8827Ì«Ñô¼¯ÍÅÌáÐÑ£º¾¯Ìè·ÂðDeepSeek×°ÖðüͶµÝWannaCryÀÕË÷Èí¼þ
°ä²¼¹¦·ò 2025-03-14¡°ÈÃÿһ¾äÈË»ú¶Ô»°¶¼°²È«¿ÉÐÅ£¬£¬£¬£¬£¬£¬£¬ÈÃÿһ´ÎÖÇÄܽ»»¥¶¼·çÏտɿءª¡ªÕâÊÇÊôÓÚAIʱÆÚµÄ°²È«³Ðŵ¡£¡£¡£¡£¡£ ¡ª¡ª 8827Ì«Ñô¼¯ÍÅ¡±
AIËÙÀÀ£º
±¾ÎÄ»áÉÌÁË2025ÄêËæ×ÅDeepSeek-R1°ä²¼Òý·¢´óÄ£Ðͱ¾µØ»¯²¿Ê𺣳±ºó£¬£¬£¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅVenusEyeÍþвµý±¨ÖÐÐÄ·¢ÏÖÀÕË÷Èí¼þÍÅ»ïÀûÓ÷ÂðDeepSeek×°Öðü½øÐй¥»÷µÄÇé¿ö£¬£¬£¬£¬£¬£¬£¬×êÑÐÍŶӷÖÎöÁËÑù±¾²¢¸ø³öÓйØÐÅÏ¢¡£¡£¡£¡£¡£¹Ø¼üÖØµãÔ̺¬:
1.¹¥»÷¼¿Á©:ºÚ¿ÍÀûÓ÷ÂðDeepSeek×°Öðü(Install_DeepSeek.exe)¹¥»÷£¬£¬£¬£¬£¬£¬£¬×Ô½âѹ¿ªÊÍWannaCryÀÕË÷Èí¼þºÍWindows XPHorror²¡¶¾¡£¡£¡£¡£¡£
2.Ñù±¾ÐÅÏ¢:³õʼ·Âð·¨Ê½Install_DeepSeek.exe£¬£¬£¬£¬£¬£¬£¬Îļþ´óÓ×56.07MB£¬£¬£¬£¬£¬£¬£¬ÓÉ2¸öexe·¨Ê½´ò°ü×é³É£¬£¬£¬£¬£¬£¬£¬Í¨¹ýSFX¾ç±¾Ö¸¶¨¿ªÊÍõè¾¶£¬£¬£¬£¬£¬£¬£¬¿ªÊÍtasksche.exeºÍSETUP.EXEµ½C:\WINDOWSÎļþ¼Ð¡£¡£¡£¡£¡£
3.¶ñÒⷨʽְÄÜ:tasksche.exe¿ªÊÍWannaCryÄ£¿£¿£¿£¿£¿£¿£¿é¼ÓÃÜÎļþ;._cache tasksche.exe½âѹËõÄ£¿£¿£¿£¿£¿£¿£¿é¡¢½âÃܲ¢Ö´ÐÐDLL;DLL¼ÓÃÜÌØ¶¨ºó׺Îļþ;SETUP.EXE (Windows XP Horror²¡¶¾)Åú¸Ä´ÅÅÌMBR£¬£¬£¬£¬£¬£¬£¬¸ü¸ÄµÇ¼½çÃæ¡£¡£¡£¡£¡£
4.¼ÓÃÜÎļþºó׺:±»¼ÓÃÜÎļþºó׺¶à¶à£¬£¬£¬£¬£¬£¬£¬¼ÓÃܺó×·¼Ó.WNCRYºó׺£¬£¬£¬£¬£¬£¬£¬Ã¿¸öÎļþ¼Ð¿ªÊÍÀÕË÷ÐźͲ¿ÃÅ»¯ÃÜ·¨Ê½¡£¡£¡£¡£¡£
5.ËÝÔ´¹ØÁª:ͨ¹ý±ÈÌØ±ÒÂòÂôµØÖ··¢ÏÖ¸Ã×éÖ¯³ÖÐøÓ¯Àû£¬£¬£¬£¬£¬£¬£¬ÀۼƻñÀûÔ¼54BTC£¬£¬£¬£¬£¬£¬£¬³¬Ç§ÍòÔªÈËÃñ±Ò£¬£¬£¬£¬£¬£¬£¬Í¬Ê±»¹¹ØÁªµ½¶à¸öÓйØÑù±¾¡£¡£¡£¡£¡£
2025Ä꣬£¬£¬£¬£¬£¬£¬Ëæ×ÅDeepSeek-R1µÄ°ä²¼£¬£¬£¬£¬£¬£¬£¬Ñ¸ËÙÒý·¢´óÄ£Ðͱ¾µØ»¯²¿Ê𺣳±¡£¡£¡£¡£¡£Ç°ËùδÓеĹØ×¢¶ÈÒ²ÎüÀÕË÷Èí¼þÍÅ»ïÒ²½ô¸úÈȵ㣬£¬£¬£¬£¬£¬£¬´î½¨´¹µöÍøÕ¾£¬£¬£¬£¬£¬£¬£¬¼Ù×°³ÉºÏ·¨µÄAIÈí¼þÏÂÔØÆ½Ì¨£¬£¬£¬£¬£¬£¬£¬ÓÕµ¼Óû§×°Öðó¸¿ÀÕË÷Èí¼þµÄ·ÂðÈí¼þ£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¶ÔÊܺ¦Ö÷»úÉϵÄÎļþ½øÐмÓÃÜ£¬£¬£¬£¬£¬£¬£¬ÒÔвÆÈÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£
¼¼Êõ·ÖÎö
Õâ´Î¹¥»÷»î¶¯µÄÑù±¾ÊǼÙ×°³ÉDeepSeek×°ÖðüµÄexeÎļþ£¬£¬£¬£¬£¬£¬£¬¸ÃÎļþÖ´Ðк󣬣¬£¬£¬£¬£¬£¬Í¨¹ý×Ô½âѹ·½Ê½¿ªÊͳöÀÕË÷Èí¼þWannaCryºÍ¿Ö²À²¡¶¾Windows XP Horror£¬£¬£¬£¬£¬£¬£¬±ðÀëÖ´ÐÐÕâ2¸ö¶ñÒⷨʽ¡£¡£¡£¡£¡£WannaCry¿ªÊͳöÀÕË÷Ö°ÄÜÄ£¿£¿£¿£¿£¿£¿£¿é²¢Ö´ÐУ¬£¬£¬£¬£¬£¬£¬¼ÓÃÜÌØ¶¨ºó׺µÄÎļþ£¬£¬£¬£¬£¬£¬£¬¿ªÊͳöÀÕË÷ÐÅ¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿Ö²À²¡¶¾Windows XP HorrorÅú¸Ä´ÅÅÌMBR£¬£¬£¬£¬£¬£¬£¬½«µÇ¼½çÃæÉèÖÃΪ÷¼÷ÃͼÏñ²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£¡£
¸ÃÑù±¾ÕûÌåÁ÷³ÌÈçÏÂͼËùʾ£º

1¡¢³õʼ·Âð·¨Ê½
¸ÃÑù±¾Îª¼Ù×°³ÉDeepSeek×°Ö÷¨Ê½µÄexeÎļþ£¬£¬£¬£¬£¬£¬£¬ÆäÑù±¾ÐÅÏ¢¼ûÏÂ±í£º

³õʼ¹¥»÷Îļþ·ÂðÁËDeepSeekµÄͼ±ê£¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

¸ÃexeÎļþÊôÓÚWinrar SFX×Ô½âѹÎļþ£¬£¬£¬£¬£¬£¬£¬ÓÉ2¸öexe·¨Ê½´ò°ü¶ø³É£¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

¶ñÒâÈí¼þͨ¹ýSFX¾ç±¾Ö¸¶¨tasksche.exeºÍSETUP.EXEµÄ¿ªÊÍõè¾¶£¬£¬£¬£¬£¬£¬£¬SFX¾ç±¾ÄÚÈÝÔ̺¬¡°DeepSeek¡±ÓйØÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

ͨ¹ýÓû§µã»÷´¥·¢SFX¶ñÒâÎļþºó£¬£¬£¬£¬£¬£¬£¬»á½«tasksche.exeºÍSETUP.EXE¿ªÊ͵½C:\WINDOWSÎļþ¼ÐÖУº

ͬʱװÖÃÖ´ÐÐtasksche.exeºÍSETUP.EXE£º

2¡¢ tasksche.exe
tasksche.exeÓÉDelphi˵»°¿ª·¢£¬£¬£¬£¬£¬£¬£¬ÆäÖ°ÄÜÊÇ¿ªÊÍWannaCryÀÕË÷Èí¼þµÄÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬ÊµÏÖÎļþ¼ÓÃÜÀÕË÷Ö°ÄÜ¡£¡£¡£¡£¡£Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º

tasksche.exeµÄ×ÊÔ´ÎļþÖÐÔ̺¬Ò»¸öEXE·¨Ê½£¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

tasksche.exeÆô¶¯ºó£¬£¬£¬£¬£¬£¬£¬Ê×ÏÈ»á¼ÓÔØ¸Ã×ÊÔ´£¬£¬£¬£¬£¬£¬£¬»ñÈ¡×ÊÔ´ÄÚÈÝ¡£¡£¡£¡£¡£¶øºó´´½¨Îļþ C:\WINDOWS\._cache_tasksche.exe£¬£¬£¬£¬£¬£¬£¬²¢½«×ÊÔ´ÖеÄÊý¾ÝдÈë¸ÃÎļþÖУ¬£¬£¬£¬£¬£¬£¬×îÖÕÖ´ÐиÃÎļþ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

3¡¢ ._cache_tasksche.exe
._cache_tasksche.exeÎļþµÄÑù±¾ÐÅÏ¢¼ûÏÂ±í£º

._cache_tasksche.exeµÄÖØÒªÖ°ÄÜÊÇ´Ó×ÊÔ´ÖнâѹËõ³öÖ°ÄÜÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬½âÃܳö1¸öDLL²¢Ö´ÐÐÆäÌØ¶¨µÄµ¼³öº¯Êý¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

Ê×ÏÈÔÚ×¢²á±íHKLM\Software\WanaCrypt0r\wd ÖÐдÈ뵱ǰõè¾¶£¬£¬£¬£¬£¬£¬£¬¼Í¼¹ý³ÌµÄ¹¤×÷Ŀ¼(work directory)£¬£¬£¬£¬£¬£¬£¬¹©ÆäËüÄ£¿£¿£¿£¿£¿£¿£¿éʹÓᣡ£¡£¡£¡£ÈçÏÂͼËùʾ£º

Åú¸ÄºóµÄ×¢²á±íÈçÏÂͼËùʾ£º

¶øºóʹÓÃÃÜÔ¿¡°WNcry@2ol7¡±½«Ç¶ÈëÔÚ×ÊÔ´ÖеÄzipѹËõ°ü½âѹµ½C:\WINDOWS¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

×ÊÔ´ÖеÄzipѹËõ°üÈçÏÂͼËùʾ£º

¸ÃѹËõ°üÖÐÓжà¸öÎļþ£¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

¶ÁÈ¡Îļþ t.wnry µÄÄÚÈݲ¢½âÃܳöDLLÎļþ£¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

½âÃܳöµÄDLLÎļþÊÇÀÕË÷Ä£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÃûΪTaskStartµÄµ¼³öº¯Êý£¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

ͨ¹ýŲÓøõ¼³öº¯Êý£¬£¬£¬£¬£¬£¬£¬Ö´ÐмÓÃÜÀÕË÷Ö°ÄÜ¡£¡£¡£¡£¡£
4¡¢ÀÕË÷Ä£¿£¿£¿£¿£¿£¿£¿é
ÉÏÒ»½×¶Î½âÃܳöµÄDLLÎļþµÄÔʼÃû³ÆÎªkgptbeilcq£¬£¬£¬£¬£¬£¬£¬ÕƹÜʵÏÖ¾ßÌåµÄ¼ÓÃÜÀÕË÷Ö°ÄÜ¡£¡£¡£¡£¡£Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º

¸ÃDLLµÄÖØÒªÖ°ÄÜÈçÏÂͼËùʾ£º

Ê×ÏÈÖÕÖ¹Êý¾Ý¿âÓйعý³Ì£¬£¬£¬£¬£¬£¬£¬Ê¹µÃ¿ÉÄܼÓÃÜÊý¾Ý¿âÎļþ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

»ñÈ¡´ÅÅÌÇý¶¯Æ÷Ãû³Æ£¬£¬£¬£¬£¬£¬£¬±éÀú¸÷´ÅÅÌ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

±éÀúÎļþ¼Ð£¬£¬£¬£¬£¬£¬£¬²é³ÎļþµÄÃû³ÆºÍºó׺£¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

¼ÓÃÜÒÔϺó׺ÃûµÄÎļþ£º

Îļþ±»¼ÓÃܺ󣬣¬£¬£¬£¬£¬£¬»á±»×·¼Óºó׺Ãû .WNCRY¡£¡£¡£¡£¡£
ÔÚÿ¸öÎļþ¼ÐÖпªÊÍÃûΪ @Please_Read_Me@.txt µÄÀÕË÷ÐźÍÃûΪ @WanaDecryptor@.exe µÄ½âÃÜ·¨Ê½¡£¡£¡£¡£¡£ÀÕË÷ÐÅÄÚÈÝÈçÏÂͼËùʾ£º

Êܺ¦Õßͨ¹ý½âÃÜ·¨Ê½ @WanaDecryptor@.exe£¬£¬£¬£¬£¬£¬£¬Äܹ»½âÃܳö10¸ö±»¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£¸Ã½âÃÜ·¨Ê½ÏÔʾÁËÌáÐÑÐÅÏ¢ºÍ±ÈÌØ±ÒµØÖ·£¬£¬£¬£¬£¬£¬£¬²¢½øÐе¹¼ÆÊ±¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

5¡¢SETUP.EXE
SETUP.EXEÊǹÅÀϵÄWindowsXP Horror²¡¶¾£¬£¬£¬£¬£¬£¬£¬¸Ã²¡¶¾»áÅú¸Ä´ÅÅÌMBR£¬£¬£¬£¬£¬£¬£¬½«µÇ¼½çÃæÅú¸ÄΪ÷¼÷ÃͼÏñ£¬£¬£¬£¬£¬£¬£¬²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£¡£
Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º

Ñù±¾Ö´Ðк󣬣¬£¬£¬£¬£¬£¬Ê×ÏÈÍ˳öµÇ¼½çÃæ£¬£¬£¬£¬£¬£¬£¬ÏÔʾ¡°Installing Windows Updates¡±µÈÌáÐÑ£¬£¬£¬£¬£¬£¬£¬ÔÚ½ø¶Èµ½66%ʱ£¬£¬£¬£¬£¬£¬£¬»áµ¯³ö¡°Setup will use the file 666.sys¡±µÄÌáÐÑ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

µÇ¼½çÃæ»á±»»»³É÷¼÷ÃͼÏñ£¬£¬£¬£¬£¬£¬£¬²»ÐÝÇл»ÑªÐÈͼƬ£¬£¬£¬£¬£¬£¬£¬²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£¡£
µã»÷×ÀÃæµÄͼ±êºó£¬£¬£¬£¬£¬£¬£¬»áµ¯³öÌáÐÑ¿ò£¬£¬£¬£¬£¬£¬£¬²¢°Ñͼ±êÒÆ¶¯µ½»ØÊÕÕ¾¡£¡£¡£¡£¡£
²Ù×÷ϵͳ±ÀÀ£²¢ÏÔʾºìÉ«²¼¾°£¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

ËÝÔ´¹ØÁª
1. ͨ¹ý¶Ô¸Ã×éÖ¯ÌṩµÄ±ÈÌØ±ÒÂòÂôµØÖ·£¬£¬£¬£¬£¬£¬£¬¸ú×Ùµ½¸Ã×éÖ¯ÔÚ2024ËêĺÊÕµ½¼¸±ÊÊܺ¦ÕßÖ§¸¶µÄBTC¡£¡£¡£¡£¡£×¢Ã÷¸Ã×éÖ¯ÈÔ¾ÉÔÚÒÀ¸½ÀÕË÷Èí¼þ³ÖÐøÓ¯Àû£º


ͬʱͨ¹ý¶Ôº¹ÇàÐÅÏ¢µÄͳ¼Æ£¬£¬£¬£¬£¬£¬£¬Äܹ»¹Û²âµ½¸Ã×éÖ¯ÔÚÅû¶µÄµØÖ·ÉÏÀۼƻñÀûÔ¼54BTC£¬£¬£¬£¬£¬£¬£¬°´µ±Ç°»ãÂʹÀËãÒѳ¬¹ýǧÍòÔªÈËÃñ±Ò¡£¡£¡£¡£¡£
2. ͨ¹ý¶Ô³õʼÑù±¾µÄÌØµã½øÐйØÁª£¬£¬£¬£¬£¬£¬£¬·¢ÏÖÒÔÏÂÓë±¾´Î¹¥»÷»î¶¯ÓйصÄÑù±¾£º
MD5£º
c27fc192811dad928730b24fd8150a03
2e5f24942932190e577319a7e81b83e4
33e884e59a7c1e1d6af5b19a283a04a7
4d4f7bfac3a17767cb9a7f88737b7ef5
061a8f66ec2f86f9668c0c157ed54b6c
5a02e019a2a7920d0b23326a616bf88f
a7389982054233436020f0ada0765a48
ATT&CK
¸ÃÑù±¾ËùѡȡµÄ¹¥»÷¼¼Õ½·¨ÓëATT&CKµÄÓ³ÉäÈçϱíËùʾ£º

IoCs



¾©¹«Íø°²±¸11010802024551ºÅ