ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab£ºMSCÎļþµÄÔÚҰʹÓÃÇéÐÎÓëºÚ¿Í¹¥»÷Ô˶¯ÆÊÎö
Ðû²¼Ê±¼ä 2024-09-14Ò»¡¢±³ ¾°
2024Äê6ÔÂ22ÈÕ£¬Ò»¸öʹÓÃMSCÃûÌõÄÐÂÐ͹¥»÷ÊÖÒյĶñÒâÑù±¾·ºÆðÔÚVTƽ̨ÉÏ£¬´ËʱʹÓÃÕâÖÖÊÖÒյĶñÒâÑù±¾ÔÚVTÉϾùÏÔʾΪÁã¼ì²âÂÊ¡£ÕâÖÖÊÖÒÕ±»ElasticÑо¿ÍŶÓÃüÃûΪ¡°GrimResource¡±£¬Æäͨ¹ý¶ñÒâ¹¹½¨µÄMSCÎļþÔÚMicrosoftÖÎÀí¿ØÖÆ̨ÖÐÖ´ÐÐí§Òâ´úÂë¡£ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLabÔÚÒÔºóµÄÁ½¸öÔÂʱ¼äÖУ¬Ò»Á¬¹ØעʹÓÃÕâÖÖʹÓÃÊÖ·¨µÄ¹¥»÷£¬Í¨¹ý¼à²âµÄЧ¹ûÆÊÎö·¢Ã÷£º×Ô¸ÃÊÖÒÕ¹ûÕæºó£¬Í¬À๥»÷ѸËÙÔöÌí£¬µ½ÏÖÔÚΪֹÄܹ»¼à²âµ½µÄÓÐÓù¥»÷¼°Æä¹¥»÷Ñù±¾ÓÐ100¶àÆð¡£²¢ÇÒÓÐÔ½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓʹÓøÃÊÖÒÕÔÚÈ«Çò¹æÄ£ÄÚ¾ÙÐÐÍøÂç¹¥»÷£¬°üÀ¨Kimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£ÏÖÔÚÒÑ·¢Ã÷µÄÄ¿µÄÓÐÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¼ÒµÄÕþ¸®»ú¹¹ºÍÆóÒµ£¬Éæ¼°Õþ¸®¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£
ÕâЩ¹¥»÷ÆÕ±éͨ¹ýMSCÎļþ×÷Ϊ¶ñÒâpayload£¬Í¨¹ýÖÖÖÖ·½·¨·¢Ë͸øÄ¿µÄ²¢ÓÕʹĿµÄ·¿ª¸ÃÎļþ¡£ÓÉÓÚMSCÃûÌõĹ¥»÷ÎļþÊÇÒ»ÖÖÏà¶ÔÓÐÊýµÄÎļþÀàÐÍ£¨´ó¶¼±»¹¥»÷Õß¿ÉÄÜÊìϤ.exe¡¢.docµÈ³£¼ûµÄ¿ÉÖ´ÐÐÎļþÀ©Õ¹Ãû£¬µ«²¢²»Ïàʶ.mscÎļþ£¬Òò´Ë¿ÉÄÜÔÚÏÖʵ¹¥»÷Öб¬·¢ÆæЧ£©£¬²¢ÇÒÏÖÔÚ·À»¤ÏµÍ³Ò²ÏÊÓжԴËÀàÎļþµÄÕë¶ÔÐÔ¼ì²â£¬ÒÔÊǺڿÍʹÓøÃÊÖÒÕʵÏÖ¹¥»÷µÄÀÖ³ÉÂʸߣ¬±»¼ì²âºÍ·¢Ã÷µÄ¼¸Âʵͣ¬¾ÍÏÖÔÚÎÒÃÇÊӲ쵽¹¥»÷ÓÕ¶ü£¬ÓаüÀ¨È磺¡°¡¶**ÂÛ̳¡·ÍâÉóר¼ÒÔ¼Ç뺯ÓëÎÄÕÂÆÀÉ󵥡±¡¢£º¡°ÄäÃûÉó¸åר¼Ò»ØÖ´ (УÍâ) ¡±¡¢¡°ÊÊÓÃÓÚÄϺ£µÄÁ½ÖÖÖ´·¨ÖƶÈÑо¿ (¸å¼þ)¡±¡¢¡°ÃÀ¹úÕ½ÂÔËõ¶Ì¶ÔÖж«µØÔµÕþÖεÄÓ°Ï족¡¢¡°****ÍøÂç´ó»á¡±µÈ¼«¾ßÒýÓÕÐԵĹ¥»÷£¬Ò»µ©µã»÷ÆäÖеÄMSCÎļþ£¬Æäϵͳ±ã»á±»Ö²ÈëÇÔÃÜľÂí£¬µ¼ÖÂÖ÷ÒªÃô¸ÐÊý¾Ý±»ÇÔÈ¡¡£
ͨ¹ýÎÒÃǶԹ¥»÷µÄ×·ËÝ·¢Ã÷ÔçÔÚ2024Äê4Ô£¬Kimusuky APT×éÖ¯¾Í×îÏÈʹÓÃMSCÎļþÀ´¶ÔÆäÄ¿µÄʵÑéÁË´ó×ڵĹ¥»÷£¬µ«ÆäʹÓÃÊÖ·¨ÓëGrimResourceÊÖÒÕÓÐËù²î±ð¡£ÓÉÓÚMSCÑù±¾µÄ¹ûÕæʹÓúÍÊÖÒÕÑݱäÉд¦ÓÚÉú³¤³õÆÚ£¬Òò´ËÓйع¥»÷Ñù±¾ºÍÊÖ·¨µÄת±äÖµµÃÒýÆðÒ»Á¬¹Ø×¢¡£±ðµÄ£¬OutflankÓÚ8ÔÂ13ÈÕ·¢ÎijÆGrimResourceÊÖÒÕÔ´ÓÚÆäÎäÆ÷¿â£¬ÆäÔÚ¹¥·ÀÑÝÁ·Öб»·ÀÊØ·½ÉÏ´«µ½¹«¹²É³Ïä¡£
¶þ¡¢½üÆÚÔÚÒ°¹¥»÷Ô˶¯ÆÊÎö
ͨ¹ý¶ÔÏÖÔÚÍøÂçµ½µÄ100Óà¸öMSCÑù±¾µÄÆÊÎö£¬ÎÒÃÇ·¢Ã÷×îÔçµÄʹÓÃÑù±¾·ºÆðÔÚ2024Äê4ÔÂ5ÈÕ£¬ËùÓÐÑù±¾ÖУ¬·ºÆðÔÚ4-5ÔµĹ¥»÷Ñù±¾Ö÷ÒªÊôÓÚKimusuky×éÖ¯¡£6Ôºó£¬Ëæ×ÅGrimResourceÊÖÒյĹûÕ棬MSCÃûÌõÄÑù±¾ÊýÄ¿ÒÔÔÂΪµ¥Î»³ÊÏÔ×ŵĵÝÔö¹Øϵ£¬Åú×¢ºÚ¿ÍÃÇÕýÆð¾¢Ê¹ÓúͲâÊÔÏà¹Ø¹¥»÷ÊÖÒÕ²¢×ª»¯ÎªÏÖʵ¹¥»÷¡£ÒÔÏÂÊǽü¼¸¸öÔ²¶»ñµ½µÄMSCÃûÌõĹ¥»÷Ñù±¾ÊýĿͼ¡£

ͼ1 MSC¹¥»÷Ñù±¾ÊýĿͳ¼Æͼ£¨µ¥Î»:Ô£©
ÔÚÕâÅú¹¥»÷Ñù±¾ÖУ¬ÆäÖÐһЩÊÇ»ùÓÚ¿ªÔ´ÏîÄ¿±àÒëµÄÑù±¾£¨ÈçÏÂͼÖÐͼ±êΪ¡°ÑÛ¾¦¡±µÄÑù±¾¼´Îª¿ªÔ´ÏîÄ¿MSC_DropperÌìÉú£©£¬ÕâÀàÑù±¾¿ÉÄÜÊDz¿·Ö¹¥»÷ÕßÕýÔÚÆ𾢵ؾÙÐÐÊÖÒÕ×¼±¸ºÍÃâɱ²âÊÔ¡£Í¬Ê±£¬Ò»Ð©ÕæʵµÄ¹¥»÷Ô˶¯Ò²Ô½À´Ô½ÆµÈԵطºÆð£¬ÔÚÏÖʵ¹¥»÷ÖÐÑù±¾Í¨³£»á°Ñͼ±êαװ³ÉWORD¡¢PDF¡¢MP4µÈÖÖÖÖ³£¼ûµÄÎļþÃûÌÃÓÃÒÔÒÉ»óÊܺ¦Ä¿µÄ£¬ÏÂͼÊDz¿·ÖÑù±¾¼°Í¼±êʾÀý¡£

ͼ2 ²¶»ñMSCÑù±¾Ê¾Àý
´ÓÖÐÎÒÃÇ·¢Ã÷ÁËÊýÆðÕë¶ÔÈ«Çò¶à¸ö¹ú¼ÒºÍµØÇøµÄ¹¥»÷Ô˶¯£¬Ä¿µÄÖ÷Òª°üÀ¨Öйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȣ¬¹¥»÷µÄÄ¿µÄÐÐÒµÔòÉæ¼°Õþ¸®¡¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£ÆäÖУ¬Õë¶ÔÖйúµÄAPT¹¥»÷Ô˶¯ÔÚ½üÆÚ×îÏÈÏÔ×ÅÔö¶à¡£ÔÚ7Ô³õÆÚ£¬Óйع¥»÷Ö÷ÒªÒÔ¡°Ò×·ÒëÖúÊÖ¡±¡¢¡±¶¶Òôǧ·ÛÆóÒµºÅ¡±¡¢¡°½ÌÓýÐÐÒµÊý¾Ý¡±µÈΪÓÕ¶üµÄºÚ²ú×éÖ¯¹¥»÷ΪÖ÷¡£¶øÔÚ8ÔÂÖ®ºó£¬×îÏȽÐø·ºÆðÁ˶àÆðÒÔÕþÖÎÒéÌ⡢ר¼ÒÔ¼Çë¡¢¾Û»áÈճ̡¢Í¶Ëß½¨Òé¡¢¾Ù±¨ÖÊÁϵÈÕë¶ÔÕþ¸®×éÖ¯»ò¿ÆÑв¿·ÖµÄÕë¶ÔÐÔ¹¥»÷£¬ÐèÒªÒýÆð¸ß¶ÈСÐÄ£¬²¿·ÖÓÕ¶üÎĵµÈçÏÂËùʾ¡£

ͼ3 Ö÷ÌâΪ¡°×¨¼ÒÔ¼Ç뺯¡±ÀàµÄÓÕ¶üÎĵµ

ͼ4 Ö÷ÌâΪ¡°Õþ²ßÖƶÈÑо¿¡±ÀàµÄÓÕ¶üÎĵµ
ͼ5 Ö÷ÌâΪ¡°****ÍøÂç´ó»á¡±µÄÓÕ¶üÎĵµ
ͼ6 Õë¶ÔË®ÀûÊðµÄÓÕ¶üÎĵµ
³ýÁËÕë¶ÔÖйúÒÔÍ⣬º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȶà¹úÒ²½ÓÁ¬ÔâÓöµ½Ê¹ÓÃMSCÎļþµÄ¹¥»÷Ô˶¯£¬ÆäÖÐÓÈÒÔº«¹úÔâÊܵĹ¥»÷×î¶à£¬Õâ¿ÉÄÜÓëkimsuky×éÖ¯µÄ¹¥»÷Ä¿µÄÇãÏòÓйأ¬²¿·Ö¹¥»÷Ô˶¯ÓÕ¶üÈçÏÂËùʾ¡£

ͼ7 Õë¶Ôº«¹úµÄÓÕ¶üÎĵµ

ͼ8 Õë¶ÔÔ½ÄÏʯÓ͹«Ë¾µÄÓÕ¶üÎĵµ
ÔÚÕë¶ÔÕâÅúÑù±¾¾ÙÐÐÉîÈëÆÊÎöºó£¬ÎÒÃÇ·¢Ã÷Á˹¥»÷ÕßʹÓõĶà¸ö»ù´¡ÉèÊ©£¬°üÀ¨¶à½×¶ÎÏÂÔØ·þÎñÆ÷ºÍC2·þÎñÆ÷µÈ£¬ÆäÖд󲿷ֶ¼½ÓÄÉÁËÔÆ·þÎñÀ´×ÌÈÅËÝÔ´×·×Ù£¬ÆäÖÐһЩ·þÎñÆ÷¹éÊôÓÚÃÀ¹ú¡¢ÈÕ±¾¡¢Èðµä¡¢·¨¹ú¡¢Ð¼ÓƵȹú¼Ò¡£²¿·ÖÑù±¾¼°C2·þÎñÆ÷ÈçÏÂËùʾ¡£
±í1 ¶ñÒâ·þÎñÆ÷µØµã
ͬʱ£¬ÎÒÃÇÒ²²¶»ñµ½Á˲¿·ÖÑù±¾µÄͶµÝURLµØµãÈçϱíËùʾ¡£
Èý¡¢MSCÎļþʹÓÃÊÖÒÕÔÀíÆÊÎö
MSC(Microsoft Snap-In Control)Îļþ£¬ÊÇ΢ÈíÖÎÀí¿ØÖÆ̨(MMC)ÓÃÀ´Ìí¼Ó/ɾ³ýµÄǶÈëʽÖÎÀíµ¥Î»Îļþ, ÖÎÀíԱͨ¹ý½¨Éè¿ØÖÆ̨¿ÉÒÔÖÎÀíÅÌËã»úµÄÖÖÖÖÉèÖã¬Ìí¼ÓÖÖÖÖ¹¦Ð§ÈçÓû§ÕË»§ÖÎÀí¡¢ÏµÍ³·þÎñ¡¢×°±¸Çý¶¯³ÌÐòµÈ£¬È»ºó¿ÉÒÔ½«ÕâЩÖÎÀíµ¥Î»µÄ×Ô½ç˵ÉèÖÃÒÔXMLµÄÐÎʽÉúÑĵ½´ÅÅÌÉÏ£¬¼´MSCÃûÌá£WindowsÖг£¼ûµÄ×°±¸ÖÎÀíÆ÷¡¢´ÅÅÌÖÎÀíÆ÷¡¢×éÕ½ÂÔÖÎÀíÆ÷µÈ¶¼ÊÇMSCÃûÌÃÎļþ¡£ÈçÏÂͼÊÇ×Ô½ç˵MSCÎļþµÄÖÎÀíµ¥Î»Ê¹Ãü°å½çÃ棬¹¥»÷Õß¿ÉÒÔͨ¹ý±à³ÌµÄ·½·¨ÓëMMC¾ÙÐн»»¥£¬´Ó¶ø½á¹¹×Ô½ç˵µÄ½çÃæºÍÄÚÈÝ¡£
ͼ9 MSCÎļþÖÎÀíµ¥Î»Ê¹Ãü°å
ͼ10 MSCÎļþÊÖÒÕʹÓÃÁ÷³Ìͼ
ͼ11 ʹÓ÷½·¨Ò»
ͼ12 ¿ØÖÆ̨ʹÃü°åÖ´ÐÐí§ÒâÏÂÁîʾÀý

ͼ13 ʹÃü°åÖ´ÐÐí§ÒâÏÂÁîXML
½«ActiveX¹¤¾ß¼ÓÔص½¡°ActiveX¿Ø¼þ¡±ÖÎÀíµ¥Î»ÖС£
½«HTMLÎļþ¼ÓÔص½¡°Á´½Óµ½WebµØµã¡±ÖÎÀíµ¥Î»ÖС£
ÔÚHTMLÎļþÖУ¬Ê¹ÓÃJavaScriptÓë¼ÓÔصÄActiveX¹¤¾ß¾ÙÐн»»¥¡£²¢Í¨¹ý MSXMLÒªÁ죬´¥·¢XSLת»»À´Ö´ÐÐJScript´úÂë¡£
×îºó´ÓJScript´úÂëÖÐŲÓÃϵͳº¯Êý£¬»òÕßͨ¹ý DotNetToJScript Ö´ÐÐ.NET´úÂë¡£
Ê×ÏÈ£¬ÔÚMMC³ÌÐòÖУ¬¹¥»÷Õß¿ÉÒÔ×Ô½ç˵²åÈëActiveX¿Ø¼þ¡£Í¨¹ýÎļþ±à¼Æ÷·¿ª½¨ÉèµÄMSCÎļþʱ£¬¿ÉÒÔ¿´µ½½¨ÉèµÄActiveX¿Ø¼þ´æ´¢ÔÚXMLµÄStringTableÖС£
ͼ14 ²åÈëActiveX¿Ø¼þ¹¤¾ß
µ«ÈôÊÇÏëÀֳɼÓÔع¤¾ß£¬¾ÍÒªÈƹýActiveX ¿Ø¼þµÄÇå¾²ÖÒÑÔ¡£¹¥»÷Õß½ÓÄÉÁËÒ»ÖÖÇÉÃîµÄÒªÁ죬ͨ¹ýMicrosoft Internet Explorerä¯ÀÀÆ÷×é¼þ»á¼ûexternal ¹¤¾ß£¬´Ó¶øÓëMMC¿ØÖÆ̨µÄÆäËûÔªËؾÙÐн»»¥£¬ÕâÊÇ΢Èí¹Ù·½Ö§³ÖµÄÒ»ÖÖ·½·¨¡£ÈçÏÂͼÖУ¬scopeNamespaceºÍdocObject¼´ÊÇͨ¹ýexternal.Document»ñÈ¡ÏÖÓй¤¾ß£¬¶ø·Ç½¨ÉèеÄActiveX¹¤¾ß£¬½ø¶øÈƹýÁËÖ±½Ó½¨ÉèActiveX¿Ø¼þʱµÄÇå¾²ÏÞÖÆ¡£
ͼ15 GrimResourceÊÖÒÕʹÓôúÂë
XSLTÊÇÒ»ÖÖÓÃÓÚ½«XMLÎĵµ×ª»»ÎªÆäËûÎĵµÃûÌõÄÓïÑÔ£¬XSLTÑùʽ±í£¨XSL£©Ôò½ç˵ÁËÔõÑù½«Ò»¸öXMLÎĵµ×ª»»ÎªÆäËûÐÎʽ¡£Î¢ÈíÖ§³ÖMSXML XSLTʹÓÃ
ͼ16 ¾ç±¾ÖеÄ
ËÄ¡¢°¸ÀýÆÊÎö
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøADLab½ÓÁ¬²¶»ñµ½Á˶àÆðʹÓÃMSCÎļþÕë¶ÔÈ«ÇòÄ¿µÄµÄ¹¥»÷Ô˶¯¡£ÆäÖÐÒÑ·¢Ã÷Õë¶ÔÖйú¡¢º«¹ú¡¢Ô½ÄÏ¡¢Ãɹŵȹú¼ÒµÄÕþ¸®»ú¹¹ºÍÆóÒµµÄ¹¥»÷£¬Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²úÍÅ»ïºÍºì¶ÓÕýÔÚʹÓÃÏà¹ØÊÖÒÕÔÚÈ«Çò¹æÄ£ÄÚ¾ÙÐÐÍøÂç¹¥»÷£¬°üÀ¨Kimusuky¡¢Òøºü¡¢º£Á«»¨µÈ¡£ÔÚÖî¶àµÄ¹¥»÷°¸ÀýÖУ¬ÎÒÃÇÑ¡È¡ÁËÔÚÊÖÒÕ²ãÃæ½ÏÓдú±íÐÔÇÒÏà¶ÔÃô¸ÐµÄÁ½À๥»÷Ñù±¾×÷Ϊ´Ë´ÎµÄÆÊÎö°¸Àý£¬Ê¹ÓÃGrimResourceÊÖÒÕÕë¶ÔÖйúµÄ¹¥»÷Ô˶¯£¬ÒÔ¼°Kimsuky×é֯ʹÓÃMMC¿ØÖÆ̨ʹÃü°åÕë¶Ôº«¹úµÄ×îй¥»÷Ô˶¯¡£ÏÂÃæÎÒÃǽ«¶ÔÑ¡È¡µÄÁ½¸ö°¸Àý¾ÙÐÐÉîÈëµÄÆÊÎö¡£
4.1 ÒÔÕþÖλ°ÌâΪÓÕ¶üÕë¶ÔÖйúµÄ¹¥»÷Ô˶¯
´Ë°¸ÀýʹÓõÄÊÇGrimResourceÊÖÒÕ£¬µ±Êܺ¦Õßµã»÷ÔËÐÐmscÎļþʱ£¬mmc.exe»áÖ´ÐÐÑù±¾ÖеÄjs´úÂ룬¼Ì¶øÖ´ÐÐǶÈëÔÚxmlÖеÄVBScript´úÂë¡£ÆäÖУ¬ÒýÖÂVBA´úÂëµÄÖ´ÐеÄÒªº¦µãÊÇtransforNode(xsl)ÒªÁìµÄŲÓá£
ͼ17 ÒýÖÂVBA´úÂëÖ´ÐеÄÒªº¦µã
transforNodeÒªÁì³£ÓÃÓÚ½«Ò»¸öXMLÎĵµÍ¨¹ýXSLTÑùʽ±í£¨×÷Ϊ²ÎÊý£©×ª»»ÎªÆäËûÎĵµÃûÌá£ÈôÊÇXSLTÑùʽ±íÖк¬ÓÐ
ͼ18 XSLTÑùʽ±íÄÚÈÝ
±»Ö´ÐеÄVBScript´úÂëͨ¹ý×Ô½ç˵±àÂëÏ¢ÕùÂë¡¢×Ö·û´®Æ´½Ó¡¢ÌØÊâ×Ö·û»ìÏý±àÂëµÈ»ìÏýÊÖÒÕ£¬Äܹ»ÓÐÓõØÒþ²ØÆäÕæʵÂß¼ºÍ¶ñÒâÐÐΪ£¬Í¬Ê±ÔöÌíÁËÆÊÎöÖ°Ô±¾ÙÐÐÄæÏòÆÊÎöµÄʱ¼ä±¾Ç®¡£ÏÂͼչʾÁËÔÚÊ״νâÂëÖ®ºóµÄ²¿·Ö´úÂë¿é£¬Äܹ»¿´µ½´úÂëÖÐÒÀÈ»±£´æ×ÅÆäËû»ìÏý¡£

ͼ19 »ìÏýµÄVBScript´úÂë
ÎÒÃǼÌÐø¶Ô´úÂë¾ÙÐÐÈ¥»ìÏýÒÔ¼°º¯ÊýÖØÃüÃû´¦Öóͷ£ºó£¬¿ÉÒÔ¿´µ½¾ç±¾ÏÈÊÇÉèÖÃÎļþ·¾¶ºÍĿ¼½á¹¹£¬ÔÙ´ÓXML½á¹¹ÖÐÌáÈ¡Êý¾Ý¾ÙÐÐbase64½âÂë²¢ÉúÑÄΪָ¶¨Îļþ£¨ÓÕ¶üÎĵµ£©£¬×îºó·¿ª¸ÃÎļþ¡£
ͼ20 ÊÍ·ÅÓÕ¶üÎĵµ
ÔÚ±¾°¸ÀýÖУ¬ÓÃÓÚÒÉ»óÊܺ¦ÕßµÄÊÇÈý¸öαװ³ÉWordµÄÓÕ¶üMSCÎļþ£¬ÏêϸÄÚÈÝÈçÏÂͼËùʾ¡£
ͼ21 ÓÕ¶üÎĵµÊ¾ÀýÒ»
ͼ22 ÓÕ¶üÎĵµÊ¾Àý¶þ

ͼ23 ÓÕ¶üÎĵµÊ¾ÀýÈý
½Ó×ÅÌáÈ¡Ï¢ÕùÂëÆäËûbase64Êý¾Ý£¬ÔÙ½«½âÂëºóµÄÊý¾ÝÉúÑÄΪ×îÖÕµÄWarp.exeºÍ7z.dll¿ÉÖ´ÐÐÎļþ¡£Ëæºó½«¡° t 8.8.8.8¡±×÷Ϊ²ÎÊý£¨×Ô¶¯¼ÓÔØͬĿ¼Ï¡°7z.dll¡±µÄËùÐèÌõ¼þ£©Æô¶¯Warp.exe³ÌÐò¡£
ͼ24 ÌìÉú²¢Ö´ÐÐwarp.exe³ÌÐò
¾Éó²é£¬¡°Warp.exe¡±¾ßÓÐ ¡°Lenovo (Beijing) Co., Ltd.¡±µÄÕýµ±Êý×ÖÊðÃû£¬ÆäÔÎļþÃûΪ¡°7zwrap.exe¡±¡£ÏêϸÐÅÏ¢ÈçÏÂͼËùʾ¡£
ͼ25 ¡°Warp.exe¡±ÏêϸÐÅÏ¢
µ±¶ñÒâ¡°7z.dll¡±Îļþ±»¡°Wrap.exe¡±ÀֳɼÓÔغó£¬Æä»áÔÚÄÚ´æÖжÔÖ¸¶¨Ãü¾Ý¾ÙÐнâÃÜ¡£¾ÄÚ´æÌØÕ÷ɨÃèºó£¬ÅжÏ×îÖÕ±»¼ÓÔØÖ´ÐеÄÊÇCobaltStrike£¬ÎÒÃÇÌáÈ¡³öµÄCSÉèÖÃÐÅÏ¢ÈçÏÂͼËùʾ¡£
4.2 ÒÔѧÊõÑݽ²ÎªÓÕ¶üÕë¶Ôº«¹úµÄ¹¥»÷Ô˶¯
¸Ã°¸ÀýÊÇKimsuky APTºÚ¿Í×éÖ¯ÔÚ½ñÄêËùÒýÈëµÄÒ»ÖÖÐµĹ¥»÷Õ½ÂÔ£¬¹¥»÷Õßͨ¹ýXMLµÄÉèÖÃÊôÐÔ½«MSC¶ñÒâÎļþµÄͼ±êÉèÖÃΪWordͼ±ê£¬½èÒÔαװ³ÉWORDÎĵµÀ´ÒÉ»óÊܺ¦Õß¡£
ͼ27 αװµÄWordͼ±ê
µ±Êܺ¦Õßµã»÷MSCÎļþʱ£¬Óû§ÕË»§¿ØÖÆ£¨UAC£©»áµ¯³öÇëÇóȨÏÞÑ¡Ôñ£¬ÈôÊÇÑ¡[ÊÇ]£¬Ôò»áͨ¹ýÖ´ÐÐmscÅþÁ¬³ÌÐòmmc.exe£¬Õ¹Ê¾¹¥»÷Õ߶¨ÖƵÄÃûΪ¡°?????.docx¡±µÄMicrosoftÖÎÀí¿ØÖÆ̨½çÃæ¡£ÏêϸÈçÏÂͼËùʾ¡£
ͼ28 ¡°?????.docx¡±µÄMicrosoftÖÎÀí¿ØÖÆ̨½çÃæ
±í3 ÌØÊâ·ûºÅÄÚÈÝÆÊÎö
ͼ29 º¬ÓÐÌØÊâ·ûºÅµÄcmd²ÎÊýÏÂÁîÐÐÄÚÈÝ
ͨ¹ý¸Ã·ûºÅËù¶ÔÓ¦µÄÆÊÎö¾ÙÐÐÌæ»»ºó£¬»ñµÃÁËÈçÏÂͼËùʾµÄÅú´¦Öóͷ£ÏÂÁî¡£¸Ã´®Åú´¦Öóͷ£ÏÂÁîÔòÊÇÖ´ÐÐMSCºóµÄÖÎÀí¿ØÖÆ̨¸ùʹÃü´°¿ÚµÄÏÂÁîÐвÎÊý¡£¸Ã¶ÎÏÂÁîµÄÖ÷Òª¹¦Ð§ÊÇ´ÓÖ¸¶¨URLÏÂÔØÃûΪ¡°Grieco Kavanagh Passive Supporters.docx¡±µÄÓÃÓÚαװµÄÓÕ¶üÎĵµ£¬ÒÔ¼°ºóÐø½×¶ÎµÄ¡°pest.exe¡±ºÍ¡°pest.exe.manifest¡±Îļþ¡£³ý´ËÖ®Í⣬Æ仹»á½¨ÉèÒ»¸öÃûΪ¡°TemporaryClearStatesesf¡±µÄÍýÏëʹÃü£¬Ã¿58·ÖÖÓÖ´ÐÐÒ»´Î¡°%appdata%\pest.exe¡±Îļþ¡£ÄÚÈÝÈçÏÂͼËùʾ¡£
ͼ30 cmd²ÎÊýÏÂÁîÐÐÄÚÈÝ
Éó²é¡°pest.exe¡±³ÌÐòÏêϸÐÅÏ¢£¬·¢Ã÷¸Ã³ÌÐòµÄÊý×ÖÊðÃûÃû³ÆΪ¡°Adersoft¡±£¬ÔʼÎļþÃûΪ¡°launcher.exe¡±¡£¸Ã³ÌÐòΪVBSEdit£¨ÓÉAdersoft¹«Ë¾³öÆ·µÄÒ»¿îСÇɶøÇ¿º·µÄVBScript±à¼¹¤¾ß£©¾ç±¾Æô¶¯Æ÷¡£
ͼ31 ¡°pest.exe¡±³ÌÐòÏêϸÐÅÏ¢
ͼ32 ¡°pest.exe¡±³ÌÐòÖ´Ðб¨´í
¡°pest.exe.manifest¡±ÎļþÄÚÈÝÊÇXMLÃûÌ㬶ñÒâ´úÂë°üÀ¨ÔÚ¡°¡±±êÇ©Ö®¼ä¡£¸ÃÎļþµÄÖ÷Òª¹¦Ð§ÊÇÓÉÒ»¶Î¾base64±àÂëµÄVBScript´úÂëÀ´ÊµÏÖ¡£²¿·Ö´úÂëÈçÏÂͼËùʾ¡£
ͼ33 base64±àÂëµÄVBScript´úÂë
ͼ34 batÎļþ²Ù×÷´úÂë
ÈôÊÇ¡°sim.sid¡±Îļþ²»±£´æ£¬ÔòÏòÖ¸¶¨µÄGoogle driveÁ´½Ó·¢ËÍHTTPÇëÇ󣬲¢»ñÈ¡ÏìÓ¦ÄÚÈÝ¡£
ͼ35 ÏòGoogle drive¹²ÏíÁ´½Ó·¢ËÍÇëÇó
ÀֳɻñÈ¡ºó£¬´ÓÎüÊÕµ½µÄÄÚÈÝÖÐÌáÈ¡base64±àÂëµÄÊý¾Ý£¨ÔÚ"pprbstart--"ºÍ"--pprbend"±êÇ©Ö®¼ä£©£¬×îºóÌæ»»ÌØÊâ×Ö·û²¢½«½âÂëºóµÄÊý¾ÝдÈëÖÁ¡±%appdata%\Microsoft\sif.bat"¡£
ͼ36 ÆÊÎöÏìÓ¦ÄÚÈÝ
Îå¡¢×Ü ½á
±¾ÎÄÕë¶ÔÎÒÃǽüÆÚ²¶»ñµ½µÄһϵÁлùÓÚÐÂÐÍMSCÎļþµÄ¹¥»÷Ô˶¯¾ÙÐÐÁËÆÊÎö£¬ÖصãÏÈÈÝÁËÏÖÔÚMSCÎļþÔÚҰʹÓõÄÁ½ÖÖʹÓÃÊÖÒÕÔÀí£¬Åû¶½üÆÚʹÓÃMSCÎļþµÄ¶àÆðÃô¸Ð¹¥»÷Ô˶¯£¬²¢Õë¶ÔÆäÖеÄÁ½¸ö°¸Àý¾ÙÐÐÁËÉîÈëÆÊÎö¡£´Ó½ü¼¸¸öÔÂMSCÎļþÏà¹Ø¹¥»÷µÄ»îÔ¾Ç÷ÊÆÀ´¿´£¬¹¥»÷Ô˶¯Éæ¼°µ½Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢ºÚ²ú×éÖ¯ÒÔ¼°ºì¶ÓµÈ£¬ÓÈÆäÊǽüÆÚÕë¶ÔÕþÖΡ¢¿Æ¼¼¡¢½ÌÓý¡¢Ê¯Ó͵ÈÁìÓòµÄAPT¹¥»÷×îÏÈÏÔÖøÔö¶à£¬ÐèÒªÒýÆðÏà¹ØÕþÆóºÍСÎÒ˽¼ÒÓû§µÄÖصã¹Ø×¢¡£
ÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøÆð¾¢·ÀÓùʵÑéÊÒ£¨ADLab£©
ADLab½¨ÉèÓÚ1999Ä꣬ÊÇÖйúÇå¾²ÐÐÒµ×îÔ罨ÉèµÄ¹¥·ÀÊÖÒÕÑо¿ÊµÑéÊÒÖ®Ò»£¬Î¢ÈíMAPPÍýÏë½¹µã³ÉÔ±£¬¡°ºÚȸ¹¥»÷¡±¿´·¨Ê×ÍÆÕß¡£×èÖ¹ÏÖÔÚ£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀÛ¼ÆÐû²¼Çå¾²Îó²î5000Óà¸ö£¬Ò»Á¬¼á³Ö¹ú¼ÊÍøÂçÇå¾²ÁìÓòÒ»Á÷Ë®×¼¡£ÊµÑéÊÒÑо¿Æ«Ïòº¸Ç»ù´¡Çå¾²Ñо¿¡¢Êý¾ÝÇå¾²Ñо¿¡¢5GÇå¾²Ñо¿¡¢È˹¤ÖÇÄÜÇå¾²Ñо¿¡¢Òƶ¯Çå¾²Ñо¿¡¢ÎïÁªÍøÇå¾²Ñо¿¡¢³µÁªÍøÇå¾²Ñо¿¡¢¹¤¿ØÇå¾²Ñо¿¡¢ÐÅ´´Çå¾²Ñо¿¡¢ÔÆÇå¾²Ñо¿¡¢ÎÞÏßÇå¾²Ñо¿¡¢¸ß¼¶ÍþвÑо¿¡¢¹¥·Àϵͳ½¨Éè¡£Ñо¿Ð§¹ûÓ¦ÓÃÓÚ²úÆ·½¹µãÊÖÒÕÑо¿¡¢¹ú¼ÒÖصã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢×¨ÒµÇå¾²·þÎñµÈ¡£