ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab£ºMSCÎļþµÄÔÚҰʹÓÃÇéÐÎÓëºÚ¿Í¹¥»÷Ô˶¯ÆÊÎö

Ðû²¼Ê±¼ä 2024-09-14

Ò»¡¢±³ ¾°


2024Äê6ÔÂ22ÈÕ £¬Ò»¸öʹÓÃMSCÃûÌõÄÐÂÐ͹¥»÷ÊÖÒյĶñÒâÑù±¾·ºÆðÔÚVTƽ̨ÉÏ £¬´ËʱʹÓÃÕâÖÖÊÖÒյĶñÒâÑù±¾ÔÚVTÉϾùÏÔʾΪÁã¼ì²âÂÊ¡£ÕâÖÖÊÖÒÕ±»ElasticÑо¿ÍŶÓÃüÃûΪ¡°GrimResource¡± £¬Æäͨ¹ý¶ñÒâ¹¹½¨µÄMSCÎļþÔÚMicrosoftÖÎÀí¿ØÖÆ̨ÖÐÖ´ÐÐí§Òâ´úÂë¡£ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÔÚÒÔºóµÄÁ½¸öÔÂʱ¼äÖÐ £¬Ò»Á¬¹ØעʹÓÃÕâÖÖʹÓÃÊÖ·¨µÄ¹¥»÷ £¬Í¨¹ý¼à²âµÄЧ¹ûÆÊÎö·¢Ã÷£º×Ô¸ÃÊÖÒÕ¹ûÕæºó £¬Í¬À๥»÷ѸËÙÔöÌí £¬µ½ÏÖÔÚΪֹÄܹ»¼à²âµ½µÄÓÐÓù¥»÷¼°Æä¹¥»÷Ñù±¾ÓÐ100¶àÆð¡£²¢ÇÒÓÐÔ½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓʹÓøÃÊÖÒÕÔÚÈ«Çò¹æÄ£ÄÚ¾ÙÐÐÍøÂç¹¥»÷ £¬°üÀ¨Kimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£ÏÖÔÚÒÑ·¢Ã÷µÄÄ¿µÄÓÐÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¼ÒµÄÕþ¸®»ú¹¹ºÍÆóÒµ £¬Éæ¼°Õþ¸®¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£


ÕâЩ¹¥»÷ÆÕ±éͨ¹ýMSCÎļþ×÷Ϊ¶ñÒâpayload £¬Í¨¹ýÖÖÖÖ·½·¨·¢Ë͸øÄ¿µÄ²¢ÓÕʹĿµÄ·­¿ª¸ÃÎļþ¡£ÓÉÓÚMSCÃûÌõĹ¥»÷ÎļþÊÇÒ»ÖÖÏà¶ÔÓÐÊýµÄÎļþÀàÐÍ£¨´ó¶¼±»¹¥»÷Õß¿ÉÄÜÊìϤ.exe¡¢.docµÈ³£¼ûµÄ¿ÉÖ´ÐÐÎļþÀ©Õ¹Ãû £¬µ«²¢²»Ïàʶ.mscÎļþ £¬Òò´Ë¿ÉÄÜÔÚÏÖʵ¹¥»÷Öб¬·¢ÆæЧ£© £¬²¢ÇÒÏÖÔÚ·À»¤ÏµÍ³Ò²ÏÊÓжԴËÀàÎļþµÄÕë¶ÔÐÔ¼ì²â £¬ÒÔÊǺڿÍʹÓøÃÊÖÒÕʵÏÖ¹¥»÷µÄÀÖ³ÉÂʸß £¬±»¼ì²âºÍ·¢Ã÷µÄ¼¸ÂʵÍ £¬¾ÍÏÖÔÚÎÒÃÇÊӲ쵽¹¥»÷ÓÕ¶ü £¬ÓаüÀ¨È磺¡°¡¶**ÂÛ̳¡·ÍâÉóר¼ÒÔ¼Ç뺯ÓëÎÄÕÂÆÀÉ󵥡±¡¢£º¡°ÄäÃûÉó¸åר¼Ò»ØÖ´ (УÍâ) ¡±¡¢¡°ÊÊÓÃÓÚÄϺ£µÄÁ½ÖÖÖ´·¨ÖƶÈÑо¿ (¸å¼þ)¡±¡¢¡°ÃÀ¹úÕ½ÂÔËõ¶Ì¶ÔÖж«µØÔµÕþÖεÄÓ°Ï족¡¢¡°****ÍøÂç´ó»á¡±µÈ¼«¾ßÒýÓÕÐԵĹ¥»÷ £¬Ò»µ©µã»÷ÆäÖеÄMSCÎļþ £¬Æäϵͳ±ã»á±»Ö²ÈëÇÔÃÜľÂí £¬µ¼ÖÂÖ÷ÒªÃô¸ÐÊý¾Ý±»ÇÔÈ¡¡£


ͨ¹ýÎÒÃǶԹ¥»÷µÄ×·ËÝ·¢Ã÷ÔçÔÚ2024Äê4Ô £¬Kimusuky APT×éÖ¯¾Í×îÏÈʹÓÃMSCÎļþÀ´¶ÔÆäÄ¿µÄʵÑéÁË´ó×ڵĹ¥»÷ £¬µ«ÆäʹÓÃÊÖ·¨ÓëGrimResourceÊÖÒÕÓÐËù²î±ð¡£ÓÉÓÚMSCÑù±¾µÄ¹ûÕæʹÓúÍÊÖÒÕÑݱäÉд¦ÓÚÉú³¤³õÆÚ £¬Òò´ËÓйع¥»÷Ñù±¾ºÍÊÖ·¨µÄת±äÖµµÃÒýÆðÒ»Á¬¹Ø×¢¡£±ðµÄ £¬OutflankÓÚ8ÔÂ13ÈÕ·¢ÎijÆGrimResourceÊÖÒÕÔ´ÓÚÆäÎäÆ÷¿â £¬ÆäÔÚ¹¥·ÀÑÝÁ·Öб»·ÀÊØ·½ÉÏ´«µ½¹«¹²É³Ïä¡£


MSC(Microsoft Snap-In Control)Îļþ £¬ÊÇ΢ÈíÖÎÀí¿ØÖÆ̨(MMC)ÓÃÀ´Ìí¼Ó/ɾ³ýµÄǶÈëʽÖÎÀíµ¥Î»Îļþ, ÓÉÓÚ´ËÀàÎļþÄܹ»Ö´ÐÐÏÂÁîºÍ¾ç±¾ £¬Òò´Ë¹¥»÷ÕßÄܹ»½èÖúMSCÎļþÔÚÄ¿µÄϵͳÉÏÖ´ÐÐÖÖÖÖ¶ñÒâʹÃü¡£×Ô΢ÈíĬÈÏÏÞÖÆÀ´×Ô»¥ÁªÍøµÄOfficeºêÎĵµºó £¬LNK¡¢MSI¡¢ISOµÈÆäËûÀàÐ͵ĶñÒâʹÓÃÊýÄ¿¾Í×îÏÈ´ó·ùÔöÌí £¬´Ë´ÎзºÆðµÄGrimResourceÊÖÒÕÒ²ÀíËùËäÈ»³ÉΪÁ˺ڿÍÃǵÄгè £¬Ïà¹ØMSCÑù±¾ÊýÄ¿×Ô4ÔÂÒÔÀ´³Ê¸ßËÙÔöÌí̬ÊÆ¡£Òò´Ë £¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÕë¶Ô½üÆÚ²¶»ñµ½µÄMSCÑù±¾¾ÙÐÐÁËÉîÈëµÄÆÊÎö £¬±¾ÎĽ«Ö÷ÒªÏÈÈÝÏÖÔÚMSCÎļþÔÚҰʹÓÃÊÖÒÕµÄÏà¹ØÔ­Àí £¬Åû¶½üÆÚʹÓÃMSCÎļþµÄ¶àÆð¹¥»÷Ô˶¯ £¬²¢ÖصãÕë¶ÔÆäÖеÄÁ½¸ö°¸Àý¾ÙÐÐÉîÈëÆÊÎö¡£

¶þ¡¢½üÆÚÔÚÒ°¹¥»÷Ô˶¯ÆÊÎö



ͨ¹ý¶ÔÏÖÔÚÍøÂçµ½µÄ100Óà¸öMSCÑù±¾µÄÆÊÎö £¬ÎÒÃÇ·¢Ã÷×îÔçµÄʹÓÃÑù±¾·ºÆðÔÚ2024Äê4ÔÂ5ÈÕ £¬ËùÓÐÑù±¾ÖÐ £¬·ºÆðÔÚ4-5ÔµĹ¥»÷Ñù±¾Ö÷ÒªÊôÓÚKimusuky×éÖ¯¡£6Ôºó £¬Ëæ×ÅGrimResourceÊÖÒյĹûÕæ £¬MSCÃûÌõÄÑù±¾ÊýÄ¿ÒÔÔÂΪµ¥Î»³ÊÏÔ×ŵĵÝÔö¹Øϵ £¬Åú×¢ºÚ¿ÍÃÇÕýÆð¾¢Ê¹ÓúͲâÊÔÏà¹Ø¹¥»÷ÊÖÒÕ²¢×ª»¯ÎªÏÖʵ¹¥»÷¡£ÒÔÏÂÊǽü¼¸¸öÔ²¶»ñµ½µÄMSCÃûÌõĹ¥»÷Ñù±¾ÊýĿͼ¡£


ͼƬ1.png

ͼ1 MSC¹¥»÷Ñù±¾ÊýĿͳ¼Æͼ£¨µ¥Î»:Ô£©


ÔÚÕâÅú¹¥»÷Ñù±¾ÖÐ £¬ÆäÖÐһЩÊÇ»ùÓÚ¿ªÔ´ÏîÄ¿±àÒëµÄÑù±¾£¨ÈçÏÂͼÖÐͼ±êΪ¡°ÑÛ¾¦¡±µÄÑù±¾¼´Îª¿ªÔ´ÏîÄ¿MSC_DropperÌìÉú£© £¬ÕâÀàÑù±¾¿ÉÄÜÊDz¿·Ö¹¥»÷ÕßÕýÔÚÆ𾢵ؾÙÐÐÊÖÒÕ×¼±¸ºÍÃâɱ²âÊÔ¡£Í¬Ê± £¬Ò»Ð©ÕæʵµÄ¹¥»÷Ô˶¯Ò²Ô½À´Ô½ÆµÈԵطºÆ𠣬ÔÚÏÖʵ¹¥»÷ÖÐÑù±¾Í¨³£»á°Ñͼ±êαװ³ÉWORD¡¢PDF¡¢MP4µÈÖÖÖÖ³£¼ûµÄÎļþÃûÌÃÓÃÒÔÒÉ»óÊܺ¦Ä¿µÄ £¬ÏÂͼÊDz¿·ÖÑù±¾¼°Í¼±êʾÀý¡£


ͼƬ2.png

ͼ2 ²¶»ñMSCÑù±¾Ê¾Àý


´ÓÖÐÎÒÃÇ·¢Ã÷ÁËÊýÆðÕë¶ÔÈ«Çò¶à¸ö¹ú¼ÒºÍµØÇøµÄ¹¥»÷Ô˶¯ £¬Ä¿µÄÖ÷Òª°üÀ¨Öйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢ÃɹŵÈ £¬¹¥»÷µÄÄ¿µÄÐÐÒµÔòÉæ¼°Õþ¸®¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£ÆäÖÐ £¬Õë¶ÔÖйúµÄAPT¹¥»÷Ô˶¯ÔÚ½üÆÚ×îÏÈÏÔ×ÅÔö¶à¡£ÔÚ7Ô³õÆÚ £¬Óйع¥»÷Ö÷ÒªÒÔ¡°Ò×·­ÒëÖúÊÖ¡±¡¢¡±¶¶Òôǧ·ÛÆóÒµºÅ¡±¡¢¡°½ÌÓýÐÐÒµÊý¾Ý¡±µÈΪÓÕ¶üµÄºÚ²ú×éÖ¯¹¥»÷ΪÖ÷¡£¶øÔÚ8ÔÂÖ®ºó £¬×îÏȽÐø·ºÆðÁ˶àÆðÒÔÕþÖÎÒéÌ⡢ר¼ÒÔ¼Çë¡¢¾Û»áÈճ̡¢Í¶Ëß½¨Òé¡¢¾Ù±¨ÖÊÁϵÈÕë¶ÔÕþ¸®×éÖ¯»ò¿ÆÑв¿·ÖµÄÕë¶ÔÐÔ¹¥»÷ £¬ÐèÒªÒýÆð¸ß¶ÈСÐÄ £¬²¿·ÖÓÕ¶üÎĵµÈçÏÂËùʾ¡£


ͼƬ3.png

ͼ3 Ö÷ÌâΪ¡°×¨¼ÒÔ¼Ç뺯¡±ÀàµÄÓÕ¶üÎĵµ


ͼƬ4.png

ͼ4 Ö÷ÌâΪ¡°Õþ²ßÖƶÈÑо¿¡±ÀàµÄÓÕ¶üÎĵµ


ͼƬ5.png

ͼ5 Ö÷ÌâΪ¡°****ÍøÂç´ó»á¡±µÄÓÕ¶üÎĵµ


ͼƬ6.png

ͼ6 Õë¶ÔË®ÀûÊðµÄÓÕ¶üÎĵµ


³ýÁËÕë¶ÔÖйúÒÔÍâ £¬º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȶà¹úÒ²½ÓÁ¬ÔâÓöµ½Ê¹ÓÃMSCÎļþµÄ¹¥»÷Ô˶¯ £¬ÆäÖÐÓÈÒÔº«¹úÔâÊܵĹ¥»÷×î¶à £¬Õâ¿ÉÄÜÓëkimsuky×éÖ¯µÄ¹¥»÷Ä¿µÄÇãÏòÓйØ £¬²¿·Ö¹¥»÷Ô˶¯ÓÕ¶üÈçÏÂËùʾ¡£


ͼƬ7.png

ͼ7 Õë¶Ôº«¹úµÄÓÕ¶üÎĵµ


ͼƬ8.png

ͼ8 Õë¶ÔÔ½ÄÏʯÓ͹«Ë¾µÄÓÕ¶üÎĵµ


ÔÚÕë¶ÔÕâÅúÑù±¾¾ÙÐÐÉîÈëÆÊÎöºó £¬ÎÒÃÇ·¢Ã÷Á˹¥»÷ÕßʹÓõĶà¸ö»ù´¡ÉèÊ© £¬°üÀ¨¶à½×¶ÎÏÂÔØ·þÎñÆ÷ºÍC2·þÎñÆ÷µÈ £¬ÆäÖд󲿷ֶ¼½ÓÄÉÁËÔÆ·þÎñÀ´×ÌÈÅËÝÔ´×·×Ù £¬ÆäÖÐһЩ·þÎñÆ÷¹éÊôÓÚÃÀ¹ú¡¢ÈÕ±¾¡¢Èðµä¡¢·¨¹ú¡¢Ð¼ÓƵȹú¼Ò¡£²¿·ÖÑù±¾¼°C2·þÎñÆ÷ÈçÏÂËùʾ¡£


±í1 ¶ñÒâ·þÎñÆ÷µØµã

±í1-1.png

±í1-2.png


ͬʱ £¬ÎÒÃÇÒ²²¶»ñµ½Á˲¿·ÖÑù±¾µÄͶµÝURLµØµãÈçϱíËùʾ¡£


±í2 Ñù±¾Í¶µÝURL

±í2-1.png

±í2-2.png


Èý¡¢MSCÎļþʹÓÃÊÖÒÕÔ­ÀíÆÊÎö


MSC(Microsoft Snap-In Control)Îļþ £¬ÊÇ΢ÈíÖÎÀí¿ØÖÆ̨(MMC)ÓÃÀ´Ìí¼Ó/ɾ³ýµÄǶÈëʽÖÎÀíµ¥Î»Îļþ, ÖÎÀíԱͨ¹ý½¨Éè¿ØÖÆ̨¿ÉÒÔÖÎÀíÅÌËã»úµÄÖÖÖÖÉèÖà £¬Ìí¼ÓÖÖÖÖ¹¦Ð§ÈçÓû§ÕË»§ÖÎÀí¡¢ÏµÍ³·þÎñ¡¢×°±¸Çý¶¯³ÌÐòµÈ £¬È»ºó¿ÉÒÔ½«ÕâЩÖÎÀíµ¥Î»µÄ×Ô½ç˵ÉèÖÃÒÔXMLµÄÐÎʽÉúÑĵ½´ÅÅÌÉÏ £¬¼´MSCÃûÌá£WindowsÖг£¼ûµÄ×°±¸ÖÎÀíÆ÷¡¢´ÅÅÌÖÎÀíÆ÷¡¢×éÕ½ÂÔÖÎÀíÆ÷µÈ¶¼ÊÇMSCÃûÌÃÎļþ¡£ÈçÏÂͼÊÇ×Ô½ç˵MSCÎļþµÄÖÎÀíµ¥Î»Ê¹Ãü°å½çÃæ £¬¹¥»÷Õß¿ÉÒÔͨ¹ý±à³ÌµÄ·½·¨ÓëMMC¾ÙÐн»»¥ £¬´Ó¶ø½á¹¹×Ô½ç˵µÄ½çÃæºÍÄÚÈÝ¡£


ͼƬ9.png

ͼ9 MSCÎļþÖÎÀíµ¥Î»Ê¹Ãü°å


ÎÒÃÇÔÚ½øÒ»²½Õë¶ÔÕâÅúÑùÌìÖ°Îöºó £¬·¢Ã÷ÏÖÔÚMSCÃûÌÃÎļþµÄÔÚҰʹÓ÷½·¨Ö÷ÒªÓÐÁ½ÖÖ¡£ÔÚÊܺ¦ÕßĬÈÏ¿ªÆôÓû§ÕË»§¿ØÖÆ£¨UAC£©µÄÇéÐÎÏ £¬µÚÒ»ÖÖʹÓ÷½·¨ÐèÒªÓëÊܺ¦Õß½»»¥Á½´Î£¨Ö÷ÒªÓÉKimusuky×é֯ʹÓã©£»ÁíÒ»ÖÖÖ»Ðè½»»¥Ò»´Î(GrimResourceÊÖÒÕ) £¬Ïà¹ØÊÖÒÕʹÓÃÁ÷³ÌͼÈçÏÂËùʾ¡£

ͼƬ10.png

ͼ10 MSCÎļþÊÖÒÕʹÓÃÁ÷³Ìͼ


ʹÓ÷½·¨Ò»£ºÔÚÊܺ¦Õß·­¿ªMSCÎļþºó £¬Ê×Ïȵ¯³öUAC¿ØÖÆÑ¡Ïî £¬ÈôÊÇÑ¡ÔñÊÇ £¬Ôò¼ÌÐøµ¯³ö¹¥»÷Õ߶¨ÖƵÄMicrosoftÖÎÀí¿ØÖÆ̨½çÃæÓÕµ¼Ä¿µÄ £¬Ò»µ©Êܺ¦Õß¼ÌÐøµã»÷open·­¿ªÎĵµ¼´»áÖÐÕÐ £¬Ö´ÐÐcmdÏÂÁî¡¢powershell¾ç±¾µÈºóÐøʹÓý׶Ρ£

ͼƬ11.png

ͼ11 ʹÓ÷½·¨Ò»


¹ØÓÚ´ËÀàÑù±¾ £¬¹¥»÷Õßͨ¹ý±à¼­MSCÎļþµÄ½çÃæαÔìUIÍâ¹Û £¬´Ó¶øÓÕÆ­Êܺ¦Õßµã»÷¿ØÖÆ̨ʹÃü°åÉϵÄÁ´½Ó £¬¶ø²»»á±¬·¢ÏÓÒÉ¡£ÕâÖÖʹÓ÷½·¨½èÖúÁËMMCÖеĿØÖÆ̨ʹÃü°åʵÑé¹¥»÷ £¬¿ØÖÆ̨ʹÃü°åÊÇÔÚMMC1.2ÖÐÒýÈëµÄ £¬¹¥»÷Õß¿ÉÒÔ½èÖú¿ØÖÆ̨ʹÃü°åÀ´Ö´ÐÐÖÖÖÖʹÃü £¬ÀýÈç·­¿ªÊôÐÔÒ³¡¢Ö´Ðв˵¥ÏÂÁî¡¢ÔËÐÐÏÂÁîÐкͷ­¿ªÍøÒ³µÈ £¬ÏÖÔÚÖ÷Òª·¢Ã÷Kimsuky×éÖ¯ÔÚ´ó×ÚʹÓôËÀ๥»÷·½·¨ £¬Ïà¹ØʹÓÃÑù±¾µÄ×îÔç·ºÆðʱ¼äÊÇÔÚ½ñÄê4ÔÂ5ÈÕ £¬Ê¹ÓÃʾÀýÈçÏÂͼËùʾ¡£

ͼƬ12.png

ͼ12 ¿ØÖÆ̨ʹÃü°åÖ´ÐÐí§ÒâÏÂÁîʾÀý


ͼƬ13.png

ͼ13 ʹÃü°åÖ´ÐÐí§ÒâÏÂÁîXML


ʹÓ÷½·¨¶þ£ºGrimResourceÊÖÒÕ £¬¸ÃÊÖÒÕʹÓÃapds.dllÖеÄXSSÎó²î £¬Í¨¹ýMSCÎļþµÄStringTable²¿·ÖÒýÓÃÒ×Êܹ¥»÷µÄAPDS×ÊÔ´ £¬´Ó¶øʵÏÖǶÈëÔÚMSCÎļþÖеÄJS´úÂëí§ÒâÖ´ÐÐ £¬×îºóÖ´ÐÐXMLÖеľ籾´úÂë¡£Ïà½ÏÓÚʹÓ÷½·¨Ò» £¬Æä¾ßÓÐ×îÉÙµÄÇå¾²ÖÒÑÔ £¬ÎÞÒÉÄܹ»Ê¹µÃ¹¥»÷µÄÀÖ³ÉÂÊ´ó´óÌá¸ß¡£Í¬Ê± £¬¹ØÓÚÐí¶àΪÁËÀû±ã¶øĬÈÏ×÷·ÏUAC֪ͨµÄÊܺ¦ÕßÀ´Ëµ¸üÊÇÄִܵïÎÞ½»»¥¼´¿ÉÖ´ÐеÄЧ¹û¡£
ÊÖÒÕʹÓÃÒªº¦µã£º


  • ½«ActiveX¹¤¾ß¼ÓÔص½¡°ActiveX¿Ø¼þ¡±ÖÎÀíµ¥Î»ÖС£

  • ½«HTMLÎļþ¼ÓÔص½¡°Á´½Óµ½WebµØµã¡±ÖÎÀíµ¥Î»ÖС£

  • ÔÚHTMLÎļþÖÐ £¬Ê¹ÓÃJavaScriptÓë¼ÓÔصÄActiveX¹¤¾ß¾ÙÐн»»¥¡£²¢Í¨¹ý MSXMLÒªÁì £¬´¥·¢XSLת»»À´Ö´ÐÐJScript´úÂë¡£

  • ×îºó´ÓJScript´úÂëÖÐŲÓÃϵͳº¯Êý £¬»òÕßͨ¹ý DotNetToJScript Ö´ÐÐ.NET´úÂë¡£


Ê×ÏÈ £¬ÔÚMMC³ÌÐòÖÐ £¬¹¥»÷Õß¿ÉÒÔ×Ô½ç˵²åÈëActiveX¿Ø¼þ¡£Í¨¹ýÎļþ±à¼­Æ÷·­¿ª½¨ÉèµÄMSCÎļþʱ £¬¿ÉÒÔ¿´µ½½¨ÉèµÄActiveX¿Ø¼þ´æ´¢ÔÚXMLµÄStringTableÖС£


ͼƬ14.png

ͼ14 ²åÈëActiveX¿Ø¼þ¹¤¾ß


µ«ÈôÊÇÏëÀֳɼÓÔع¤¾ß £¬¾ÍÒªÈƹýActiveX ¿Ø¼þµÄÇå¾²ÖÒÑÔ¡£¹¥»÷Õß½ÓÄÉÁËÒ»ÖÖÇÉÃîµÄÒªÁì £¬Í¨¹ýMicrosoft Internet Explorerä¯ÀÀÆ÷×é¼þ»á¼ûexternal ¹¤¾ß £¬´Ó¶øÓëMMC¿ØÖÆ̨µÄÆäËûÔªËؾÙÐн»»¥ £¬ÕâÊÇ΢Èí¹Ù·½Ö§³ÖµÄÒ»ÖÖ·½·¨¡£ÈçÏÂͼÖÐ £¬scopeNamespaceºÍdocObject¼´ÊÇͨ¹ýexternal.Document»ñÈ¡ÏÖÓй¤¾ß £¬¶ø·Ç½¨ÉèеÄActiveX¹¤¾ß £¬½ø¶øÈƹýÁËÖ±½Ó½¨ÉèActiveX¿Ø¼þʱµÄÇå¾²ÏÞÖÆ¡£


ͼƬ15.png

ͼ15 GrimResourceÊÖÒÕʹÓôúÂë


ͬʱ £¬¹¥»÷ÕßʹÓÃÁËapds.dllµÄÒ»¸öXSSÎó²î £¬´Ó¶ø¿ÉÒÔÖ´ÐÐConsole RootÖеÄJscript £¬½ø¶øÔÙÖ´ÐÐXMLÖеľ籾¡£ÕâÆäÖл¹Éæ¼°µ½Ò»¸ö¼¼ÇÉ £¬¼´Ê¹ÓÃMSXML£¨Microsoft.XMLDOM / {2933BF90-7B36-11D2-B20E-00C04F983E60} £©Ö´ÐÐXSLÎļþÖÐǶÈëµÄ¾ç±¾¡£

XSLTÊÇÒ»ÖÖÓÃÓÚ½«XMLÎĵµ×ª»»ÎªÆäËûÎĵµÃûÌõÄÓïÑÔ £¬XSLTÑùʽ±í£¨XSL£©Ôò½ç˵ÁËÔõÑù½«Ò»¸öXMLÎĵµ×ª»»ÎªÆäËûÐÎʽ¡£Î¢ÈíÖ§³ÖMSXML XSLTʹÓÃÔªËؼ°ÆäÊôÐÔimplements-prefixʵÏÖ²¢À©Õ¹º¯ÊýÒÔÌṩ¾ç±¾¼¶Ö§³Ö¡£Òò´Ë £¬¹¥»÷Õßͨ¹ýMSXMLµÄ·½·¨¼´¿ÉÖ´ÐÐXSLÎļþÖÐǶÈëµÄ¾ç±¾ £¬ÈçŲÓú¯Êý XML.transformNode(xsl) £¬¼´¿ÉÖ´ÐÐǶÈëµÄ¾ç±¾¼°ºóÐøµÄ¶ñÒâʹÓÃÄ £¿é £¬½âÂë¾ç±¾ÖеıêÇ©ÈçÏÂͼËùʾ¡£


ͼƬ16.png

ͼ16 ¾ç±¾ÖеÄ



ËÄ¡¢°¸ÀýÆÊÎö


ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab½ÓÁ¬²¶»ñµ½Á˶àÆðʹÓÃMSCÎļþÕë¶ÔÈ«ÇòÄ¿µÄµÄ¹¥»÷Ô˶¯¡£ÆäÖÐÒÑ·¢Ã÷Õë¶ÔÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¼ÒµÄÕþ¸®»ú¹¹ºÍÆóÒµµÄ¹¥»÷ £¬Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓÕýÔÚʹÓÃÏà¹ØÊÖÒÕÔÚÈ«Çò¹æÄ£ÄÚ¾ÙÐÐÍøÂç¹¥»÷ £¬°üÀ¨Kimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£ÔÚÖî¶àµÄ¹¥»÷°¸ÀýÖÐ £¬ÎÒÃÇÑ¡È¡ÁËÔÚÊÖÒÕ²ãÃæ½ÏÓдú±íÐÔÇÒÏà¶ÔÃô¸ÐµÄÁ½À๥»÷Ñù±¾×÷Ϊ´Ë´ÎµÄÆÊÎö°¸Àý £¬Ê¹ÓÃGrimResourceÊÖÒÕÕë¶ÔÖйúµÄ¹¥»÷Ô˶¯ £¬ÒÔ¼°Kimsuky×é֯ʹÓÃMMC¿ØÖÆ̨ʹÃü°åÕë¶Ôº«¹úµÄ×îй¥»÷Ô˶¯¡£ÏÂÃæÎÒÃǽ«¶ÔÑ¡È¡µÄÁ½¸ö°¸Àý¾ÙÐÐÉîÈëµÄÆÊÎö¡£


4.1 ÒÔÕþÖλ°ÌâΪÓÕ¶üÕë¶ÔÖйúµÄ¹¥»÷Ô˶¯


´Ë°¸ÀýʹÓõÄÊÇGrimResourceÊÖÒÕ £¬µ±Êܺ¦Õßµã»÷ÔËÐÐmscÎļþʱ £¬mmc.exe»áÖ´ÐÐÑù±¾ÖеÄjs´úÂë £¬¼Ì¶øÖ´ÐÐǶÈëÔÚxmlÖеÄVBScript´úÂë¡£ÆäÖÐ £¬ÒýÖÂVBA´úÂëµÄÖ´ÐеÄÒªº¦µãÊÇtransforNode(xsl)ÒªÁìµÄŲÓá£


ͼƬ17.png

ͼ17 ÒýÖÂVBA´úÂëÖ´ÐеÄÒªº¦µã


transforNodeÒªÁì³£ÓÃÓÚ½«Ò»¸öXMLÎĵµÍ¨¹ýXSLTÑùʽ±í£¨×÷Ϊ²ÎÊý£©×ª»»ÎªÆäËûÎĵµÃûÌá£ÈôÊÇXSLTÑùʽ±íÖк¬ÓлòÔªËØʱ £¬ÄÇôԪËØÖеľ籾Ôò»áÔÚת»»Àú³ÌÖб»Ö´ÐС£


ͼƬ18.png

ͼ18 XSLTÑùʽ±íÄÚÈÝ


±»Ö´ÐеÄVBScript´úÂëͨ¹ý×Ô½ç˵±àÂëÏ¢ÕùÂë¡¢×Ö·û´®Æ´½Ó¡¢ÌØÊâ×Ö·û»ìÏý±àÂëµÈ»ìÏýÊÖÒÕ £¬Äܹ»ÓÐÓõØÒþ²ØÆäÕæʵÂß¼­ºÍ¶ñÒâÐÐΪ £¬Í¬Ê±ÔöÌíÁËÆÊÎöÖ°Ô±¾ÙÐÐÄæÏòÆÊÎöµÄʱ¼ä±¾Ç®¡£ÏÂͼչʾÁËÔÚÊ״νâÂëÖ®ºóµÄ²¿·Ö´úÂë¿é £¬Äܹ»¿´µ½´úÂëÖÐÒÀÈ»±£´æ×ÅÆäËû»ìÏý¡£


ͼƬ19.png

ͼ19 »ìÏýµÄVBScript´úÂë


ÎÒÃǼÌÐø¶Ô´úÂë¾ÙÐÐÈ¥»ìÏýÒÔ¼°º¯ÊýÖØÃüÃû´¦Öóͷ£ºó £¬¿ÉÒÔ¿´µ½¾ç±¾ÏÈÊÇÉèÖÃÎļþ·¾¶ºÍĿ¼½á¹¹ £¬ÔÙ´ÓXML½á¹¹ÖÐÌáÈ¡Êý¾Ý¾ÙÐÐbase64½âÂë²¢ÉúÑÄΪָ¶¨Îļþ£¨ÓÕ¶üÎĵµ£© £¬×îºó·­¿ª¸ÃÎļþ¡£


ͼƬ20.png

ͼ20 ÊÍ·ÅÓÕ¶üÎĵµ


ÔÚ±¾°¸ÀýÖÐ £¬ÓÃÓÚÒÉ»óÊܺ¦ÕßµÄÊÇÈý¸öαװ³ÉWordµÄÓÕ¶üMSCÎļþ £¬ÏêϸÄÚÈÝÈçÏÂͼËùʾ¡£


ͼƬ21.png

ͼ21 ÓÕ¶üÎĵµÊ¾ÀýÒ»


ͼƬ22.png

ͼ22 ÓÕ¶üÎĵµÊ¾Àý¶þ


ͼƬ23.png

ͼ23 ÓÕ¶üÎĵµÊ¾ÀýÈý


½Ó×ÅÌáÈ¡Ï¢ÕùÂëÆäËûbase64Êý¾Ý £¬ÔÙ½«½âÂëºóµÄÊý¾ÝÉúÑÄΪ×îÖÕµÄWarp.exeºÍ7z.dll¿ÉÖ´ÐÐÎļþ¡£Ëæºó½«¡° t 8.8.8.8¡±×÷Ϊ²ÎÊý£¨×Ô¶¯¼ÓÔØͬĿ¼Ï¡°7z.dll¡±µÄËùÐèÌõ¼þ£©Æô¶¯Warp.exe³ÌÐò¡£


ͼƬ24.png

ͼ24 ÌìÉú²¢Ö´ÐÐwarp.exe³ÌÐò


¾­Éó²é £¬¡°Warp.exe¡±¾ßÓÐ ¡°Lenovo (Beijing) Co., Ltd.¡±µÄÕýµ±Êý×ÖÊðÃû £¬ÆäÔ­ÎļþÃûΪ¡°7zwrap.exe¡±¡£ÏêϸÐÅÏ¢ÈçÏÂͼËùʾ¡£


ͼƬ25.png

ͼ25 ¡°Warp.exe¡±ÏêϸÐÅÏ¢


µ±¶ñÒâ¡°7z.dll¡±Îļþ±»¡°Wrap.exe¡±ÀֳɼÓÔغó £¬Æä»áÔÚÄÚ´æÖжÔÖ¸¶¨Ãü¾Ý¾ÙÐнâÃÜ¡£¾­ÄÚ´æÌØÕ÷ɨÃèºó £¬ÅжÏ×îÖÕ±»¼ÓÔØÖ´ÐеÄÊÇCobaltStrike £¬ÎÒÃÇÌáÈ¡³öµÄCSÉèÖÃÐÅÏ¢ÈçÏÂͼËùʾ¡£



ͼƬ26.png

ͼ26 CSÉèÖÃÐÅÏ¢


4.2 ÒÔѧÊõÑݽ²ÎªÓÕ¶üÕë¶Ôº«¹úµÄ¹¥»÷Ô˶¯


¸Ã°¸ÀýÊÇKimsuky APTºÚ¿Í×éÖ¯ÔÚ½ñÄêËùÒýÈëµÄÒ»ÖÖÐµĹ¥»÷Õ½ÂÔ £¬¹¥»÷Õßͨ¹ýXMLµÄÉèÖÃÊôÐÔ½«MSC¶ñÒâÎļþµÄͼ±êÉèÖÃΪWordͼ±ê £¬½èÒÔαװ³ÉWORDÎĵµÀ´ÒÉ»óÊܺ¦Õß¡£


ͼƬ27.png

ͼ27 αװµÄWordͼ±ê


µ±Êܺ¦Õßµã»÷MSCÎļþʱ £¬Óû§ÕË»§¿ØÖÆ£¨UAC£©»áµ¯³öÇëÇóȨÏÞÑ¡Ôñ £¬ÈôÊÇÑ¡[ÊÇ] £¬Ôò»áͨ¹ýÖ´ÐÐmscÅþÁ¬³ÌÐòmmc.exe £¬Õ¹Ê¾¹¥»÷Õ߶¨ÖƵÄÃûΪ¡°?????.docx¡±µÄMicrosoftÖÎÀí¿ØÖÆ̨½çÃæ¡£ÏêϸÈçÏÂͼËùʾ¡£


ͼƬ28.png

ͼ28 ¡°?????.docx¡±µÄMicrosoftÖÎÀí¿ØÖÆ̨½çÃæ


´úÂëÖаüÀ¨Ò»¶Îcmd²ÎÊýÏÂÁîÐÐ £¬ÆäÖÐʹÓÃÁËÈý¸öÍøÒ³ä¯ÀÀÆ÷¿Éʶ±ðµÄHTMLÌØÊâ·ûºÅ £¬ÆäËù¶ÔÓ¦µÄÆÊÎöÄÚÈÝÈçϱíËùʾ¡£


±í3 ÌØÊâ·ûºÅÄÚÈÝÆÊÎö

±í3.png


ͼƬ29.png

ͼ29 º¬ÓÐÌØÊâ·ûºÅµÄcmd²ÎÊýÏÂÁîÐÐÄÚÈÝ


ͨ¹ý¸Ã·ûºÅËù¶ÔÓ¦µÄÆÊÎö¾ÙÐÐÌæ»»ºó £¬»ñµÃÁËÈçÏÂͼËùʾµÄÅú´¦Öóͷ£ÏÂÁî¡£¸Ã´®Åú´¦Öóͷ£ÏÂÁîÔòÊÇÖ´ÐÐMSCºóµÄÖÎÀí¿ØÖÆ̨¸ùʹÃü´°¿ÚµÄÏÂÁîÐвÎÊý¡£¸Ã¶ÎÏÂÁîµÄÖ÷Òª¹¦Ð§ÊÇ´ÓÖ¸¶¨URLÏÂÔØÃûΪ¡°Grieco Kavanagh Passive Supporters.docx¡±µÄÓÃÓÚαװµÄÓÕ¶üÎĵµ £¬ÒÔ¼°ºóÐø½×¶ÎµÄ¡°pest.exe¡±ºÍ¡°pest.exe.manifest¡±Îļþ¡£³ý´ËÖ®Íâ £¬Æ仹»á½¨ÉèÒ»¸öÃûΪ¡°TemporaryClearStatesesf¡±µÄÍýÏëʹÃü £¬Ã¿58·ÖÖÓÖ´ÐÐÒ»´Î¡°%appdata%\pest.exe¡±Îļþ¡£ÄÚÈÝÈçÏÂͼËùʾ¡£


ͼƬ30.png

ͼ30 cmd²ÎÊýÏÂÁîÐÐÄÚÈÝ


Éó²é¡°pest.exe¡±³ÌÐòÏêϸÐÅÏ¢ £¬·¢Ã÷¸Ã³ÌÐòµÄÊý×ÖÊðÃûÃû³ÆΪ¡°Adersoft¡± £¬Ô­Ê¼ÎļþÃûΪ¡°launcher.exe¡±¡£¸Ã³ÌÐòΪVBSEdit£¨ÓÉAdersoft¹«Ë¾³öÆ·µÄÒ»¿îСÇɶøÇ¿º·µÄVBScript±à¼­¹¤¾ß£©¾ç±¾Æô¶¯Æ÷¡£


ͼƬ31.png

ͼ31 ¡°pest.exe¡±³ÌÐòÏêϸÐÅÏ¢


ÔÚ¡°pest.exe¡±³ÌÐòÆô¶¯Ê± £¬»áĬÈϼÓÔØ¡°pest.exe.manifest¡±Îļþ £¬. manifestÎļþÊÇWindowsÓ¦ÓóÌÐòÇåµ¥ÎļþµÄÒ»²¿·Ö £¬³£ÓÃÓÚÖ¸¶¨Ó¦ÓóÌÐòµÄÔËÐÐʱÌõ¼þºÍÇéÐαäÁ¿µÈ¡£¹¥»÷ÕßʹÓô˳ÌÐòµÄÔËÐлúÖƽ«¶ñÒâ´úÂëдÈëÖÁÇåµ¥ÎļþÖÐ £¬ÄÇôµ±¡°pest.exe¡±³ÌÐòÔËÐÐʱ¶ñÒâ´úÂë±ã¿É±»×Ô¶¯¼ÓÔØÖ´ÐС£


ͼƬ32.png

ͼ32 ¡°pest.exe¡±³ÌÐòÖ´Ðб¨´í


 ¡°pest.exe.manifest¡±ÎļþÄÚÈÝÊÇXMLÃûÌà £¬¶ñÒâ´úÂë°üÀ¨ÔÚ¡°¡±±êÇ©Ö®¼ä¡£¸ÃÎļþµÄÖ÷Òª¹¦Ð§ÊÇÓÉÒ»¶Î¾­base64±àÂëµÄVBScript´úÂëÀ´ÊµÏÖ¡£²¿·Ö´úÂëÈçÏÂͼËùʾ¡£


ͼƬ33.png

ͼ33 base64±àÂëµÄVBScript´úÂë


½âÂëºóÎÒÃÇ¿ÉÒÔ¿´µ½ £¬¶ñÒâ´úÂëÊ×ÏÈ»áÅжÏ"%appdata%\ Microsoft \"Ŀ¼ÏÂÊÇ·ñ±£´æ¡°sim.sid¡±Îļþ¡£Èô±£´æÇÒСÓÚ9×Ö½Ú £¬Ôòɾ³ý¸ÃÎļþ²¢Í˳ö¾ç±¾£»²»È» £¬½«¡°sim.sid¡±Òƶ¯ÖÁ¡±%appdata%\Microsoft\sif.bat"²¢ÔËÐÐbatÎļþ £¬Ö´ÐÐÍê³Éºóɾ³ý×ÔÉíÎļþ¡£


ͼƬ34.png

ͼ34 batÎļþ²Ù×÷´úÂë


ÈôÊÇ¡°sim.sid¡±Îļþ²»±£´æ £¬ÔòÏòÖ¸¶¨µÄGoogle driveÁ´½Ó·¢ËÍHTTPÇëÇó £¬²¢»ñÈ¡ÏìÓ¦ÄÚÈÝ¡£


ͼƬ35.png

ͼ35 ÏòGoogle drive¹²ÏíÁ´½Ó·¢ËÍÇëÇó


ÀֳɻñÈ¡ºó £¬´ÓÎüÊÕµ½µÄÄÚÈÝÖÐÌáÈ¡base64±àÂëµÄÊý¾Ý£¨ÔÚ"pprbstart--"ºÍ"--pprbend"±êÇ©Ö®¼ä£© £¬×îºóÌæ»»ÌØÊâ×Ö·û²¢½«½âÂëºóµÄÊý¾ÝдÈëÖÁ¡±%appdata%\Microsoft\sif.bat"¡£


ͼƬ36.png

ͼ36 ÆÊÎöÏìÓ¦ÄÚÈÝ


×èÖ¹ÆÊÎöʱ¸ÃGoogle drive¹²ÏíÁ´½ÓÒÑʧЧ £¬ÔÝʱÎÞ·¨»ñÈ¡µ½ºóÐø½×¶ÎµÄ¹¥»÷Ñù±¾ £¬ÆÊÎöÖÁ´Ë¿¢Ê¡£


Îå¡¢×Ü ½á


±¾ÎÄÕë¶ÔÎÒÃǽüÆÚ²¶»ñµ½µÄһϵÁлùÓÚÐÂÐÍMSCÎļþµÄ¹¥»÷Ô˶¯¾ÙÐÐÁËÆÊÎö £¬ÖصãÏÈÈÝÁËÏÖÔÚMSCÎļþÔÚҰʹÓõÄÁ½ÖÖʹÓÃÊÖÒÕÔ­Àí £¬Åû¶½üÆÚʹÓÃMSCÎļþµÄ¶àÆðÃô¸Ð¹¥»÷Ô˶¯ £¬²¢Õë¶ÔÆäÖеÄÁ½¸ö°¸Àý¾ÙÐÐÁËÉîÈëÆÊÎö¡£´Ó½ü¼¸¸öÔÂMSCÎļþÏà¹Ø¹¥»÷µÄ»îÔ¾Ç÷ÊÆÀ´¿´ £¬¹¥»÷Ô˶¯Éæ¼°µ½Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²ú×éÖ¯ÒÔ¼°ºì¶ÓµÈ £¬ÓÈÆäÊǽüÆÚÕë¶ÔÕþÖΡ¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÁìÓòµÄAPT¹¥»÷×îÏÈÏÔÖøÔö¶à £¬ÐèÒªÒýÆðÏà¹ØÕþÆóºÍСÎÒ˽¼ÒÓû§µÄÖصã¹Ø×¢¡£


ͬʱ £¬MSCÎļþµÄ¹ûÕæʹÓúÍÊÖÒÕÑݱäÉд¦ÓÚÉú³¤³õÆÚ £¬Ö»¹ÜÏÖÔÚÖ»ÊÇ·¢Ã÷ÁËÁ½ÖÖÔÚҰʹÓ÷½·¨ £¬µ«MMC×Ô¼º±£´æ²»ÉÙÇå¾²Òþ»¼ £¬Î´À´Ëæןü¶à¹¥·ÀÑо¿Ö°Ô±µÄÉîÈëÍÚ¾ò £¬¿ÉÄ᷺ܻÆð¸ü¶à»ùÓÚMSC»òÊÇÆäËüWindows×é¼þµÄÐÂÐͶñÒâʹÓÃÊÖÒÕ £¬ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÒ²½«Ò»Á¬×·×ÙÏà¹ØÊÖÒÕµÄÉú³¤Ñݽø £¬ÊµÊ±Åû¶ÓйØÍþвÔ˶¯¡£


ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©


ADLab½¨ÉèÓÚ1999Äê £¬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò» £¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ± £¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£×èÖ¹ÏÖÔÚ £¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Çå¾²Îó²î5000Óà¸ö £¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº­¸Ç»ù´¡Çå¾²Ñо¿¡¢Êý¾ÝÇå¾²Ñо¿¡¢5GÇå¾²Ñо¿¡¢È˹¤ÖÇÄÜÇå¾²Ñо¿¡¢Òƶ¯Çå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢³µÁªÍøÇå¾²Ñо¿¡¢¹¤¿ØÇå¾²Ñо¿¡¢ÐÅ´´Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡¢ÎÞÏßÇå¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·Àϵͳ½¨Éè¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£



adlab.jpg