OG¶«·½ÌüADLab£º£ºMSCÎļþµÄÔÚÒ°ÀûÓÃÇé¿öÓëºÚ¿Í¹¥»÷»î¶¯·ÖÎö

°ä²¼¹¦·ò 2024-09-14

Ò»¡¢¡¢±³ ¾°


2024Äê6ÔÂ22ÈÕ£¬£¬Ò»¸öÀûÓÃMSCÌåʽµÄÐÂÐ͹¥»÷¼¼ÊõµÄ¶ñÒâÑù±¾³Ê´Ë¿ÌVTƽ̨ÉÏ£¬£¬´ËʱÀûÓÃÕâÖÖ¼¼ÊõµÄ¶ñÒâÑù±¾ÔÚVTÉϾùÏÔʾΪÁã¼ì²âÂÊ¡£ÕâÖÖ¼¼Êõ±»Elastic×êÑÐÍŶӶ¨ÃûΪ¡°GrimResource¡±£¬£¬Æäͨ¹ý¶ñÒâ¹¹½¨µÄMSCÎļþÔÚMicrosoftÖÎÀí½ÚÖÆÌ¨ÖÐÖ´ÐÐËÁÒâ´úÂë¡£OG¶«·½ÌüADLabÔÚ¶ûºóµÄÁ½¸öÔ¹¦·òÖУ¬£¬³ÖÐø¹Ø×¢Ê¹ÓÃÕâÖÖÀûÓÃÊÖ·¨µÄ¹¥»÷£¬£¬Í¨¹ý¼à²âµÄÁ˾ַÖÎö·¢ÏÖ£º£º×Ըü¼Êõ¹«¿ªºó£¬£¬Í¬À๥»÷ѸËÙÔö³¤£¬£¬µ½Ä¿Ç°ÎªÖ¹¿ÉÄܼà²âµ½µÄÓÐЧ¹¥»÷¼°Æä¹¥»÷Ñù±¾ÓÐ100¶àÆð¡£²¢ÇÒÓÐÔ½À´Ô½¶àµÄAPT×éÖ¯¡¢¡¢ºÚ²úÍÅ»ïºÍºì¶ÓÀûÓøü¼ÊõÔÚÈ«ÇòÁìÓòÄÚ½øÐÐÍøÂç¹¥»÷£¬£¬Ô̺¬Kimusuky¡¢¡¢Òøºü¡¢¡¢º£Á«»¨µÈ¡£Ä¿Ç°ÒÑ·¢ÏÖµÄÖ¸±êÓÐÖйú¡¢¡¢º«¹ú¡¢¡¢Ô½ÄÏ¡¢¡¢Ãɹŵȹú¶ÈÈ·µ±¾Ö»ú¹¹ºÍÆóÒµ£¬£¬Éæ¼°µ±¾Ö¡¢¡¢¿Æ¼¼¡¢¡¢½ÌÓý¡¢¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£


ÕâЩ¹¥»÷ÆÕ±éͨ¹ýMSCÎļþ×÷Ϊ¶ñÒâpayload£¬£¬Í¨¹ý¸÷À෽ʽ·¢Ë͸øÖ¸±ê²¢ÓÕʹָ±ê´ò¿ª¸ÃÎļþ¡£ÓÉÓÚMSCÌåʽµÄ¹¥»÷ÎļþÊÇÒ»ÖÖÏà¶Ôº±¼ûµÄÎļþÀàÐÍ£¨ÎÞÊý±»¹¥»÷Õß¿ÉÄÜÊìϤ.exe¡¢¡¢.docµÈ³£¼ûµÄ¿ÉÖ´ÐÐÎļþÀ©´óÃû£¬£¬µ«²¢²»Ïàʶ.mscÎļþ£¬£¬Òò¶ø¿ÉÄÜÔÚÏÖʵ¹¥»÷ÖвúÉúÆæÐ§£©£¬£¬²¢ÇÒĿǰ·À»¤ÏµÍ³Ò²ÏÊÓжԴËÀàÎļþµÄÕë¶ÔÐÔ¼ì²â£¬£¬ËùÒÔºÚ¿ÍÀûÓøü¼ÊõʵÏÖ¹¥»÷µÄ³É¹¦Âʸߣ¬£¬±»¼ì²âºÍ·¢Ïֵļ¸ÂʵÍ£¬£¬¾ÍĿǰÎÒÃǹ۲쵽¹¥»÷µö¶ü£¬£¬ÓÐÔ̺¬È磺£º¡°¡¶**ÂÛ̳¡·ÍâÉóר¼ÒÔ¼Ç뺯ÓëÎÄÕÂÆÀÉ󵥡±¡¢¡¢£º£º¡°ÄäÃûÉó¸åר¼Ò»ØÖ´ (УÍâ) ¡±¡¢¡¢¡°ºÏÓÃÓÚÄϺ£µÄÁ½ÖÖ˾·¨ÖƶÈ×êÑÐ (¸å¼þ)¡±¡¢¡¢¡°ÃÀ¹úÕ½ÊõÊÕËõ¶ÔÖж«µØÔµÕþÖεÄÓ°Ï족¡¢¡¢¡°****ÍøÂç´ó»á¡±µÈ¼«¾ßÒýÓÕÐԵĹ¥»÷£¬£¬Ò»µ©µã»÷ÆäÖеÄMSCÎļþ£¬£¬Æäϵͳ±ã»á±»Ö²ÈëÇÔÃÜľÂí£¬£¬µ¼ÖÂÖØÒªÃô¸ÐÊý¾Ý±»ÇÔÈ¡¡£


ͨ¹ýÎÒÃǶԹ¥»÷µÄ×·Òä·¢ÏÖÔçÔÚ2024Äê4Ô£¬£¬Kimusuky APT×éÖ¯¾ÍÆðÍ·ÀûÓÃMSCÎļþÀ´¶ÔÆäÖ¸±êÖ´ÐÐÁË´óÁ¿µÄ¹¥»÷£¬£¬µ«ÆäÀûÓÃÊÖ·¨ÓëGrimResource¼¼ÊõÓÐËù·ÖÆç¡£ÓÉÓÚMSCÑù±¾µÄ¹«¿ªÀûÓúͼ¼ÊõÑݱäÉд¦ÓÚ·¢Õ¹³õÆÚ£¬£¬Òò¶øÓйع¥»÷Ñù±¾ºÍÊÖ·¨µÄ±ä¶¯ÖµµÃÒýÆð³ÖÐø¹Ø×¢¡£´ËÍ⣬£¬OutflankÓÚ8ÔÂ13ÈÕ·¢ÎijÆGrimResource¼¼ÊõÔ´ÓÚÆä±øÆ÷¿â£¬£¬ÆäÔÚ¹¥·ÀÑÝÁ·Öб»·ÀÊØ·½ÉÏ´«µ½¹«¹²É³Ïä¡£


MSC(Microsoft Snap-In Control)Îļþ£¬£¬ÊÇ΢ÈíÖÎÀí½ÚÖÆÌ¨(MMC)ÓÃÀ´Ôö³¤/ɾ³ýµÄǶÈëʽÖÎÀíµ¥ÔªÎļþ, ÓÉÓÚ´ËÀàÎļþ¿ÉÄÜÖ´ÐкÅÁîºÍ¾ç±¾£¬£¬Òò¶ø¹¥»÷Õß¿ÉÄܽèÖúMSCÎļþÔÚÖ¸±êϵͳÉÏÖ´Ðи÷Àà¶ñÒ⹤×÷¡£×Ô΢ÈíĬÈÏÏÞ¶ÈÀ´×Ô»¥ÁªÍøµÄOfficeºêÎĵµºó£¬£¬LNK¡¢¡¢MSI¡¢¡¢ISOµÈÆäËûÀàÐ͵ĶñÒâÀûÓÃÊýÁ¿¾ÍÆðÍ·´ó·ùÔö³¤£¬£¬Õâ´ÎгöÏÖµÄGrimResource¼¼ÊõÒ²Ìì¾­µØÒå³ÉΪÁ˺ڿÍÃǵÄг裬£¬ÓйØMSCÑù±¾ÊýÁ¿×Ô4ÔÂÒÔÀ´³Ê¸ßËÙÔö³¤Ì¬ÊÆ¡£Òò¶ø£¬£¬OG¶«·½ÌüADLabÕë¶Ô½üÆÚ²¶»ñµ½µÄMSCÑù±¾½øÐÐÁËÉî¿ÌµÄ·ÖÎö£¬£¬±¾ÎĽ«ÖØÒª½éÉÜĿǰMSCÎļþÔÚÒ°ÀûÓü¼ÊõµÄÓйصÀÀí£¬£¬Åû¶½üÆÚÀûÓÃMSCÎļþµÄ¶àÆð¹¥»÷»î¶¯£¬£¬²¢ÖصãÕë¶ÔÆäÖеÄÁ½¸ö°¸Àý½øÐÐÉî¿Ì·ÖÎö¡£

¶þ¡¢¡¢½üÆÚÔÚÒ°¹¥»÷»î¶¯·ÖÎö



ͨ¹ý¶ÔÄ¿Ç°ÍøÂçµ½µÄ100Óà¸öMSCÑù±¾µÄ·ÖÎö£¬£¬ÎÒÃÇ·¢ÏÖ×îÔçµÄÀûÓÃÑù±¾³Ê´Ë¿Ì2024Äê4ÔÂ5ÈÕ£¬£¬ËùÓÐÑù±¾ÖУ¬£¬³Ê´Ë¿Ì4-5ÔµĹ¥»÷Ñù±¾ÖØÒªÊôÓÚKimusuky×éÖ¯¡£6Ժ󣬣¬Ëæ×ÅGrimResource¼¼ÊõµÄ¹«¿ª£¬£¬MSCÌåʽµÄÑù±¾ÊýÁ¿ÒÔÔÂΪµ¥Ôª³ÊÏÔÖøµÄµÝÔö¹ØÏµ£¬£¬Åú×¢ºÚ¿ÍÃÇÕý»ý¼«ÀûÓúͲâÊÔÓйع¥»÷¼¼Êõ²¢×ª»¯ÎªÏÖʵ¹¥»÷¡£ÒÔÏÂÊǽü¼¸¸öÔ²¶»ñµ½µÄMSCÌåʽµÄ¹¥»÷Ñù±¾ÊýÁ¿Í¼¡£


ͼƬ1.png

ͼ1 MSC¹¥»÷Ñù±¾ÊýÁ¿Í³¼ÆÍ¼£¨µ¥Ôª:Ô£©


ÔÚÕâÅú¹¥»÷Ñù±¾ÖУ¬£¬ÆäÖÐһЩÊÇ»ùÓÚ¿ªÔ´ÏîÄ¿±àÒëµÄÑù±¾£¨ÈçÏÂͼÖÐͼ±êΪ¡°ÑÛ¾¦¡±µÄÑù±¾¼´Îª¿ªÔ´ÏîÄ¿MSC_DropperÌìÉú£©£¬£¬ÕâÀàÑù±¾¿ÉÄÜÊDz¿ÃŹ¥»÷ÕßÕýÔÚ»ý¼«µØ½øÐм¼Êõ³ï±¸ºÍÃâɱ²âÊÔ¡£Í¬Ê±£¬£¬Ò»Ð©ÕæÊµµÄ¹¥»÷»î¶¯Ò²Ô½À´Ô½ÆµÈԵسöÏÖ£¬£¬ÔÚÏÖʵ¹¥»÷ÖÐÑù±¾Í¨³£»á°Ñͼ±ê¼Ù×°³ÉWORD¡¢¡¢PDF¡¢¡¢MP4µÈ¸÷Àà³£¼ûµÄÎļþÌåʽÓÃÒԹƻóÊܺ¦Ö¸±ê£¬£¬ÏÂͼÊDz¿ÃÅÑù±¾¼°Í¼±êʾÀý¡£


ͼƬ2.png

ͼ2 ²¶»ñMSCÑù±¾Ê¾Àý


´ÓÖÐÎÒÃÇ·¢ÏÖÁËÊýÆðÕë¶ÔÈ«Çò¶à¸ö¹ú¶ÈºÍµØÓòµÄ¹¥»÷»î¶¯£¬£¬Ö¸±êÖØÒªÔ̺¬Öйú¡¢¡¢º«¹ú¡¢¡¢Ô½ÄÏ¡¢¡¢ÃɹŵÈ£¬£¬¹¥»÷µÄÖ¸±êÐÐÒµÔòÉæ¼°µ±¾Ö¡¢¡¢¿Æ¼¼¡¢¡¢½ÌÓý¡¢¡¢Ê¯Ó͵ÈÃô¸ÐÐÐÒµ¡£ÆäÖУ¬£¬Õë¶ÔÖйúµÄAPT¹¥»÷»î¶¯ÔÚ½üÆÚÆðÍ·ÏÔÖøÔö¶à¡£ÔÚ7Ô³õÆÚ£¬£¬Óйع¥»÷ÖØÒªÒÔ¡°Ò×·­ÒëÖúÊÖ¡±¡¢¡¢¡±¶¶Òôǧ·ÛÆóÒµºÅ¡±¡¢¡¢¡°½ÌÓýÐÐÒµÊý¾Ý¡±µÈΪµö¶üµÄºÚ²ú×éÖ¯¹¥»÷ΪÖ÷¡£¶øÔÚ8ÔÂÖ®ºó£¬£¬ÆðÍ·Â½Ðø³öÏÖÁ˶àÆðÒÔÕþÖÎÒéÌâ¡¢¡¢×¨¼ÒÔ¼Çë¡¢¡¢»áÒéÈճ̡¢¡¢Í¶Ëß½¨Òé¡¢¡¢¾Ù±¨×ÊÁϵÈÕë¶Ôµ±¾Ö×éÖ¯»ò¿ÆÑв¿ÃŵÄÕë¶ÔÐÔ¹¥»÷£¬£¬±ØÒªÒýÆð¸ß¶È¾¯Ì裬£¬²¿Ãŵö¶üÎĵµÈçÏÂËùʾ¡£


ͼƬ3.png

ͼ3 Ö÷ÌâΪ¡°×¨¼ÒÔ¼Ç뺯¡±ÀàµÄµö¶üÎĵµ


ͼƬ4.png

ͼ4 Ö÷ÌâΪ¡°Õþ²ßÖÆ¶È×êÑС±ÀàµÄµö¶üÎĵµ


ͼƬ5.png

ͼ5 Ö÷ÌâΪ¡°****ÍøÂç´ó»á¡±µÄµö¶üÎĵµ


ͼƬ6.png

ͼ6 Õë¶ÔË®ÀûÊðµÄµö¶üÎĵµ


³ýÁËÕë¶ÔÖйúÒÔÍ⣬£¬º«¹ú¡¢¡¢Ô½ÄÏ¡¢¡¢Ãɹŵȶà¹úÒ²½ÓÁ¬Ôâ·êµ½ÀûÓÃMSCÎļþµÄ¹¥»÷»î¶¯£¬£¬ÆäÖÐÓÈÒÔº«¹úÔâ·êµÄ¹¥»÷×î¶à£¬£¬Õâ¿ÉÄÜÓëkimsuky×éÖ¯µÄ¹¥»÷Ö¸±êÆ«²îÓйØ£¬£¬²¿ÃŹ¥»÷»î¶¯µö¶üÈçÏÂËùʾ¡£


ͼƬ7.png

ͼ7 Õë¶Ôº«¹úµÄµö¶üÎĵµ


ͼƬ8.png

ͼ8 Õë¶ÔÔ½ÄÏʯÓ͹«Ë¾µÄµö¶üÎĵµ


ÔÚÕë¶ÔÕâÅúÑù±¾½øÐÐÉî¿Ì·ÖÎöºó£¬£¬ÎÒÃÇ·¢ÏÖÁ˹¥»÷ÕßʹÓõĶà¸ö»ù´¡ÉèÊ©£¬£¬Ô̺¬¶à½×¶ÎÏÂÔØ·þÎñÆ÷ºÍC2·þÎñÆ÷µÈ£¬£¬ÆäÖдó²¿ÃŶ¼Ñ¡È¡ÁËÔÆ·þÎñÀ´×ÌÈÅËÝÔ´×·×Ù£¬£¬ÆäÖÐһЩ·þÎñÆ÷¹éÊôÓÚÃÀ¹ú¡¢¡¢ÈÕ±¾¡¢¡¢Èðµä¡¢¡¢·¨¹ú¡¢¡¢ÐÂ¼ÓÆÂµÈ¹ú¶È¡£²¿ÃÅÑù±¾¼°C2·þÎñÆ÷ÈçÏÂËùʾ¡£


±í1 ¶ñÒâ·þÎñÆ÷µØÖ·

±í1-1.png

±í1-2.png


ͬʱ£¬£¬ÎÒÃÇÒ²²¶»ñµ½Á˲¿ÃÅÑù±¾µÄͶµÝURLµØÖ·ÈçϱíËùʾ¡£


±í2 Ñù±¾Í¶µÝURL

±í2-1.png

±í2-2.png


Èý¡¢¡¢MSCÎļþÀûÓü¼ÊõµÀÀí·ÖÎö


MSC(Microsoft Snap-In Control)Îļþ£¬£¬ÊÇ΢ÈíÖÎÀí½ÚÖÆÌ¨(MMC)ÓÃÀ´Ôö³¤/ɾ³ýµÄǶÈëʽÖÎÀíµ¥ÔªÎļþ, ÖÎÀíԱͨ¹ý´´½¨½ÚÖÆÌ¨Äܹ»ÖÎÀíÍÆËã»úµÄ¸÷ÀàÉèÖ㬣¬Ôö³¤¸÷ÀàÖ°ÄÜÈçÓû§ÕË»§ÖÎÀí¡¢¡¢ÏµÍ³·þÎñ¡¢¡¢É豸Çý¶¯·¨Ê½µÈ£¬£¬¶øºóÄܹ»½«ÕâЩÖÎÀíµ¥ÔªµÄ×Ô½ç˵ÅäÖÃÒÔXMLµÄ´ó¾Ö±£Áôµ½´ÅÅÌÉÏ£¬£¬¼´MSCÌåʽ¡£WindowsÖг£¼ûµÄÉ豸ÖÎÀíÆ÷¡¢¡¢´ÅÅÌÖÎÀíÆ÷¡¢¡¢×éÕ½ÊõÖÎÀíÆ÷µÈ¶¼ÊÇMSCÌåʽÎļþ¡£ÈçÏÂͼÊÇ×Ô½ç˵MSCÎļþµÄÖÎÀíµ¥Ôª¹¤×÷°å½çÃæ£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ý±à³ÌµÄ·½Ê½ÓëMMC½øÐн»»¥£¬£¬´Ó¶ø»ú¹Ø×Ô½ç˵µÄ½çÃæºÍÄÚÈÝ¡£


ͼƬ9.png

ͼ9 MSCÎļþÖÎÀíµ¥Ôª¹¤×÷°å


ÎÒÃÇÔÚ½øÒ»²½Õë¶ÔÕâÅúÑù±¾·ÖÎöºó£¬£¬·¢ÏÖĿǰMSCÌåʽÎļþµÄÔÚÒ°ÀûÓ÷½Ê½ÖØÒªÓÐÁ½ÖÖ¡£ÔÚÊܺ¦ÕßĬÈÏ¿ªÆôÓû§ÕË»§½ÚÖÆ£¨UAC£©µÄÇé¿öÏ£¬£¬µÚÒ»ÖÖÀûÓ÷½Ê½±ØÒªÓëÊܺ¦Õß½»»¥Á½´Î£¨ÖØÒªÓÉKimusuky×é֯ʹÓã©£»ÁíÒ»ÖÖÖ»Ðè½»»¥Ò»´Î(GrimResource¼¼Êõ)£¬£¬Óйؼ¼ÊõÀûÓÃÁ÷³ÌͼÈçÏÂËùʾ¡£

ͼƬ10.png

ͼ10 MSCÎļþ¼¼ÊõÀûÓÃÁ÷³Ìͼ


ÀûÓ÷½Ê½Ò»£º£ºÔÚÊܺ¦Õß´ò¿ªMSCÎļþºó£¬£¬Ê×Ïȵ¯³öUAC½ÚÖÆÑ¡Ï£¬ÈôÊÇÑ¡ÔñÊÇ£¬£¬Ôò³ÖÐøµ¯³ö¹¥»÷Õß¶¨ÖƵÄMicrosoftÖÎÀí½ÚÖÆÌ¨½çÃæÓÕµ¼Ö¸±ê£¬£¬Ò»µ©Êܺ¦Õß³ÖÐøµã»÷open´ò¿ªÎĵµ¼´»áÖÐÕУ¬£¬Ö´ÐÐcmdºÅÁî¡¢¡¢powershell¾ç±¾µÈºóÐøÀûÓý׶Ρ£

ͼƬ11.png

ͼ11 ÀûÓ÷½Ê½Ò»


¶ÔÓÚ´ËÀàÑù±¾£¬£¬¹¥»÷Õßͨ¹ý±à×ëMSCÎļþµÄ½çÃæÎ±ÔìUIÍâ¹Û£¬£¬´Ó¶øÓÕÆ­Êܺ¦Õßµã»÷½ÚÖÆÌ¨¹¤×÷°åÉϵÄÁ´½Ó£¬£¬¶ø²»»á²úÉúÒÉ»ó¡£ÕâÖÖÀûÓ÷½Ê½½èÖúÁËMMCÖеĽÚÖÆÌ¨¹¤×÷°åÖ´Ðй¥»÷£¬£¬½ÚÖÆÌ¨¹¤×÷°åÊÇÔÚMMC1.2ÖÐÒýÈëµÄ£¬£¬¹¥»÷ÕßÄܹ»½èÖú½ÚÖÆÌ¨¹¤×÷°åÀ´Ö´Ðи÷À๤×÷£¬£¬ÀýÈç´ò¿ªÊôÐÔÒ³¡¢¡¢Ö´Ðв˵¥ºÅÁî¡¢¡¢ÔËÐкÅÁîÐкʹò¿ªÍøÒ³µÈ£¬£¬Ä¿Ç°ÖØÒª·¢ÏÖKimsuky×éÖ¯ÔÚ´óÁ¿Ê¹ÓôËÀ๥»÷·½Ê½£¬£¬ÓйØÀûÓÃÑù±¾µÄ×îÔç³öÏÖ¹¦·òÊÇÔÚ½ñÄê4ÔÂ5ÈÕ£¬£¬ÀûÓÃʾÀýÈçÏÂͼËùʾ¡£

ͼƬ12.png

ͼ12 ½ÚÖÆÌ¨¹¤×÷°åÖ´ÐÐËÁÒâºÅÁîʾÀý


ͼƬ13.png

ͼ13 ¹¤×÷°åÖ´ÐÐËÁÒâºÅÁîXML


ÀûÓ÷½Ê½¶þ£º£ºGrimResource¼¼Êõ£¬£¬¸Ã¼¼ÊõÀûÓÃapds.dllÖеÄXSS·ì϶£¬£¬Í¨¹ýMSCÎļþµÄStringTable²¿ÃÅÒýÓÃÒ×Êܹ¥»÷µÄAPDS×ÊÔ´£¬£¬´Ó¶øÊµÏÖǶÈëÔÚMSCÎļþÖеÄJS´úÂëËÁÒâÖ´ÐУ¬£¬×îºóÖ´ÐÐXMLÖеľ籾´úÂë¡£Ïà½ÏÓÚÀûÓ÷½Ê½Ò»£¬£¬ÆäÓµÓÐÖÁÉٵݲȫÖҸ棬£¬ÎÞÒÉ¿ÉÄÜʹµÃ¹¥»÷µÄ³É¹¦ÂÊ´ó´óÌá¸ß¡£Í¬Ê±£¬£¬¶ÔÓںöàΪÁË·½±ã¶øÄ¬ÈÏÈ¡µÞUAC֪ͨµÄÊܺ¦ÕßÀ´Ëµ¸üÊÇÄÜ´ïµ½ÎÞ½»»¥¼´¿ÉÖ´ÐеijÉЧ¡£
¼¼ÊõÀûÓùؼüµã£º£º


  • ½«ActiveX¶ÔÏó¼ÓÔØµ½¡°ActiveX¿Ø¼þ¡±ÖÎÀíµ¥ÔªÖС£

  • ½«HTMLÎļþ¼ÓÔØµ½¡°Á´½Óµ½WebµØÖ·¡±ÖÎÀíµ¥ÔªÖС£

  • ÔÚHTMLÎļþÖУ¬£¬Ê¹ÓÃJavaScriptÓë¼ÓÔØµÄActiveX¶ÔÏó½øÐн»»¥¡£²¢Í¨¹ý MSXML²½Ö裬£¬´¥·¢XSLת»»À´Ö´ÐÐJScript´úÂë¡£

  • ×îºó´ÓJScript´úÂëÖÐŲÓÃϵͳº¯Êý£¬£¬»òÕßͨ¹ý DotNetToJScript Ö´ÐÐ.NET´úÂë¡£


Ê×ÏÈ£¬£¬ÔÚMMC·¨Ê½ÖУ¬£¬¹¥»÷ÕßÄܹ»×Ô½ç˵²åÈëActiveX¿Ø¼þ¡£Í¨¹ýÎļþ±à×ëÆ÷´ò¿ª´´½¨µÄMSCÎļþʱ£¬£¬Äܹ»¿´µ½´´½¨µÄActiveX¿Ø¼þ´æ´¢ÔÚXMLµÄStringTableÖС£


ͼƬ14.png

ͼ14 ²åÈëActiveX¿Ø¼þ¶ÔÏó


µ«ÈôÊÇÏë³É¹¦¼ÓÔØ¶ÔÏ󣬣¬¾ÍÒªÈÆ¹ýActiveX ¿Ø¼þµÄ°²È«ÖҸ档¹¥»÷ÕßѡȡÁËÒ»ÖÖÆæÃîµÄ²½Ö裬£¬Í¨¹ýMicrosoft Internet Explorerä¯ÀÀÆ÷×é¼þ½Ó¼ûexternal ¶ÔÏ󣬣¬´Ó¶øÓëMMC½ÚÖÆÌ¨µÄÆäËûÔªËØ½øÐн»»¥£¬£¬ÕâÊÇ΢Èí¹Ù·½Ö§³ÖµÄÒ»ÖÖ·½Ê½¡£ÈçÏÂͼÖУ¬£¬scopeNamespaceºÍdocObject¼´ÊÇͨ¹ýexternal.Document»ñÈ¡ÏÖÓжÔÏ󣬣¬¶ø·Ç´´½¨ÐµÄActiveX¶ÔÏ󣬣¬½ø¶øÈƹýÁËÖ±½Ó´´½¨ActiveX¿Ø¼þʱµÄ°²È«ÏÞ¶È¡£


ͼƬ15.png

ͼ15 GrimResource¼¼ÊõÀûÓôúÂë


ͬʱ£¬£¬¹¥»÷ÕßÀûÓÃÁËapds.dllµÄÒ»¸öXSS·ì϶£¬£¬´Ó¶øÄܹ»Ö´ÐÐConsole RootÖеÄJscript£¬£¬½ø¶øÔÙÖ´ÐÐXMLÖеľ籾¡£ÕâÆäÖл¹Éæ¼°µ½Ò»¸ö¼¼ÇÉ£¬£¬¼´ÀûÓÃMSXML£¨Microsoft.XMLDOM / {2933BF90-7B36-11D2-B20E-00C04F983E60} £©Ö´ÐÐXSLÎļþÖÐǶÈëµÄ¾ç±¾¡£

XSLTÊÇÒ»ÖÖÓÃÓÚ½«XMLÎĵµ×ª»»ÎªÆäËûÎĵµÌåʽµÄ˵»°£¬£¬XSLTÐÎ×´±í£¨XSL£©Ôò½ç˵ÁËÈôºÎ½«Ò»¸öXMLÎĵµ×ª»»ÎªÆäËû´ó¾Ö¡£Î¢ÈíÖ§³ÖMSXML XSLTʹÓÃÔªËØ¼°ÆäÊôÐÔimplements-prefixʵÏÖ²¢À©´óº¯ÊýÒÔÌṩ¾ç±¾¼¶Ö§³Ö¡£Òò¶ø£¬£¬¹¥»÷Õßͨ¹ýMSXMLµÄ·½Ê½¼´¿ÉÖ´ÐÐXSLÎļþÖÐǶÈëµÄ¾ç±¾£¬£¬ÈçŲÓú¯Êý XML.transformNode(xsl)£¬£¬¼´¿ÉÖ´ÐÐǶÈëµÄ¾ç±¾¼°ºóÐøµÄ¶ñÒâÀûÓÃÄ£¿£¿é£¬£¬½âÂë¾ç±¾ÖеıêÇ©ÈçÏÂͼËùʾ¡£


ͼƬ16.png

ͼ16 ¾ç±¾ÖеÄ



ËÄ¡¢¡¢°¸Àý·ÖÎö


OG¶«·½ÌüADLab½ÓÁ¬²¶»ñµ½Á˶àÆðÀûÓÃMSCÎļþÕë¶ÔÈ«ÇòÖ¸±êµÄ¹¥»÷»î¶¯¡£ÆäÖÐÒÑ·¢ÏÖÕë¶ÔÖйú¡¢¡¢º«¹ú¡¢¡¢Ô½ÄÏ¡¢¡¢Ãɹŵȹú¶ÈÈ·µ±¾Ö»ú¹¹ºÍÆóÒµµÄ¹¥»÷£¬£¬Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢¡¢ºÚ²úÍÅ»ïºÍºì¶ÓÕýÔÚÀûÓÃÓйؼ¼ÊõÔÚÈ«ÇòÁìÓòÄÚ½øÐÐÍøÂç¹¥»÷£¬£¬Ô̺¬Kimusuky¡¢¡¢Òøºü¡¢¡¢º£Á«»¨µÈ¡£ÔÚÖî¶àµÄ¹¥»÷°¸ÀýÖУ¬£¬ÎÒÃǰÎÈ¡ÁËÔÚ¼¼Êõ²ãÃæ½ÏÓдú±íÐÔÇÒÏà¶ÔÃô¸ÐµÄÁ½À๥»÷Ñù±¾×÷ΪÕâ´ÎµÄ·ÖÎö°¸Àý£¬£¬ÀûÓÃGrimResource¼¼ÊõÕë¶ÔÖйúµÄ¹¥»÷»î¶¯£¬£¬ÒÔ¼°Kimsuky×éÖ¯ÀûÓÃMMC½ÚÖÆÌ¨¹¤×÷°åÕë¶Ôº«¹úµÄ×îй¥»÷»î¶¯¡£ÏÂÃæÎÒÃǽ«¶Ô°ÎÈ¡µÄÁ½¸ö°¸Àý½øÐÐÉî¿ÌµÄ·ÖÎö¡£


4.1 ÒÔÕþÖλ°ÌâΪµö¶üÕë¶ÔÖйúµÄ¹¥»÷»î¶¯


´Ë°¸ÀýÀûÓõÄÊÇGrimResource¼¼Êõ£¬£¬µ±Êܺ¦Õßµã»÷ÔËÐÐmscÎļþʱ£¬£¬mmc.exe»áÖ´ÐÐÑù±¾ÖеÄjs´úÂ룬£¬¼Ì¶øÖ´ÐÐǶÈëÔÚxmlÖеÄVBScript´úÂë¡£ÆäÖУ¬£¬ÒýÖÂVBA´úÂëµÄÖ´ÐеĹؼüµãÊÇtransforNode(xsl)²½ÖèµÄŲÓá£


ͼƬ17.png

ͼ17 ÒýÖÂVBA´úÂëÖ´ÐеĹؼüµã


transforNode²½Öè³£ÓÃÓÚ½«Ò»¸öXMLÎĵµÍ¨¹ýXSLTÐÎ×´±í£¨×÷Ϊ²ÎÊý£©×ª»»ÎªÆäËûÎĵµÌåʽ¡£ÈôÊÇXSLTÐÎ×´±íÖк¬ÓлòÔªËØÊ±£¬£¬ÄÇÃ´ÔªËØÖеľ籾Ôò»áÔÚת»»¹ý³ÌÖб»Ö´ÐС£


ͼƬ18.png

ͼ18 XSLTÐÎ×´±íÄÚÈÝ


±»Ö´ÐеÄVBScript´úÂëͨ¹ý×Ô½ç˵±àÂëºÍ½âÂë¡¢¡¢×Ö·û´®Æ´½Ó¡¢¡¢ÌØÊâ×Ö·û»ìºÏ±àÂëµÈ»ìºÏ¼¼Êõ£¬£¬¿ÉÄÜÓÐЧµØ°µ²ØÆäÕæÊµÂß¼­ºÍ¶ñÒâÐÐΪ£¬£¬Í¬Ê±Ôö³¤ÁË·ÖÎöÈËÔ±½øÐÐÄæÏò·ÖÎöµÄ¹¦·ò³É±¾¡£ÏÂͼչʾÁËÔÚ³õ´Î½âÂëÖ®ºóµÄ²¿ÃÅ´úÂë¿é£¬£¬¿ÉÄÜ¿´µ½´úÂëÖÐÒÀÈ»´æÔÚ×ÅÆäËû»ìºÏ¡£


ͼƬ19.png

ͼ19 »ìºÏµÄVBScript´úÂë


ÎÒÃdzÖÐø¶Ô´úÂë½øÐÐÈ¥»ìºÏÒÔ¼°º¯ÊýÖØ¶¨Ãû´¦Öú󣬣¬Äܹ»¿´µ½¾ç±¾ÏÈÊÇÉèÖÃÎļþõè¾¶ºÍĿ¼½á¹¹£¬£¬ÔÙ´ÓXML½á¹¹ÖÐÌáÈ¡Êý¾Ý½øÐÐbase64½âÂë²¢±£ÁôΪָ¶¨Îļþ£¨µö¶üÎĵµ£©£¬£¬×îºó´ò¿ª¸ÃÎļþ¡£


ͼƬ20.png

ͼ20 ¿ªÊ͵ö¶üÎĵµ


ÔÚ±¾°¸ÀýÖУ¬£¬ÓÃÓڹƻóÊܺ¦ÕßµÄÊÇÈý¸ö¼Ù×°³ÉWordµÄµö¶üMSCÎļþ£¬£¬¾ßÌåÄÚÈÝÈçÏÂͼËùʾ¡£


ͼƬ21.png

ͼ21 µö¶üÎĵµÊ¾ÀýÒ»


ͼƬ22.png

ͼ22 µö¶üÎĵµÊ¾Àý¶þ


ͼƬ23.png

ͼ23 µö¶üÎĵµÊ¾ÀýÈý


½Ó×ÅÌáÈ¡ºÍ½âÂëÆäËûbase64Êý¾Ý£¬£¬ÔÙ½«½âÂëºóµÄÊý¾Ý±£ÁôΪ×îÖÕµÄWarp.exeºÍ7z.dll¿ÉÖ´ÐÐÎļþ¡£Ëæºó½«¡° t 8.8.8.8¡±×÷Ϊ²ÎÊý£¨×Ô¶¯¼ÓÔØÍ¬Ä¿Â¼Ï¡°7z.dll¡±µÄËùÐèǰÌᣩÆô¶¯Warp.exe·¨Ê½¡£


ͼƬ24.png

ͼ24 ÌìÉú²¢Ö´ÐÐwarp.exe·¨Ê½


¾­²é¿´£¬£¬¡°Warp.exe¡±ÓµÓÐ ¡°Lenovo (Beijing) Co., Ltd.¡±µÄºÏ·¨Êý×ÖÊðÃû£¬£¬ÆäÔ­ÎļþÃûΪ¡°7zwrap.exe¡±¡£¾ßÌåÐÅÏ¢ÈçÏÂͼËùʾ¡£


ͼƬ25.png

ͼ25 ¡°Warp.exe¡±¾ßÌåÐÅÏ¢


µ±¶ñÒâ¡°7z.dll¡±Îļþ±»¡°Wrap.exe¡±³É¹¦¼ÓÔØºó£¬£¬Æä»áÔÚÄÚ´æÖжÔÖ¸¶¨Êý¾Ý½øÐнâÃÜ¡£¾­ÄÚ´æÌصãɨÃèºó£¬£¬Åж¨×îÖÕ±»¼ÓÔØÖ´ÐеÄÊÇCobaltStrike£¬£¬ÎÒÃÇÌáÈ¡³öµÄCSÅäÏàÐÅÏ¢ÈçÏÂͼËùʾ¡£



ͼƬ26.png

ͼ26 CSÅäÏàÐÅÏ¢


4.2 ÒÔѧÊõÑݽ²Îªµö¶üÕë¶Ôº«¹úµÄ¹¥»÷»î¶¯


¸Ã°¸ÀýÊÇKimsuky APTºÚ¿Í×éÖ¯ÔÚ½ñÄêËùÒýÈëµÄÒ»ÖÖÐµĹ¥»÷Õ½Êõ£¬£¬¹¥»÷Õßͨ¹ýXMLµÄÉèÖÃÊôÐÔ½«MSC¶ñÒâÎļþµÄͼ±êÉèÖÃΪWordͼ±ê£¬£¬½èÒÔ¼Ù×°³ÉWORDÎĵµÀ´¹Æ»óÊܺ¦Õß¡£


ͼƬ27.png

ͼ27 ¼Ù×°µÄWordͼ±ê


µ±Êܺ¦Õßµã»÷MSCÎļþʱ£¬£¬Óû§ÕË»§½ÚÖÆ£¨UAC£©»áµ¯³öÒªÇóȨÏÞÑ¡Ôñ£¬£¬ÈôÊÇÑ¡[ÊÇ]£¬£¬Ôò»áͨ¹ýÖ´ÐÐmscÏνӷ¨Ê½mmc.exe£¬£¬Õ¹Ê¾¹¥»÷Õß¶¨ÖƵÄÃûΪ¡°?????.docx¡±µÄMicrosoftÖÎÀí½ÚÖÆÌ¨½çÃæ¡£¾ßÌåÈçÏÂͼËùʾ¡£


ͼƬ28.png

ͼ28 ¡°?????.docx¡±µÄMicrosoftÖÎÀí½ÚÖÆÌ¨½çÃæ


´úÂëÖÐÔ̺¬Ò»¶Îcmd²ÎÊýºÅÁîÐУ¬£¬ÆäÖÐʹÓÃÁËÈý¸öÍøÒ³ä¯ÀÀÆ÷¿Éʶ´ËÍâHTMLÌØÊâ·ûºÅ£¬£¬ÆäËù¶ÔÓ¦µÄ½âÎöÄÚÈÝÈçϱíËùʾ¡£


±í3 ÌØÊâ·ûºÅÄÚÈݽâÎö

±í3.png


ͼƬ29.png

ͼ29 º¬ÓÐÌØÊâ·ûºÅµÄcmd²ÎÊýºÅÁîÐÐÄÚÈÝ


ͨ¹ý¸Ã·ûºÅËù¶ÔÓ¦µÄ½âÎö½øÐдúÌæºó£¬£¬µÃµ½ÁËÈçÏÂͼËùʾµÄÅú´¦ÖúÅÁî¡£¸Ã´®Åú´¦ÖúÅÁîÔòÊÇÖ´ÐÐMSCºóµÄÖÎÀí½ÚÖÆÌ¨¸ù¹¤×÷´°¿ÚµÄºÅÁîÐвÎÊý¡£¸Ã¶ÎºÅÁîµÄÖØÒªÖ°ÄÜÊÇ´ÓÖ¸¶¨URLÏÂÔØÃûΪ¡°Grieco Kavanagh Passive Supporters.docx¡±µÄÓÃÓÚ¼Ù×°µÄµö¶üÎĵµ£¬£¬ÒÔ¼°ºóÐø½×¶ÎµÄ¡°pest.exe¡±ºÍ¡°pest.exe.manifest¡±Îļþ¡£³ý´ËÖ®Í⣬£¬Æä»¹»á´´½¨Ò»¸öÃûΪ¡°TemporaryClearStatesesf¡±µÄ´òË㹤×÷£¬£¬Ã¿58·ÖÖÓÖ´ÐÐÒ»´Î¡°%appdata%\pest.exe¡±Îļþ¡£ÄÚÈÝÈçÏÂͼËùʾ¡£


ͼƬ30.png

ͼ30 cmd²ÎÊýºÅÁîÐÐÄÚÈÝ


²é¿´¡°pest.exe¡±·¨Ê½¾ßÌåÐÅÏ¢£¬£¬·¢Ïָ÷¨Ê½µÄÊý×ÖÊðÃûÃû³ÆÎª¡°Adersoft¡±£¬£¬Ô­Ê¼ÎļþÃûΪ¡°launcher.exe¡±¡£¸Ã·¨Ê½ÎªVBSEdit£¨ÓÉAdersoft¹«Ë¾³öÆ·µÄÒ»¿îСÇɶøÇ¿º·µÄVBScript±à×빤¾ß£©¾ç±¾Æô¶¯Æ÷¡£


ͼƬ31.png

ͼ31 ¡°pest.exe¡±·¨Ê½¾ßÌåÐÅÏ¢


ÔÚ¡°pest.exe¡±·¨Ê½Æô¶¯Ê±£¬£¬»áĬÈϼÓÔØ¡°pest.exe.manifest¡±Îļþ£¬£¬. manifestÎļþÊÇWindowsÀûÓ÷¨Ê½Çåµ¥ÎļþµÄÒ»²¿ÃÅ£¬£¬³£ÓÃÓÚÖ¸¶¨ÀûÓ÷¨Ê½µÄÔËÐÐʱǰÌáºÍ»·¾³±äÁ¿µÈ¡£¹¥»÷ÕßÀûÓô˷¨Ê½µÄÔËÐлúÖÆ½«¶ñÒâ´úÂëдÈëÖÁÇåµ¥ÎļþÖУ¬£¬ÄÇôµ±¡°pest.exe¡±·¨Ê½ÔËÐÐʱ¶ñÒâ´úÂë±ã¿É±»×Ô¶¯¼ÓÔØÖ´ÐС£


ͼƬ32.png

ͼ32 ¡°pest.exe¡±·¨Ê½Ö´Ðб¨´í


 ¡°pest.exe.manifest¡±ÎļþÄÚÈÝÊÇXMLÌåʽ£¬£¬¶ñÒâ´úÂëÔ̺¬ÔÚ¡°¡±±êǩ֮¼ä¡£¸ÃÎļþµÄÖØÒªÖ°ÄÜÊÇÓÉÒ»¶Î¾­base64±àÂëµÄVBScript´úÂëÀ´ÊµÏÖ¡£²¿ÃÅ´úÂëÈçÏÂͼËùʾ¡£


ͼƬ33.png

ͼ33 base64±àÂëµÄVBScript´úÂë


½âÂëºóÎÒÃÇÄܹ»¿´µ½£¬£¬¶ñÒâ´úÂëÊ×ÏÈ»áÅжÏ"%appdata%\ Microsoft \"Ŀ¼ÏÂÊÇ·ñ´æÔÚ¡°sim.sid¡±Îļþ¡£Èô´æÔÚÇÒСÓÚ9×Ö½Ú£¬£¬Ôòɾ³ý¸ÃÎļþ²¢Í˳ö¾ç±¾£»²»È»£¬£¬½«¡°sim.sid¡±Òƶ¯ÖÁ¡±%appdata%\Microsoft\sif.bat"²¢ÔËÐÐbatÎļþ£¬£¬Ö´ÐÐʵÏÖºóɾ³ý×ÔÉíÎļþ¡£


ͼƬ34.png

ͼ34 batÎļþ²Ù×÷´úÂë


ÈôÊÇ¡°sim.sid¡±Îļþ²»´æÔÚ£¬£¬ÔòÏòÖ¸¶¨µÄGoogle driveÁ´½Ó·¢ËÍHTTPÒªÇ󣬣¬²¢»ñÈ¡ÏìÓ¦ÄÚÈÝ¡£


ͼƬ35.png

ͼ35 ÏòGoogle drive¹²ÏíÁ´½Ó·¢ËÍÒªÇó


³É¹¦»ñÈ¡ºó£¬£¬´Ó½Ó¹Üµ½µÄÄÚÈÝÖÐÌáÈ¡base64±àÂëµÄÊý¾Ý£¨ÔÚ"pprbstart--"ºÍ"--pprbend"±êǩ֮¼ä£©£¬£¬×îºó´úÌæÌØÊâ×Ö·û²¢½«½âÂëºóµÄÊý¾ÝдÈëÖÁ¡±%appdata%\Microsoft\sif.bat"¡£


ͼƬ36.png

ͼ36 ½âÎöÏìÓ¦ÄÚÈÝ


½ØÖ¹·ÖÎöʱ¸ÃGoogle drive¹²ÏíÁ´½ÓÒÑʧЧ£¬£¬ÁÙʱÎÞ·¨»ñÈ¡µ½ºóÐø½×¶ÎµÄ¹¥»÷Ñù±¾£¬£¬·ÖÎöÖÁ´ËʵÏÖ¡£


Îå¡¢¡¢×Ü ½á


±¾ÎÄÕë¶ÔÎÒÃǽüÆÚ²¶»ñµ½µÄһϵÁлùÓÚÐÂÐÍMSCÎļþµÄ¹¥»÷»î¶¯½øÐÐÁË·ÖÎö£¬£¬Öصã½éÉÜÁËĿǰMSCÎļþÔÚҰʹÓõÄÁ½ÖÖÀûÓü¼ÊõµÀÀí£¬£¬Åû¶½üÆÚÀûÓÃMSCÎļþµÄ¶àÆðÃô¸Ð¹¥»÷»î¶¯£¬£¬²¢Õë¶ÔÆäÖеÄÁ½¸ö°¸Àý½øÐÐÁËÉî¿Ì·ÖÎö¡£´Ó½ü¼¸¸öÔÂMSCÎļþÓйع¥»÷µÄ»îÔ¾Ç÷ÏòÀ´¿´£¬£¬¹¥»÷»î¶¯Éæ¼°µ½Ô½À´Ô½¶àµÄAPT×éÖ¯¡¢¡¢ºÚ²ú×éÖ¯ÒÔ¼°ºì¶ÓµÈ£¬£¬ÓÈÆäÊǽüÆÚÕë¶ÔÕþÖΡ¢¡¢¿Æ¼¼¡¢¡¢½ÌÓý¡¢¡¢Ê¯Ó͵ÈÁìÓòµÄAPT¹¥»÷ÆðÍ·ÏÔÖøÔö¶à£¬£¬±ØÒªÒýÆðÓйØÕþÆóºÍСÎÒÓû§µÄÖØµã¹Ø×¢¡£


ͬʱ£¬£¬MSCÎļþµÄ¹«¿ªÀûÓúͼ¼ÊõÑݱäÉд¦ÓÚ·¢Õ¹³õÆÚ£¬£¬Ö»¹ÜĿǰֻÊÇ·¢ÏÖÁËÁ½ÖÖÔÚÒ°ÀûÓ÷½Ê½£¬£¬µ«MMC×ÔÉí´æÔÚ²»ÉÙ°²È«Òþ»¼£¬£¬½«À´Ëæ×Ÿü¶à¹¥·À×êÑÐÈËÔ±µÄÉî¿ÌÍÚ¾ò£¬£¬¿ÉÄÜ»á³öÏÖ¸ü¶à»ùÓÚMSC»òÊÇÆäËüWindows×é¼þµÄÐÂÐͶñÒâÀûÓü¼Êõ£¬£¬OG¶«·½ÌüADLabÒ²½«³ÖÐø×·×ÙÓйؼ¼ÊõµÄ·¢Õ¹Ñݽø£¬£¬ÊµÊ±Åû¶ÓйØÍþв»î¶¯¡£


OG¶«·½Ìü»ý¼«·ÀÓù³¢ÊÔÊÒ£¨ADLab£©


ADLab³ÉÁ¢ÓÚ1999Ä꣬£¬ÊÇÖйú°²È«ÐÐÒµ×îÔç³ÉÁ¢µÄ¹¥·À¼¼Êõ×êÑг¢ÊÔÊÒÖ®Ò»£¬£¬Î¢ÈíMAPP´òËãÖ÷Ìâ³ÉÔ±£¬£¬¡°ºÚȸ¹¥»÷¡±¸ÅÄîÊ×ÍÆÕß¡£½ØÖÁĿǰ£¬£¬ADLabÒÑͨ¹ý CNVD/CNNVD/NVDB/CVEÀۼư䲼°²È«·ì϶5000Óà¸ö£¬£¬³ÖÐøÎ¬³Ö¹ú¼ÊÍøÂ簲ȫÁìÓòÒ»Á÷Ë®×¼¡£³¢ÊÔÊÒ×êÑз½Ïòº­¸Ç»ù´¡°²È«×êÑС¢¡¢Êý¾Ý°²È«×êÑС¢¡¢5G°²È«×êÑС¢¡¢ÈËΪÖÇÄܰ²È«×êÑС¢¡¢Òƶ¯°²È«×êÑС¢¡¢ÎïÁªÍø°²È«×êÑС¢¡¢³µÁªÍø°²È«×êÑС¢¡¢¹¤¿Ø°²È«×êÑС¢¡¢ÐÅ´´°²È«×êÑС¢¡¢Ôư²È«×êÑС¢¡¢ÎÞÏß°²È«×êÑС¢¡¢¸ß¼¶Íþв×êÑС¢¡¢¹¥·Àϵͳ½¨Éè¡£×êÑгɾÍÀûÓÃÓÚ²úÆ·Ö÷Ìâ¼¼Êõ×êÑС¢¡¢¹ú¶ÈÖØµã¿Æ¼¼ÏîÄ¿¹¥¹Ø¡¢¡¢×¨Òµ°²È«·þÎñµÈ¡£



adlab.jpg