab.jpg