8827Ì«Ñô¼¯ÍÅÌáÐÑ£º¾¯Ìè·ÂðDeepSeek×°ÖðüͶµÝWannaCryÀÕË÷Èí¼þ

°ä²¼¹¦·ò 2025-03-14

¡°ÈÃÿһ¾äÈË»ú¶Ô»°¶¼°²È«¿ÉÐÅ£¬ £¬ £¬£¬£¬£¬£¬ÈÃÿһ´ÎÖÇÄܽ»»¥¶¼·çÏտɿءª¡ªÕâÊÇÊôÓÚAIʱÆÚµÄ°²È«³Ðŵ¡£¡£¡£¡£¡£ ¡ª¡ª 8827Ì«Ñô¼¯ÍÅ¡±


AIËÙÀÀ£º


±¾ÎÄ»áÉÌÁË2025ÄêËæ×ÅDeepSeek-R1°ä²¼Òý·¢´óÄ£Ðͱ¾µØ»¯²¿Ê𺣳±ºó£¬ £¬ £¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅVenusEyeÍþвµý±¨ÖÐÐÄ·¢ÏÖÀÕË÷Èí¼þÍÅ»ïÀûÓ÷ÂðDeepSeek×°Öðü½øÐй¥»÷µÄÇé¿ö£¬ £¬ £¬£¬£¬£¬£¬×êÑÐÍŶӷÖÎöÁËÑù±¾²¢¸ø³öÓйØÐÅÏ¢¡£¡£¡£¡£¡£¹Ø¼üÖØµãÔ̺¬:

1.¹¥»÷¼¿Á©:ºÚ¿ÍÀûÓ÷ÂðDeepSeek×°Öðü(Install_DeepSeek.exe)¹¥»÷£¬ £¬ £¬£¬£¬£¬£¬×Ô½âѹ¿ªÊÍWannaCryÀÕË÷Èí¼þºÍWindows XPHorror²¡¶¾¡£¡£¡£¡£¡£

2.Ñù±¾ÐÅÏ¢:³õʼ·Âð·¨Ê½Install_DeepSeek.exe£¬ £¬ £¬£¬£¬£¬£¬Îļþ´óÓ×56.07MB£¬ £¬ £¬£¬£¬£¬£¬ÓÉ2¸öexe·¨Ê½´ò°ü×é³É£¬ £¬ £¬£¬£¬£¬£¬Í¨¹ýSFX¾ç±¾Ö¸¶¨¿ªÊÍõè¾¶£¬ £¬ £¬£¬£¬£¬£¬¿ªÊÍtasksche.exeºÍSETUP.EXEµ½C:\WINDOWSÎļþ¼Ð¡£¡£¡£¡£¡£

3.¶ñÒⷨʽְÄÜ:tasksche.exe¿ªÊÍWannaCryÄ£¿£¿£¿£¿£¿£¿£¿é¼ÓÃÜÎļþ;._cache tasksche.exe½âѹËõÄ£¿£¿£¿£¿£¿£¿£¿é¡¢½âÃܲ¢Ö´ÐÐDLL;DLL¼ÓÃÜÌØ¶¨ºó׺Îļþ;SETUP.EXE (Windows XP Horror²¡¶¾)Åú¸Ä´ÅÅÌMBR£¬ £¬ £¬£¬£¬£¬£¬¸ü¸ÄµÇ¼½çÃæ¡£¡£¡£¡£¡£

4.¼ÓÃÜÎļþºó׺:±»¼ÓÃÜÎļþºó׺¶à¶à£¬ £¬ £¬£¬£¬£¬£¬¼ÓÃܺó×·¼Ó.WNCRYºó׺£¬ £¬ £¬£¬£¬£¬£¬Ã¿¸öÎļþ¼Ð¿ªÊÍÀÕË÷ÐźͲ¿ÃÅ»¯ÃÜ·¨Ê½¡£¡£¡£¡£¡£

5.ËÝÔ´¹ØÁª:ͨ¹ý±ÈÌØ±ÒÂòÂôµØÖ··¢ÏÖ¸Ã×éÖ¯³ÖÐøÓ¯Àû£¬ £¬ £¬£¬£¬£¬£¬ÀۼƻñÀûÔ¼54BTC£¬ £¬ £¬£¬£¬£¬£¬³¬Ç§ÍòÔªÈËÃñ±Ò£¬ £¬ £¬£¬£¬£¬£¬Í¬Ê±»¹¹ØÁªµ½¶à¸öÓйØÑù±¾¡£¡£¡£¡£¡£


2025Ä꣬ £¬ £¬£¬£¬£¬£¬Ëæ×ÅDeepSeek-R1µÄ°ä²¼£¬ £¬ £¬£¬£¬£¬£¬Ñ¸ËÙÒý·¢´óÄ£Ðͱ¾µØ»¯²¿Ê𺣳±¡£¡£¡£¡£¡£Ç°ËùδÓеĹØ×¢¶ÈÒ²ÎüÀÕË÷Èí¼þÍÅ»ïÒ²½ô¸úÈȵ㣬 £¬ £¬£¬£¬£¬£¬´î½¨´¹µöÍøÕ¾£¬ £¬ £¬£¬£¬£¬£¬¼Ù×°³ÉºÏ·¨µÄAIÈí¼þÏÂÔØÆ½Ì¨£¬ £¬ £¬£¬£¬£¬£¬ÓÕµ¼Óû§×°Öðó¸¿ÀÕË÷Èí¼þµÄ·ÂðÈí¼þ£¬ £¬ £¬£¬£¬£¬£¬´Ó¶ø¶ÔÊܺ¦Ö÷»úÉϵÄÎļþ½øÐмÓÃÜ£¬ £¬ £¬£¬£¬£¬£¬ÒÔвÆÈÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£


¼¼Êõ·ÖÎö


Õâ´Î¹¥»÷»î¶¯µÄÑù±¾ÊǼÙ×°³ÉDeepSeek×°ÖðüµÄexeÎļþ£¬ £¬ £¬£¬£¬£¬£¬¸ÃÎļþÖ´ÐÐºó£¬ £¬ £¬£¬£¬£¬£¬Í¨¹ý×Ô½âѹ·½Ê½¿ªÊͳöÀÕË÷Èí¼þWannaCryºÍ¿Ö²À²¡¶¾Windows XP Horror£¬ £¬ £¬£¬£¬£¬£¬±ðÀëÖ´ÐÐÕâ2¸ö¶ñÒⷨʽ¡£¡£¡£¡£¡£WannaCry¿ªÊͳöÀÕË÷Ö°ÄÜÄ£¿£¿£¿£¿£¿£¿£¿é²¢Ö´ÐУ¬ £¬ £¬£¬£¬£¬£¬¼ÓÃÜÌØ¶¨ºó׺µÄÎļþ£¬ £¬ £¬£¬£¬£¬£¬¿ªÊͳöÀÕË÷ÐÅ¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿Ö²À²¡¶¾Windows XP HorrorÅú¸Ä´ÅÅÌMBR£¬ £¬ £¬£¬£¬£¬£¬½«µÇ¼½çÃæÉèÖÃΪ÷¼÷ÃͼÏñ²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£¡£


¸ÃÑù±¾ÕûÌåÁ÷³ÌÈçÏÂͼËùʾ£º


ͼƬ1.png


1¡¢³õʼ·Âð·¨Ê½


¸ÃÑù±¾Îª¼Ù×°³ÉDeepSeek×°Ö÷¨Ê½µÄexeÎļþ£¬ £¬ £¬£¬£¬£¬£¬ÆäÑù±¾ÐÅÏ¢¼ûÏÂ±í£º


ͼƬ2.png


³õʼ¹¥»÷Îļþ·ÂðÁËDeepSeekµÄͼ±ê£¬ £¬ £¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ3.png

¸ÃexeÎļþÊôÓÚWinrar SFX×Ô½âѹÎļþ£¬ £¬ £¬£¬£¬£¬£¬ÓÉ2¸öexe·¨Ê½´ò°ü¶ø³É£¬ £¬ £¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ4.png


¶ñÒâÈí¼þͨ¹ýSFX¾ç±¾Ö¸¶¨tasksche.exeºÍSETUP.EXEµÄ¿ªÊÍõè¾¶£¬ £¬ £¬£¬£¬£¬£¬SFX¾ç±¾ÄÚÈÝÔ̺¬¡°DeepSeek¡±ÓйØÐÅÏ¢£¬ £¬ £¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ5.png


ͨ¹ýÓû§µã»÷´¥·¢SFX¶ñÒâÎļþºó£¬ £¬ £¬£¬£¬£¬£¬»á½«tasksche.exeºÍSETUP.EXE¿ªÊ͵½C:\WINDOWSÎļþ¼ÐÖУº


ͼƬ6.png


ͬʱװÖÃÖ´ÐÐtasksche.exeºÍSETUP.EXE£º


ͼƬ7.png


2¡¢ tasksche.exe


tasksche.exeÓÉDelphi˵»°¿ª·¢£¬ £¬ £¬£¬£¬£¬£¬ÆäÖ°ÄÜÊÇ¿ªÊÍWannaCryÀÕË÷Èí¼þµÄÄ£¿£¿£¿£¿£¿£¿£¿é£¬ £¬ £¬£¬£¬£¬£¬ÊµÏÖÎļþ¼ÓÃÜÀÕË÷Ö°ÄÜ¡£¡£¡£¡£¡£Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º


ͼƬ8.png


tasksche.exeµÄ×ÊÔ´ÎļþÖÐÔ̺¬Ò»¸öEXE·¨Ê½£¬ £¬ £¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ9.png


tasksche.exeÆô¶¯ºó£¬ £¬ £¬£¬£¬£¬£¬Ê×ÏÈ»á¼ÓÔØ¸Ã×ÊÔ´£¬ £¬ £¬£¬£¬£¬£¬»ñÈ¡×ÊÔ´ÄÚÈÝ¡£¡£¡£¡£¡£¶øºó´´½¨Îļþ C:\WINDOWS\._cache_tasksche.exe£¬ £¬ £¬£¬£¬£¬£¬²¢½«×ÊÔ´ÖеÄÊý¾ÝдÈë¸ÃÎļþÖУ¬ £¬ £¬£¬£¬£¬£¬×îÖÕÖ´ÐиÃÎļþ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ10.png


3¡¢ ._cache_tasksche.exe


._cache_tasksche.exeÎļþµÄÑù±¾ÐÅÏ¢¼ûÏÂ±í£º


ͼƬ11.png


._cache_tasksche.exeµÄÖØÒªÖ°ÄÜÊÇ´Ó×ÊÔ´ÖнâѹËõ³öÖ°ÄÜÄ£¿£¿£¿£¿£¿£¿£¿é£¬ £¬ £¬£¬£¬£¬£¬½âÃܳö1¸öDLL²¢Ö´ÐÐÆäÌØ¶¨µÄµ¼³öº¯Êý¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ12.png


Ê×ÏÈÔÚ×¢²á±íHKLM\Software\WanaCrypt0r\wd ÖÐдÈ뵱ǰõè¾¶£¬ £¬ £¬£¬£¬£¬£¬¼Í¼¹ý³ÌµÄ¹¤×÷Ŀ¼(work directory)£¬ £¬ £¬£¬£¬£¬£¬¹©ÆäËüÄ£¿£¿£¿£¿£¿£¿£¿éʹÓᣡ£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ13.png


Åú¸ÄºóµÄ×¢²á±íÈçÏÂͼËùʾ£º


ͼƬ14.png


¶øºóʹÓÃÃÜÔ¿¡°WNcry@2ol7¡±½«Ç¶ÈëÔÚ×ÊÔ´ÖеÄzipѹËõ°ü½âѹµ½C:\WINDOWS¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ15.png


×ÊÔ´ÖеÄzipѹËõ°üÈçÏÂͼËùʾ£º


ͼƬ16.png


¸ÃѹËõ°üÖÐÓжà¸öÎļþ£¬ £¬ £¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ17.png


¶ÁÈ¡Îļþ t.wnry µÄÄÚÈݲ¢½âÃܳöDLLÎļþ£¬ £¬ £¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ18.png


½âÃܳöµÄDLLÎļþÊÇÀÕË÷Ä£¿£¿£¿£¿£¿£¿£¿é£¬ £¬ £¬£¬£¬£¬£¬ÓµÓÐÃûΪTaskStartµÄµ¼³öº¯Êý£¬ £¬ £¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º  


ͼƬ19.png

 

ͨ¹ýŲÓøõ¼³öº¯Êý£¬ £¬ £¬£¬£¬£¬£¬Ö´ÐмÓÃÜÀÕË÷Ö°ÄÜ¡£¡£¡£¡£¡£


4¡¢ÀÕË÷Ä£¿£¿£¿£¿£¿£¿£¿é


ÉÏÒ»½×¶Î½âÃܳöµÄDLLÎļþµÄԭʼÃû³ÆÎªkgptbeilcq£¬ £¬ £¬£¬£¬£¬£¬ÕƹÜʵÏÖ¾ßÌåµÄ¼ÓÃÜÀÕË÷Ö°ÄÜ¡£¡£¡£¡£¡£Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º


ͼƬ20.png


¸ÃDLLµÄÖØÒªÖ°ÄÜÈçÏÂͼËùʾ£º


ͼƬ21.png


Ê×ÏÈÖÕÖ¹Êý¾Ý¿âÓйعý³Ì£¬ £¬ £¬£¬£¬£¬£¬Ê¹µÃ¿ÉÄܼÓÃÜÊý¾Ý¿âÎļþ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ22.png


»ñÈ¡´ÅÅÌÇý¶¯Æ÷Ãû³Æ£¬ £¬ £¬£¬£¬£¬£¬±éÀú¸÷´ÅÅÌ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ23.png


±éÀúÎļþ¼Ð£¬ £¬ £¬£¬£¬£¬£¬²é³­ÎļþµÄÃû³ÆºÍºó׺£¬ £¬ £¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ24.png


¼ÓÃÜÒÔϺó׺ÃûµÄÎļþ£º


ÎļþÃû.png


Îļþ±»¼ÓÃÜºó£¬ £¬ £¬£¬£¬£¬£¬»á±»×·¼Óºó׺Ãû .WNCRY¡£¡£¡£¡£¡£


 ÔÚÿ¸öÎļþ¼ÐÖпªÊÍÃûΪ @Please_Read_Me@.txt µÄÀÕË÷ÐźÍÃûΪ @WanaDecryptor@.exe µÄ½âÃÜ·¨Ê½¡£¡£¡£¡£¡£ÀÕË÷ÐÅÄÚÈÝÈçÏÂͼËùʾ£º


ͼƬ25.png


Êܺ¦Õßͨ¹ý½âÃÜ·¨Ê½ @WanaDecryptor@.exe£¬ £¬ £¬£¬£¬£¬£¬Äܹ»½âÃܳö10¸ö±»¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£¸Ã½âÃÜ·¨Ê½ÏÔʾÁËÌáÐÑÐÅÏ¢ºÍ±ÈÌØ±ÒµØÖ·£¬ £¬ £¬£¬£¬£¬£¬²¢½øÐе¹¼ÆÊ±¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ26.png


5¡¢SETUP.EXE


SETUP.EXEÊǹÅÀϵÄWindowsXP Horror²¡¶¾£¬ £¬ £¬£¬£¬£¬£¬¸Ã²¡¶¾»áÅú¸Ä´ÅÅÌMBR£¬ £¬ £¬£¬£¬£¬£¬½«µÇ¼½çÃæÅú¸ÄΪ÷¼÷ÃͼÏñ£¬ £¬ £¬£¬£¬£¬£¬²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£¡£


Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º


ͼƬ27.png


Ñù±¾Ö´ÐÐºó£¬ £¬ £¬£¬£¬£¬£¬Ê×ÏÈÍ˳öµÇ¼½çÃæ£¬ £¬ £¬£¬£¬£¬£¬ÏÔʾ¡°Installing Windows Updates¡±µÈÌáÐÑ£¬ £¬ £¬£¬£¬£¬£¬ÔÚ½ø¶Èµ½66%ʱ£¬ £¬ £¬£¬£¬£¬£¬»áµ¯³ö¡°Setup will use the file 666.sys¡±µÄÌáÐÑ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ28.png


µÇ¼½çÃæ»á±»»»³É÷¼÷ÃͼÏñ£¬ £¬ £¬£¬£¬£¬£¬²»ÐÝÇл»ÑªÐÈͼƬ£¬ £¬ £¬£¬£¬£¬£¬²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£¡£


µã»÷×ÀÃæµÄͼ±êºó£¬ £¬ £¬£¬£¬£¬£¬»áµ¯³öÌáÐÑ¿ò£¬ £¬ £¬£¬£¬£¬£¬²¢°Ñͼ±êÒÆ¶¯µ½»ØÊÕÕ¾¡£¡£¡£¡£¡£


²Ù×÷ϵͳ±ÀÀ£²¢ÏÔʾºìÉ«²¼¾°£¬ £¬ £¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ29.png


ËÝÔ´¹ØÁª


1. ͨ¹ý¶Ô¸Ã×éÖ¯ÌṩµÄ±ÈÌØ±ÒÂòÂôµØÖ·£¬ £¬ £¬£¬£¬£¬£¬¸ú×Ùµ½¸Ã×éÖ¯ÔÚ2024ËêĺÊÕµ½¼¸±ÊÊܺ¦ÕßÖ§¸¶µÄBTC¡£¡£¡£¡£¡£×¢Ã÷¸Ã×éÖ¯ÈÔ¾ÉÔÚÒÀ¸½ÀÕË÷Èí¼þ³ÖÐøÓ¯Àû£º


ͼƬ30.png


ͼƬ31.png


ͬʱͨ¹ý¶Ôº¹ÇàÐÅÏ¢µÄͳ¼Æ£¬ £¬ £¬£¬£¬£¬£¬Äܹ»¹Û²âµ½¸Ã×éÖ¯ÔÚÅû¶µÄµØÖ·ÉÏÀۼƻñÀûÔ¼54BTC£¬ £¬ £¬£¬£¬£¬£¬°´µ±Ç°»ãÂʹÀËãÒѳ¬¹ýǧÍòÔªÈËÃñ±Ò¡£¡£¡£¡£¡£


2. ͨ¹ý¶Ô³õʼÑù±¾µÄÌØµã½øÐйØÁª£¬ £¬ £¬£¬£¬£¬£¬·¢ÏÖÒÔÏÂÓë±¾´Î¹¥»÷»î¶¯ÓйصÄÑù±¾£º


MD5£º

c27fc192811dad928730b24fd8150a03

2e5f24942932190e577319a7e81b83e4

33e884e59a7c1e1d6af5b19a283a04a7

4d4f7bfac3a17767cb9a7f88737b7ef5

061a8f66ec2f86f9668c0c157ed54b6c

5a02e019a2a7920d0b23326a616bf88f

a7389982054233436020f0ada0765a48


ATT&CK


¸ÃÑù±¾ËùѡȡµÄ¹¥»÷¼¼Õ½·¨ÓëATT&CKµÄÓ³ÉäÈçϱíËùʾ£º


ͼƬ32.png


IoCs


ͼƬ33.png