¼øºÚµ£±£ÍøÌáÐÑ£ºÐ¡ÐÄ·ÂðDeepSeek×°ÖðüͶµÝWannaCryÀÕË÷Èí¼þ

Ðû²¼Ê±¼ä 2025-03-14

¡°ÈÃÿһ¾äÈË»ú¶Ô»°¶¼Çå¾²¿ÉÐÅ£¬ £¬£¬£¬£¬£¬£¬ÈÃÿһ´ÎÖÇÄܽ»»¥¶¼Î£º¦¿É¿Ø¡ª¡ªÕâÊÇÊôÓÚAIʱ´úµÄÇå¾²ÔÊÐí¡£¡£¡£¡£¡£ ¡ª¡ª ¼øºÚµ£±£Íø¡±


AIËÙÀÀ£º


±¾ÎÄÌÖÂÛÁË2025ÄêËæ×ÅDeepSeek-R1Ðû²¼Òý·¢´óÄ£×ÓÍâµØ»¯°²ÅÅÀ˳±ºó£¬ £¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøVenusEyeÍþвÇ鱨ÖÐÐÄ·¢Ã÷ÀÕË÷Èí¼þÍÅ»ïʹÓ÷ÂðDeepSeek×°Öðü¾ÙÐй¥»÷µÄÇéÐΣ¬ £¬£¬£¬£¬£¬£¬Ñо¿ÍŶӯÊÎöÁËÑù±¾²¢¸ø³öÏà¹ØÐÅÏ¢¡£¡£¡£¡£¡£Òªº¦Òªµã°üÀ¨:

1.¹¥»÷ÊÖ¶Î:ºÚ¿ÍʹÓ÷ÂðDeepSeek×°Öðü(Install_DeepSeek.exe)¹¥»÷£¬ £¬£¬£¬£¬£¬£¬×Ô½âѹÊÍ·ÅWannaCryÀÕË÷Èí¼þºÍWindows XPHorror²¡¶¾¡£¡£¡£¡£¡£

2.Ñù±¾ÐÅÏ¢:³õʼ·Âð³ÌÐòInstall_DeepSeek.exe£¬ £¬£¬£¬£¬£¬£¬Îļþ¾Þϸ56.07MB£¬ £¬£¬£¬£¬£¬£¬ÓÉ2¸öexe³ÌÐò´ò°ü×é³É£¬ £¬£¬£¬£¬£¬£¬Í¨¹ýSFX¾ç±¾Ö¸¶¨ÊÍ·Å·¾¶£¬ £¬£¬£¬£¬£¬£¬ÊÍ·Åtasksche.exeºÍSETUP.EXEµ½C:\WINDOWSÎļþ¼Ð¡£¡£¡£¡£¡£

3.¶ñÒâ³ÌÐò¹¦Ð§:tasksche.exeÊÍ·ÅWannaCryÄ£¿£¿£¿é¼ÓÃÜÎļþ;._cache tasksche.exe½âѹËõÄ£¿£¿£¿é¡¢½âÃܲ¢Ö´ÐÐDLL;DLL¼ÓÃÜÌØ¶¨ºó׺Îļþ;SETUP.EXE (Windows XP Horror²¡¶¾)Ð޸ĴÅÅÌMBR£¬ £¬£¬£¬£¬£¬£¬¸ü¸ÄµÇ¼½çÃæ¡£¡£¡£¡£¡£

4.¼ÓÃÜÎļþºó׺:±»¼ÓÃÜÎļþºó׺Öڶ࣬ £¬£¬£¬£¬£¬£¬¼ÓÃܺó×·¼Ó.WNCRYºó׺£¬ £¬£¬£¬£¬£¬£¬Ã¿¸öÎļþ¼ÐÊÍ·ÅÀÕË÷ÐźͲ¿·Ö½âÃܳÌÐò¡£¡£¡£¡£¡£

5.ËÝÔ´¹ØÁª:ͨ¹ý±ÈÌØ±ÒÉúÒâµØµã·¢Ã÷¸Ã×éÖ¯Ò»Á¬Ó¯Àû£¬ £¬£¬£¬£¬£¬£¬ÀÛ¼Æ×¬Ç®Ô¼54BTC£¬ £¬£¬£¬£¬£¬£¬³¬ÍòÍòÔªÈËÃñ±Ò£¬ £¬£¬£¬£¬£¬£¬Í¬Ê±»¹¹ØÁªµ½¶à¸öÏà¹ØÑù±¾¡£¡£¡£¡£¡£


2025Ä꣬ £¬£¬£¬£¬£¬£¬Ëæ×ÅDeepSeek-R1µÄÐû²¼£¬ £¬£¬£¬£¬£¬£¬Ñ¸ËÙÒý·¢´óÄ£×ÓÍâµØ»¯°²ÅÅÀ˳±¡£¡£¡£¡£¡£Ø¨¹ÅδÓеĹØ×¢¶ÈÒ²ÎüÀÕË÷Èí¼þÍÅ»ïÒ²½ô¸úÈÈÃÅ£¬ £¬£¬£¬£¬£¬£¬´î½¨´¹ÂÚÍøÕ¾£¬ £¬£¬£¬£¬£¬£¬Î±×°³ÉÕýµ±µÄAIÈí¼þÏÂÔØÆ½Ì¨£¬ £¬£¬£¬£¬£¬£¬ÓÕµ¼Óû§×°ÖÃÀ¦°óÀÕË÷Èí¼þµÄ·ÂðÈí¼þ£¬ £¬£¬£¬£¬£¬£¬´Ó¶ø¶ÔÊܺ¦Ö÷»úÉϵÄÎļþ¾ÙÐмÓÃÜ£¬ £¬£¬£¬£¬£¬£¬ÒÔвÆÈÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£


ÊÖÒÕÆÊÎö


´Ë´Î¹¥»÷»î¶¯µÄÑù±¾ÊÇαװ³ÉDeepSeek×°ÖðüµÄexeÎļþ£¬ £¬£¬£¬£¬£¬£¬¸ÃÎļþÖ´Ðкó£¬ £¬£¬£¬£¬£¬£¬Í¨¹ý×Ô½âѹ·½·¨ÊͷųöÀÕË÷Èí¼þWannaCryºÍ¿Ö²À²¡¶¾Windows XP Horror£¬ £¬£¬£¬£¬£¬£¬»®·ÖÖ´ÐÐÕâ2¸ö¶ñÒâ³ÌÐò¡£¡£¡£¡£¡£WannaCryÊͷųöÀÕË÷¹¦Ð§Ä£¿£¿£¿é²¢Ö´ÐУ¬ £¬£¬£¬£¬£¬£¬¼ÓÃÜÌØ¶¨ºó׺µÄÎļþ£¬ £¬£¬£¬£¬£¬£¬ÊͷųöÀÕË÷ÐÅ¡£¡£¡£¡£¡£¿£¿£¿Ö²À²¡¶¾Windows XP HorrorÐ޸ĴÅÅÌMBR£¬ £¬£¬£¬£¬£¬£¬½«µÇ¼½çÃæÉèÖÃΪ÷¼÷ÃͼÏñ²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£¡£


¸ÃÑù±¾ÕûÌåÁ÷³ÌÈçÏÂͼËùʾ£º


ͼƬ1.png


1¡¢³õʼ·Âð³ÌÐò


¸ÃÑù±¾ÎªÎ±×°³ÉDeepSeek×°ÖóÌÐòµÄexeÎļþ£¬ £¬£¬£¬£¬£¬£¬ÆäÑù±¾ÐÅÏ¢¼ûÏÂ±í£º


ͼƬ2.png


³õʼ¹¥»÷Îļþ·ÂðÁËDeepSeekµÄͼ±ê£¬ £¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ3.png

¸ÃexeÎļþÊôÓÚWinrar SFX×Ô½âѹÎļþ£¬ £¬£¬£¬£¬£¬£¬ÓÉ2¸öexe³ÌÐò´ò°ü¶ø³É£¬ £¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ4.png


¶ñÒâÈí¼þͨ¹ýSFX¾ç±¾Ö¸¶¨tasksche.exeºÍSETUP.EXEµÄÊÍ·Å·¾¶£¬ £¬£¬£¬£¬£¬£¬SFX¾ç±¾ÄÚÈݰüÀ¨¡°DeepSeek¡±Ïà¹ØÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ5.png


ͨ¹ýÓû§µã»÷´¥·¢SFX¶ñÒâÎļþºó£¬ £¬£¬£¬£¬£¬£¬»á½«tasksche.exeºÍSETUP.EXEÊͷŵ½C:\WINDOWSÎļþ¼ÐÖУº


ͼƬ6.png


ͬʱװÖÃÖ´ÐÐtasksche.exeºÍSETUP.EXE£º


ͼƬ7.png


2¡¢ tasksche.exe


tasksche.exeÓÉDelphiÓïÑÔ¿ª·¢£¬ £¬£¬£¬£¬£¬£¬Æä¹¦Ð§ÊÇÊÍ·ÅWannaCryÀÕË÷Èí¼þµÄÄ£¿£¿£¿é£¬ £¬£¬£¬£¬£¬£¬ÊµÏÖÎļþ¼ÓÃÜÀÕË÷¹¦Ð§¡£¡£¡£¡£¡£Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º


ͼƬ8.png


tasksche.exeµÄ×ÊÔ´ÎļþÖаüÀ¨Ò»¸öEXE³ÌÐò£¬ £¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ9.png


tasksche.exeÆô¶¯ºó£¬ £¬£¬£¬£¬£¬£¬Ê×ÏÈ»á¼ÓÔØ¸Ã×ÊÔ´£¬ £¬£¬£¬£¬£¬£¬»ñÈ¡×ÊÔ´ÄÚÈÝ¡£¡£¡£¡£¡£È»ºó½¨ÉèÎļþ C:\WINDOWS\._cache_tasksche.exe£¬ £¬£¬£¬£¬£¬£¬²¢½«×ÊÔ´ÖеÄÊý¾ÝдÈë¸ÃÎļþÖУ¬ £¬£¬£¬£¬£¬£¬×îÖÕÖ´ÐиÃÎļþ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ10.png


3¡¢ ._cache_tasksche.exe


._cache_tasksche.exeÎļþµÄÑù±¾ÐÅÏ¢¼ûÏÂ±í£º


ͼƬ11.png


._cache_tasksche.exeµÄÖ÷Òª¹¦Ð§ÊÇ´Ó×ÊÔ´ÖнâѹËõ³ö¹¦Ð§Ä£¿£¿£¿é£¬ £¬£¬£¬£¬£¬£¬½âÃܳö1¸öDLL²¢Ö´ÐÐÆäÌØ¶¨µÄµ¼³öº¯Êý¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ12.png


Ê×ÏÈÔÚ×¢²á±íHKLM\Software\WanaCrypt0r\wd ÖÐдÈëÄ¿½ñ·¾¶£¬ £¬£¬£¬£¬£¬£¬¼Í¼Àú³ÌµÄÊÂÇéĿ¼(work directory)£¬ £¬£¬£¬£¬£¬£¬¹©ÆäËüÄ£¿£¿£¿éʹÓᣡ£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ13.png


Ð޸ĺóµÄ×¢²á±íÈçÏÂͼËùʾ£º


ͼƬ14.png


È»ºóʹÓÃÃÜÔ¿¡°WNcry@2ol7¡±½«Ç¶ÈëÔÚ×ÊÔ´ÖеÄzipѹËõ°ü½âѹµ½C:\WINDOWS¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ15.png


×ÊÔ´ÖеÄzipѹËõ°üÈçÏÂͼËùʾ£º


ͼƬ16.png


¸ÃѹËõ°üÖÐÓжà¸öÎļþ£¬ £¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ17.png


¶ÁÈ¡Îļþ t.wnry µÄÄÚÈݲ¢½âÃܳöDLLÎļþ£¬ £¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ18.png


½âÃܳöµÄDLLÎļþÊÇÀÕË÷Ä£¿£¿£¿é£¬ £¬£¬£¬£¬£¬£¬¾ßÖøÃûΪTaskStartµÄµ¼³öº¯Êý£¬ £¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º  


ͼƬ19.png

 

ͨ¹ýŲÓøõ¼³öº¯Êý£¬ £¬£¬£¬£¬£¬£¬Ö´ÐмÓÃÜÀÕË÷¹¦Ð§¡£¡£¡£¡£¡£


4¡¢ÀÕË÷Ä£¿£¿£¿é


ÉÏÒ»½×¶Î½âÃܳöµÄDLLÎļþµÄԭʼÃû³ÆÎªkgptbeilcq£¬ £¬£¬£¬£¬£¬£¬ÈÏÕæÊµÏÖÏêϸµÄ¼ÓÃÜÀÕË÷¹¦Ð§¡£¡£¡£¡£¡£Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º


ͼƬ20.png


¸ÃDLLµÄÖ÷Òª¹¦Ð§ÈçÏÂͼËùʾ£º


ͼƬ21.png


Ê×ÏÈÖÕÖ¹Êý¾Ý¿âÏà¹ØÀú³Ì£¬ £¬£¬£¬£¬£¬£¬Ê¹µÃÄܹ»¼ÓÃÜÊý¾Ý¿âÎļþ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ22.png


»ñÈ¡´ÅÅÌÇý¶¯Æ÷Ãû³Æ£¬ £¬£¬£¬£¬£¬£¬±éÀú¸÷´ÅÅÌ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ23.png


±éÀúÎļþ¼Ð£¬ £¬£¬£¬£¬£¬£¬¼ì²éÎļþµÄÃû³ÆºÍºó׺£¬ £¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ24.png


¼ÓÃÜÒÔϺó׺ÃûµÄÎļþ£º


ÎļþÃû.png


Îļþ±»¼ÓÃܺó£¬ £¬£¬£¬£¬£¬£¬»á±»×·¼Óºó׺Ãû .WNCRY¡£¡£¡£¡£¡£


 ÔÚÿ¸öÎļþ¼ÐÖÐÊÍ·ÅÃûΪ @Please_Read_Me@.txt µÄÀÕË÷ÐźÍÃûΪ @WanaDecryptor@.exe µÄ½âÃܳÌÐò¡£¡£¡£¡£¡£ÀÕË÷ÐÅÄÚÈÝÈçÏÂͼËùʾ£º


ͼƬ25.png


Êܺ¦Õßͨ¹ý½âÃܳÌÐò @WanaDecryptor@.exe£¬ £¬£¬£¬£¬£¬£¬¿ÉÒÔ½âÃܳö10¸ö±»¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£¸Ã½âÃܳÌÐòÏÔʾÁËÌáÐÑÐÅÏ¢ºÍ±ÈÌØ±ÒµØµã£¬ £¬£¬£¬£¬£¬£¬²¢¾ÙÐе¹¼ÆÊ±¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ26.png


5¡¢SETUP.EXE


SETUP.EXEÊǹÅÀϵÄWindowsXP Horror²¡¶¾£¬ £¬£¬£¬£¬£¬£¬¸Ã²¡¶¾»áÐ޸ĴÅÅÌMBR£¬ £¬£¬£¬£¬£¬£¬½«µÇ¼½çÃæÐÞ¸ÄΪ÷¼÷ÃͼÏñ£¬ £¬£¬£¬£¬£¬£¬²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£¡£


Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º


ͼƬ27.png


Ñù±¾Ö´Ðкó£¬ £¬£¬£¬£¬£¬£¬Ê×ÏÈÍ˳öµÇ¼½çÃæ£¬ £¬£¬£¬£¬£¬£¬ÏÔʾ¡°Installing Windows Updates¡±µÈÌáÐÑ£¬ £¬£¬£¬£¬£¬£¬ÔÚ½ø¶Èµ½66%ʱ£¬ £¬£¬£¬£¬£¬£¬»áµ¯³ö¡°Setup will use the file 666.sys¡±µÄÌáÐÑ¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£º


ͼƬ28.png


µÇ¼½çÃæ»á±»»»³É÷¼÷ÃͼÏñ£¬ £¬£¬£¬£¬£¬£¬Ò»Ö±Çл»ÑªÐÈͼƬ£¬ £¬£¬£¬£¬£¬£¬²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£¡£


µã»÷×ÀÃæµÄͼ±êºó£¬ £¬£¬£¬£¬£¬£¬»áµ¯³öÌáÐÑ¿ò£¬ £¬£¬£¬£¬£¬£¬²¢°Ñͼ±êÒÆ¶¯µ½½ÓÄÉÕ¾¡£¡£¡£¡£¡£


²Ù×÷ϵͳÍ߽ⲢÏÔʾºìÉ«Åä¾°£¬ £¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º


ͼƬ29.png


ËÝÔ´¹ØÁª


1. ͨ¹ý¶Ô¸Ã×éÖ¯ÌṩµÄ±ÈÌØ±ÒÉúÒâµØµã£¬ £¬£¬£¬£¬£¬£¬¸ú×Ùµ½¸Ã×éÖ¯ÔÚ2024ÄêβÊÕµ½¼¸±ÊÊܺ¦ÕßÖ§¸¶µÄBTC¡£¡£¡£¡£¡£ËµÃ÷¸Ã×éÖ¯ÒÀ¾ÉÔÚÒÀÀµÀÕË÷Èí¼þÒ»Á¬Ó¯Àû£º


ͼƬ30.png


ͼƬ31.png


ͬʱͨ¹ý¶ÔÀúÊ·ÐÅÏ¢µÄͳ¼Æ£¬ £¬£¬£¬£¬£¬£¬¿ÉÒÔÊӲ쵽¸Ã×éÖ¯ÔÚÅû¶µÄµØµãÉÏÀÛ¼Æ×¬Ç®Ô¼54BTC£¬ £¬£¬£¬£¬£¬£¬°´Ä¿½ñ»ãÂʹÀËãÒÑÁè¼ÝÍòÍòÔªÈËÃñ±Ò¡£¡£¡£¡£¡£


2. ͨ¹ý¶Ô³õʼÑù±¾µÄÌØÕ÷¾ÙÐйØÁª£¬ £¬£¬£¬£¬£¬£¬·¢Ã÷ÒÔÏÂÓë±¾´Î¹¥»÷»î¶¯Ïà¹ØµÄÑù±¾£º


MD5£º

c27fc192811dad928730b24fd8150a03

2e5f24942932190e577319a7e81b83e4

33e884e59a7c1e1d6af5b19a283a04a7

4d4f7bfac3a17767cb9a7f88737b7ef5

061a8f66ec2f86f9668c0c157ed54b6c

5a02e019a2a7920d0b23326a616bf88f

a7389982054233436020f0ada0765a48


ATT&CK


¸ÃÑù±¾Ëù½ÓÄɵĹ¥»÷¼¼Õ½·¨ÓëATT&CKµÄÓ³ÉäÈçϱíËùʾ£º


ͼƬ32.png


IoCs


ͼƬ33.png