¿Ðý¹ú¼ÊÓÎÏ·ÌáÐÑ£ºÐ¡ÐÄ·ÂðDeepSeek×°ÖðüͶµÝWannaCryÀÕË÷Èí¼þ
Ðû²¼Ê±¼ä 2025-03-14¡°ÈÃÿһ¾äÈË»ú¶Ô»°¶¼Çå¾²¿ÉÐÅ£¬£¬£¬£¬£¬£¬ÈÃÿһ´ÎÖÇÄܽ»»¥¶¼Î£º¦¿É¿Ø¡ª¡ªÕâÊÇÊôÓÚAIʱ´úµÄÇå¾²ÔÊÐí¡£¡£¡£¡£ ¡ª¡ª ¿Ðý¹ú¼ÊÓÎÏ·¡±
AIËÙÀÀ£º
±¾ÎÄÌÖÂÛÁË2025ÄêËæ×ÅDeepSeek-R1Ðû²¼Òý·¢´óÄ£×ÓÍâµØ»¯°²ÅÅÀ˳±ºó£¬£¬£¬£¬£¬£¬¿Ðý¹ú¼ÊÓÎÏ·VenusEyeÍþвÇ鱨ÖÐÐÄ·¢Ã÷ÀÕË÷Èí¼þÍÅ»ïʹÓ÷ÂðDeepSeek×°Öðü¾ÙÐй¥»÷µÄÇéÐΣ¬£¬£¬£¬£¬£¬Ñо¿ÍŶӯÊÎöÁËÑù±¾²¢¸ø³öÏà¹ØÐÅÏ¢¡£¡£¡£¡£Òªº¦Òªµã°üÀ¨:
1.¹¥»÷ÊÖ¶Î:ºÚ¿ÍʹÓ÷ÂðDeepSeek×°Öðü(Install_DeepSeek.exe)¹¥»÷£¬£¬£¬£¬£¬£¬×Ô½âѹÊÍ·ÅWannaCryÀÕË÷Èí¼þºÍWindows XPHorror²¡¶¾¡£¡£¡£¡£
2.Ñù±¾ÐÅÏ¢:³õʼ·Âð³ÌÐòInstall_DeepSeek.exe£¬£¬£¬£¬£¬£¬Îļþ¾Þϸ56.07MB£¬£¬£¬£¬£¬£¬ÓÉ2¸öexe³ÌÐò´ò°ü×é³É£¬£¬£¬£¬£¬£¬Í¨¹ýSFX¾ç±¾Ö¸¶¨ÊÍ·Å·¾¶£¬£¬£¬£¬£¬£¬ÊÍ·Åtasksche.exeºÍSETUP.EXEµ½C:\WINDOWSÎļþ¼Ð¡£¡£¡£¡£
3.¶ñÒâ³ÌÐò¹¦Ð§:tasksche.exeÊÍ·ÅWannaCryÄ£¿£¿£¿£¿£¿£¿é¼ÓÃÜÎļþ;._cache tasksche.exe½âѹËõÄ£¿£¿£¿£¿£¿£¿é¡¢½âÃܲ¢Ö´ÐÐDLL;DLL¼ÓÃÜÌØ¶¨ºó׺Îļþ;SETUP.EXE (Windows XP Horror²¡¶¾)Ð޸ĴÅÅÌMBR£¬£¬£¬£¬£¬£¬¸ü¸ÄµÇ¼½çÃæ¡£¡£¡£¡£
4.¼ÓÃÜÎļþºó׺:±»¼ÓÃÜÎļþºó׺Öڶ࣬£¬£¬£¬£¬£¬¼ÓÃܺó×·¼Ó.WNCRYºó׺£¬£¬£¬£¬£¬£¬Ã¿¸öÎļþ¼ÐÊÍ·ÅÀÕË÷ÐźͲ¿·Ö½âÃܳÌÐò¡£¡£¡£¡£
5.ËÝÔ´¹ØÁª:ͨ¹ý±ÈÌØ±ÒÉúÒâµØµã·¢Ã÷¸Ã×éÖ¯Ò»Á¬Ó¯Àû£¬£¬£¬£¬£¬£¬ÀÛ¼Æ×¬Ç®Ô¼54BTC£¬£¬£¬£¬£¬£¬³¬ÍòÍòÔªÈËÃñ±Ò£¬£¬£¬£¬£¬£¬Í¬Ê±»¹¹ØÁªµ½¶à¸öÏà¹ØÑù±¾¡£¡£¡£¡£
2025Ä꣬£¬£¬£¬£¬£¬Ëæ×ÅDeepSeek-R1µÄÐû²¼£¬£¬£¬£¬£¬£¬Ñ¸ËÙÒý·¢´óÄ£×ÓÍâµØ»¯°²ÅÅÀ˳±¡£¡£¡£¡£Ø¨¹ÅδÓеĹØ×¢¶ÈÒ²ÎüÀÕË÷Èí¼þÍÅ»ïÒ²½ô¸úÈÈÃÅ£¬£¬£¬£¬£¬£¬´î½¨´¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬£¬Î±×°³ÉÕýµ±µÄAIÈí¼þÏÂÔØÆ½Ì¨£¬£¬£¬£¬£¬£¬ÓÕµ¼Óû§×°ÖÃÀ¦°óÀÕË÷Èí¼þµÄ·ÂðÈí¼þ£¬£¬£¬£¬£¬£¬´Ó¶ø¶ÔÊܺ¦Ö÷»úÉϵÄÎļþ¾ÙÐмÓÃÜ£¬£¬£¬£¬£¬£¬ÒÔвÆÈÊܺ¦ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£
ÊÖÒÕÆÊÎö
´Ë´Î¹¥»÷»î¶¯µÄÑù±¾ÊÇαװ³ÉDeepSeek×°ÖðüµÄexeÎļþ£¬£¬£¬£¬£¬£¬¸ÃÎļþÖ´Ðк󣬣¬£¬£¬£¬£¬Í¨¹ý×Ô½âѹ·½·¨ÊͷųöÀÕË÷Èí¼þWannaCryºÍ¿Ö²À²¡¶¾Windows XP Horror£¬£¬£¬£¬£¬£¬»®·ÖÖ´ÐÐÕâ2¸ö¶ñÒâ³ÌÐò¡£¡£¡£¡£WannaCryÊͷųöÀÕË÷¹¦Ð§Ä£¿£¿£¿£¿£¿£¿é²¢Ö´ÐУ¬£¬£¬£¬£¬£¬¼ÓÃÜÌØ¶¨ºó׺µÄÎļþ£¬£¬£¬£¬£¬£¬ÊͷųöÀÕË÷ÐÅ¡£¡£¡£¡£¿£¿£¿£¿£¿£¿Ö²À²¡¶¾Windows XP HorrorÐ޸ĴÅÅÌMBR£¬£¬£¬£¬£¬£¬½«µÇ¼½çÃæÉèÖÃΪ÷¼÷ÃͼÏñ²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£
¸ÃÑù±¾ÕûÌåÁ÷³ÌÈçÏÂͼËùʾ£º

1¡¢³õʼ·Âð³ÌÐò
¸ÃÑù±¾ÎªÎ±×°³ÉDeepSeek×°ÖóÌÐòµÄexeÎļþ£¬£¬£¬£¬£¬£¬ÆäÑù±¾ÐÅÏ¢¼ûÏÂ±í£º

³õʼ¹¥»÷Îļþ·ÂðÁËDeepSeekµÄͼ±ê£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º
¸ÃexeÎļþÊôÓÚWinrar SFX×Ô½âѹÎļþ£¬£¬£¬£¬£¬£¬ÓÉ2¸öexe³ÌÐò´ò°ü¶ø³É£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

¶ñÒâÈí¼þͨ¹ýSFX¾ç±¾Ö¸¶¨tasksche.exeºÍSETUP.EXEµÄÊÍ·Å·¾¶£¬£¬£¬£¬£¬£¬SFX¾ç±¾ÄÚÈݰüÀ¨¡°DeepSeek¡±Ïà¹ØÐÅÏ¢£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

ͨ¹ýÓû§µã»÷´¥·¢SFX¶ñÒâÎļþºó£¬£¬£¬£¬£¬£¬»á½«tasksche.exeºÍSETUP.EXEÊͷŵ½C:\WINDOWSÎļþ¼ÐÖУº

ͬʱװÖÃÖ´ÐÐtasksche.exeºÍSETUP.EXE£º

2¡¢ tasksche.exe
tasksche.exeÓÉDelphiÓïÑÔ¿ª·¢£¬£¬£¬£¬£¬£¬Æä¹¦Ð§ÊÇÊÍ·ÅWannaCryÀÕË÷Èí¼þµÄÄ£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬ÊµÏÖÎļþ¼ÓÃÜÀÕË÷¹¦Ð§¡£¡£¡£¡£Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º

tasksche.exeµÄ×ÊÔ´ÎļþÖаüÀ¨Ò»¸öEXE³ÌÐò£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

tasksche.exeÆô¶¯ºó£¬£¬£¬£¬£¬£¬Ê×ÏÈ»á¼ÓÔØ¸Ã×ÊÔ´£¬£¬£¬£¬£¬£¬»ñÈ¡×ÊÔ´ÄÚÈÝ¡£¡£¡£¡£È»ºó½¨ÉèÎļþ C:\WINDOWS\._cache_tasksche.exe£¬£¬£¬£¬£¬£¬²¢½«×ÊÔ´ÖеÄÊý¾ÝдÈë¸ÃÎļþÖУ¬£¬£¬£¬£¬£¬×îÖÕÖ´ÐиÃÎļþ¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

3¡¢ ._cache_tasksche.exe
._cache_tasksche.exeÎļþµÄÑù±¾ÐÅÏ¢¼ûÏÂ±í£º

._cache_tasksche.exeµÄÖ÷Òª¹¦Ð§ÊÇ´Ó×ÊÔ´ÖнâѹËõ³ö¹¦Ð§Ä£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬½âÃܳö1¸öDLL²¢Ö´ÐÐÆäÌØ¶¨µÄµ¼³öº¯Êý¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

Ê×ÏÈÔÚ×¢²á±íHKLM\Software\WanaCrypt0r\wd ÖÐдÈëÄ¿½ñ·¾¶£¬£¬£¬£¬£¬£¬¼Í¼Àú³ÌµÄÊÂÇéĿ¼(work directory)£¬£¬£¬£¬£¬£¬¹©ÆäËüÄ£¿£¿£¿£¿£¿£¿éʹÓᣡ£¡£¡£ÈçÏÂͼËùʾ£º

Ð޸ĺóµÄ×¢²á±íÈçÏÂͼËùʾ£º

È»ºóʹÓÃÃÜÔ¿¡°WNcry@2ol7¡±½«Ç¶ÈëÔÚ×ÊÔ´ÖеÄzipѹËõ°ü½âѹµ½C:\WINDOWS¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

×ÊÔ´ÖеÄzipѹËõ°üÈçÏÂͼËùʾ£º

¸ÃѹËõ°üÖÐÓжà¸öÎļþ£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

¶ÁÈ¡Îļþ t.wnry µÄÄÚÈݲ¢½âÃܳöDLLÎļþ£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

½âÃܳöµÄDLLÎļþÊÇÀÕË÷Ä£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬¾ßÖøÃûΪTaskStartµÄµ¼³öº¯Êý£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

ͨ¹ýŲÓøõ¼³öº¯Êý£¬£¬£¬£¬£¬£¬Ö´ÐмÓÃÜÀÕË÷¹¦Ð§¡£¡£¡£¡£
4¡¢ÀÕË÷Ä£¿£¿£¿£¿£¿£¿é
ÉÏÒ»½×¶Î½âÃܳöµÄDLLÎļþµÄÔʼÃû³ÆÎªkgptbeilcq£¬£¬£¬£¬£¬£¬ÈÏÕæÊµÏÖÏêϸµÄ¼ÓÃÜÀÕË÷¹¦Ð§¡£¡£¡£¡£Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º

¸ÃDLLµÄÖ÷Òª¹¦Ð§ÈçÏÂͼËùʾ£º

Ê×ÏÈÖÕÖ¹Êý¾Ý¿âÏà¹ØÀú³Ì£¬£¬£¬£¬£¬£¬Ê¹µÃÄܹ»¼ÓÃÜÊý¾Ý¿âÎļþ¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

»ñÈ¡´ÅÅÌÇý¶¯Æ÷Ãû³Æ£¬£¬£¬£¬£¬£¬±éÀú¸÷´ÅÅÌ¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

±éÀúÎļþ¼Ð£¬£¬£¬£¬£¬£¬¼ì²éÎļþµÄÃû³ÆºÍºó׺£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

¼ÓÃÜÒÔϺó׺ÃûµÄÎļþ£º
Îļþ±»¼ÓÃܺ󣬣¬£¬£¬£¬£¬»á±»×·¼Óºó׺Ãû .WNCRY¡£¡£¡£¡£
ÔÚÿ¸öÎļþ¼ÐÖÐÊÍ·ÅÃûΪ @Please_Read_Me@.txt µÄÀÕË÷ÐźÍÃûΪ @WanaDecryptor@.exe µÄ½âÃܳÌÐò¡£¡£¡£¡£ÀÕË÷ÐÅÄÚÈÝÈçÏÂͼËùʾ£º
Êܺ¦Õßͨ¹ý½âÃܳÌÐò @WanaDecryptor@.exe£¬£¬£¬£¬£¬£¬¿ÉÒÔ½âÃܳö10¸ö±»¼ÓÃܵÄÎļþ¡£¡£¡£¡£¸Ã½âÃܳÌÐòÏÔʾÁËÌáÐÑÐÅÏ¢ºÍ±ÈÌØ±ÒµØµã£¬£¬£¬£¬£¬£¬²¢¾ÙÐе¹¼ÆÊ±¡£¡£¡£¡£ÈçÏÂͼËùʾ£º
5¡¢SETUP.EXE
SETUP.EXEÊǹÅÀϵÄWindowsXP Horror²¡¶¾£¬£¬£¬£¬£¬£¬¸Ã²¡¶¾»áÐ޸ĴÅÅÌMBR£¬£¬£¬£¬£¬£¬½«µÇ¼½çÃæÐÞ¸ÄΪ÷¼÷ÃͼÏñ£¬£¬£¬£¬£¬£¬²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£
Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º

Ñù±¾Ö´Ðк󣬣¬£¬£¬£¬£¬Ê×ÏÈÍ˳öµÇ¼½çÃæ£¬£¬£¬£¬£¬£¬ÏÔʾ¡°Installing Windows Updates¡±µÈÌáÐÑ£¬£¬£¬£¬£¬£¬ÔÚ½ø¶Èµ½66%ʱ£¬£¬£¬£¬£¬£¬»áµ¯³ö¡°Setup will use the file 666.sys¡±µÄÌáÐÑ¡£¡£¡£¡£ÈçÏÂͼËùʾ£º

µÇ¼½çÃæ»á±»»»³É÷¼÷ÃͼÏñ£¬£¬£¬£¬£¬£¬Ò»Ö±Çл»ÑªÐÈͼƬ£¬£¬£¬£¬£¬£¬²¢²¥·Å¿Ö²À¶¯Í¼¡£¡£¡£¡£
µã»÷×ÀÃæµÄͼ±êºó£¬£¬£¬£¬£¬£¬»áµ¯³öÌáÐÑ¿ò£¬£¬£¬£¬£¬£¬²¢°Ñͼ±êÒÆ¶¯µ½½ÓÄÉÕ¾¡£¡£¡£¡£
²Ù×÷ϵͳÍ߽ⲢÏÔʾºìÉ«Åä¾°£¬£¬£¬£¬£¬£¬ÈçÏÂͼËùʾ£º

ËÝÔ´¹ØÁª
1. ͨ¹ý¶Ô¸Ã×éÖ¯ÌṩµÄ±ÈÌØ±ÒÉúÒâµØµã£¬£¬£¬£¬£¬£¬¸ú×Ùµ½¸Ã×éÖ¯ÔÚ2024ÄêβÊÕµ½¼¸±ÊÊܺ¦ÕßÖ§¸¶µÄBTC¡£¡£¡£¡£ËµÃ÷¸Ã×éÖ¯ÒÀ¾ÉÔÚÒÀÀµÀÕË÷Èí¼þÒ»Á¬Ó¯Àû£º

ͬʱͨ¹ý¶ÔÀúÊ·ÐÅÏ¢µÄͳ¼Æ£¬£¬£¬£¬£¬£¬¿ÉÒÔÊӲ쵽¸Ã×éÖ¯ÔÚÅû¶µÄµØµãÉÏÀÛ¼Æ×¬Ç®Ô¼54BTC£¬£¬£¬£¬£¬£¬°´Ä¿½ñ»ãÂʹÀËãÒÑÁè¼ÝÍòÍòÔªÈËÃñ±Ò¡£¡£¡£¡£
2. ͨ¹ý¶Ô³õʼÑù±¾µÄÌØÕ÷¾ÙÐйØÁª£¬£¬£¬£¬£¬£¬·¢Ã÷ÒÔÏÂÓë±¾´Î¹¥»÷»î¶¯Ïà¹ØµÄÑù±¾£º
MD5£º
c27fc192811dad928730b24fd8150a03
2e5f24942932190e577319a7e81b83e4
33e884e59a7c1e1d6af5b19a283a04a7
4d4f7bfac3a17767cb9a7f88737b7ef5
061a8f66ec2f86f9668c0c157ed54b6c
5a02e019a2a7920d0b23326a616bf88f
a7389982054233436020f0ada0765a48
ATT&CK
¸ÃÑù±¾Ëù½ÓÄɵĹ¥»÷¼¼Õ½·¨ÓëATT&CKµÄÓ³ÉäÈçϱíËùʾ£º

IoCs