¶«Éƽ̨ÌáÐÑ£º¾¯Ìè·ÂðDeepSeek°²×°°üͶµÝWannaCryÀÕË÷Èí¼þ
Ðû²¼Ê±¼ä 2025-03-14¡°ÈÃÿһ¾äÈË»ú¶Ô»°¶¼Äþ¾²¿ÉÐÅ£¬ÈÃÿһ´ÎÖÇÄܽ»»¥¶¼·çÏÕ¿É¿Ø¡ª¡ªÕâÊÇÊôÓÚAIʱ´úµÄÄþ¾²ÔÊÐí¡£ ¡ª¡ª ¶«Éƽ̨¡±
AIËÙÀÀ£º
±¾ÎÄÌÖÂÛÁË2025ÄêËæ×ÅDeepSeek-R1Ðû²¼Òý·¢´óÄ£Ð͵±µØ»¯²¿ÊðÀ˳±ºó£¬¶«Éƽ̨VenusEyeÍþвÇ鱨ÖÐÐÄ·¢ÏÖÀÕË÷Èí¼þÍÅ»ïÀûÓ÷ÂðDeepSeek°²×°°ü½øÐй¥»÷µÄÇé¿ö£¬Ñо¿ÍŶӷÖÎöÁËÑù±¾²¢¸ø³öÏà¹ØÐÅÏ¢¡£Òªº¦Òªµã°üÂÞ:
1.¹¥»÷ÊÖ¶Î:ºÚ¿ÍÀûÓ÷ÂðDeepSeek°²×°°ü(Install_DeepSeek.exe)¹¥»÷£¬×Ô½âѹÊÍ·ÅWannaCryÀÕË÷Èí¼þºÍWindows XPHorror²¡¶¾¡£
2.Ñù±¾ÐÅÏ¢:³õʼ·Âð·¨Ê½Install_DeepSeek.exe£¬Îļþ¾Þϸ56.07MB£¬ÓÉ2¸öexe·¨Ê½´ò°ü×é³É£¬Í¨¹ýSFX½Å±¾Ö¸¶¨ÊÍ·Å·¾¶£¬ÊÍ·Åtasksche.exeºÍSETUP.EXEµ½C:\WINDOWSÎļþ¼Ð¡£
3.¶ñÒⷨʽ¹¦Ð§:tasksche.exeÊÍ·ÅWannaCryÄ£¿é¼ÓÃÜÎļþ;._cache tasksche.exe½âѹËõÄ£¿é¡¢½âÃܲ¢Ö´ÐÐDLL;DLL¼ÓÃÜÌض¨ºó׺Îļþ;SETUP.EXE (Windows XP Horror²¡¶¾)Ð޸ĴÅÅÌMBR£¬¸ü¸ÄµÇ¼½çÃæ¡£
4.¼ÓÃÜÎļþºó׺:±»¼ÓÃÜÎļþºó׺Öڶ࣬¼ÓÃܺó×·¼Ó.WNCRYºó׺£¬Ã¿¸öÎļþ¼ÐÊÍ·ÅÀÕË÷ÐźͲ¿ÃŽâÃÜ·¨Ê½¡£
5.ËÝÔ´¹ØÁª:ͨ¹ý±ÈÌرҽ»Ò×µØÖ··¢ÏÖ¸Ã×éÖ¯Á¬ÐøÓ¯Àû£¬ÀۼƻñÀûÔ¼54BTC£¬³¬Ç§ÍòÔªÈËÃñ±Ò£¬Í¬Ê±»¹¹ØÁªµ½¶à¸öÏà¹ØÑù±¾¡£
2025Ä꣬Ëæ×ÅDeepSeek-R1µÄÐû²¼£¬Ñ¸ËÙÒý·¢´óÄ£Ð͵±µØ»¯²¿ÊðÀ˳±¡£Ç°ËùδÓеĹØ×¢¶ÈÒ²ÎüÀÕË÷Èí¼þÍÅ»ïÒ²½ô¸úÈȵ㣬´î½¨µöÓãÍøÕ¾£¬Î±×°³ÉºÏ·¨µÄAIÈí¼þÏÂÔØƽ̨£¬ÓÕµ¼Óû§°²×°À¦°óÀÕË÷Èí¼þµÄ·ÂðÈí¼þ£¬´Ó¶ø¶ÔÊܺ¦Ö÷»úÉϵÄÎļþ½øÐмÓÃÜ£¬ÒÔвÆÈÊܺ¦ÕßÖ§¸¶Êê½ð¡£
¼¼Êõ·ÖÎö
´Ë´Î¹¥»÷»î¶¯µÄÑù±¾ÊÇαװ³ÉDeepSeek°²×°°üµÄexeÎļþ£¬¸ÃÎļþÖ´Ðкó£¬Í¨¹ý×Ô½âѹ·½Ê½ÊͷųöÀÕË÷Èí¼þWannaCryºÍ¿Ö²À²¡¶¾Windows XP Horror£¬·Ö±ðÖ´ÐÐÕâ2¸ö¶ñÒⷨʽ¡£WannaCryÊͷųöÀÕË÷¹¦Ð§Ä£¿é²¢Ö´ÐУ¬¼ÓÃÜÌض¨ºó׺µÄÎļþ£¬ÊͷųöÀÕË÷ÐÅ¡£¿Ö²À²¡¶¾Windows XP HorrorÐ޸ĴÅÅÌMBR£¬½«µÇ¼½çÃæÉèÖÃΪ÷¼÷ÃͼÏñ²¢²¥·Å¿Ö²À¶¯Í¼¡£
¸ÃÑù±¾ÕûÌåÁ÷³ÌÈçÏÂͼËùʾ£º

1¡¢³õʼ·Âð·¨Ê½
¸ÃÑù±¾ÎªÎ±×°³ÉDeepSeek°²×°·¨Ê½µÄexeÎļþ£¬ÆäÑù±¾ÐÅÏ¢¼ûÏÂ±í£º

³õʼ¹¥»÷Îļþ·ÂðÁËDeepSeekµÄͼ±ê£¬ÈçÏÂͼËùʾ£º
¸ÃexeÎļþÊôÓÚWinrar SFX×Ô½âѹÎļþ£¬ÓÉ2¸öexe·¨Ê½´ò°ü¶ø³É£¬ÈçÏÂͼËùʾ£º

¶ñÒâÈí¼þͨ¹ýSFX½Å±¾Ö¸¶¨tasksche.exeºÍSETUP.EXEµÄÊÍ·Å·¾¶£¬SFX½Å±¾ÄÚÈÝ°üÂÞ¡°DeepSeek¡±Ïà¹ØÐÅÏ¢£¬ÈçÏÂͼËùʾ£º

ͨ¹ýÓû§µã»÷´¥·¢SFX¶ñÒâÎļþºó£¬»á½«tasksche.exeºÍSETUP.EXEÊͷŵ½C:\WINDOWSÎļþ¼ÐÖУº

ͬʱ°²×°Ö´ÐÐtasksche.exeºÍSETUP.EXE£º

2¡¢ tasksche.exe
tasksche.exeÓÉDelphiÓïÑÔ¿ª·¢£¬Æ书ЧÊÇÊÍ·ÅWannaCryÀÕË÷Èí¼þµÄÄ£¿é£¬ÊµÏÖÎļþ¼ÓÃÜÀÕË÷¹¦Ð§¡£Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º

tasksche.exeµÄ×ÊÔ´ÎļþÖаüÂÞÒ»¸öEXE·¨Ê½£¬ÈçÏÂͼËùʾ£º

tasksche.exeÆô¶¯ºó£¬Ê×ÏÈ»á¼ÓÔظÃ×ÊÔ´£¬»ñÈ¡×ÊÔ´ÄÚÈÝ¡£È»ºó´´½¨Îļþ C:\WINDOWS\._cache_tasksche.exe£¬²¢½«×ÊÔ´ÖеÄÊý¾ÝдÈë¸ÃÎļþÖУ¬×îÖÕÖ´ÐиÃÎļþ¡£ÈçÏÂͼËùʾ£º

3¡¢ ._cache_tasksche.exe
._cache_tasksche.exeÎļþµÄÑù±¾ÐÅÏ¢¼ûÏÂ±í£º

._cache_tasksche.exeµÄÖ÷Òª¹¦Ð§ÊÇ´Ó×ÊÔ´ÖнâѹËõ³ö¹¦Ð§Ä£¿é£¬½âÃܳö1¸öDLL²¢Ö´ÐÐÆäÌض¨µÄµ¼³öº¯Êý¡£ÈçÏÂͼËùʾ£º

Ê×ÏÈÔÚ×¢²á±íHKLM\Software\WanaCrypt0r\wd ÖÐдÈ뵱ǰ·¾¶£¬¼Ç¼½ø³ÌµÄÊÂÇéĿ¼(work directory)£¬¹©ÆäËüÄ£¿éʹÓá£ÈçÏÂͼËùʾ£º

Ð޸ĺóµÄ×¢²á±íÈçÏÂͼËùʾ£º

È»ºóʹÓÃÃÜÔ¿¡°WNcry@2ol7¡±½«Ç¶ÈëÔÚ×ÊÔ´ÖеÄzipѹËõ°ü½âѹµ½C:\WINDOWS¡£ÈçÏÂͼËùʾ£º

×ÊÔ´ÖеÄzipѹËõ°üÈçÏÂͼËùʾ£º

¸ÃѹËõ°üÖÐÓжà¸öÎļþ£¬ÈçÏÂͼËùʾ£º

¶ÁÈ¡Îļþ t.wnry µÄÄÚÈݲ¢½âÃܳöDLLÎļþ£¬ÈçÏÂͼËùʾ£º

½âÃܳöµÄDLLÎļþÊÇÀÕË÷Ä£¿é£¬¾ßÓÐÃûΪTaskStartµÄµ¼³öº¯Êý£¬ÈçÏÂͼËùʾ£º

ͨ¹ýµ÷Óøõ¼³öº¯Êý£¬Ö´ÐмÓÃÜÀÕË÷¹¦Ð§¡£
4¡¢ÀÕË÷Ä£¿é
ÉÏÒ»½×¶Î½âÃܳöµÄDLLÎļþµÄÔʼÃû³ÆΪkgptbeilcq£¬ÂôÁ¦ÊµÏÖ¾ßÌåµÄ¼ÓÃÜÀÕË÷¹¦Ð§¡£Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º

¸ÃDLLµÄÖ÷Òª¹¦Ð§ÈçÏÂͼËùʾ£º

Ê×ÏÈÖÕÖ¹Êý¾Ý¿âÏà¹Ø½ø³Ì£¬Ê¹µÃÄܹ»¼ÓÃÜÊý¾Ý¿âÎļþ¡£ÈçÏÂͼËùʾ£º

»ñÈ¡´ÅÅÌÇý¶¯Æ÷Ãû³Æ£¬±éÀú¸÷´ÅÅÌ¡£ÈçÏÂͼËùʾ£º

±éÀúÎļþ¼Ð£¬¼ì²éÎļþµÄÃû³ÆºÍºó׺£¬ÈçÏÂͼËùʾ£º

¼ÓÃÜÒÔϺó׺ÃûµÄÎļþ£º
Îļþ±»¼ÓÃܺ󣬻ᱻ׷¼Óºó׺Ãû .WNCRY¡£
ÔÚÿ¸öÎļþ¼ÐÖÐÊÍ·ÅÃûΪ @Please_Read_Me@.txt µÄÀÕË÷ÐźÍÃûΪ @WanaDecryptor@.exe µÄ½âÃÜ·¨Ê½¡£ÀÕË÷ÐÅÄÚÈÝÈçÏÂͼËùʾ£º
Êܺ¦Õßͨ¹ý½âÃÜ·¨Ê½ @WanaDecryptor@.exe£¬¿ÉÒÔ½âÃܳö10¸ö±»¼ÓÃܵÄÎļþ¡£¸Ã½âÃÜ·¨Ê½ÏÔʾÁËÌáʾÐÅÏ¢ºÍ±ÈÌرҵØÖ·£¬²¢½øÐе¹¼Æʱ¡£ÈçÏÂͼËùʾ£º
5¡¢SETUP.EXE
SETUP.EXEÊǹÅÀϵÄWindowsXP Horror²¡¶¾£¬¸Ã²¡¶¾»áÐ޸ĴÅÅÌMBR£¬½«µÇ¼½çÃæÐÞ¸ÄΪ÷¼÷ÃͼÏñ£¬²¢²¥·Å¿Ö²À¶¯Í¼¡£
Ñù±¾ÐÅÏ¢¼ûÏÂ±í£º

Ñù±¾Ö´Ðкó£¬Ê×ÏÈÍ˳öµÇ¼½çÃ棬ÏÔʾ¡°Installing Windows Updates¡±µÈÌáʾ£¬ÔÚ½ø¶Èµ½66%ʱ£¬»áµ¯³ö¡°Setup will use the file 666.sys¡±µÄÌáʾ¡£ÈçÏÂͼËùʾ£º

µÇ¼½çÃæ»á±»»»³É÷¼÷ÃͼÏñ£¬²»Í£Çл»ÑªÐÈͼƬ£¬²¢²¥·Å¿Ö²À¶¯Í¼¡£
µã»÷×ÀÃæµÄͼ±êºó£¬»áµ¯³öÌáʾ¿ò£¬²¢°Ñͼ±êÒƶ¯µ½»ØÊÕÕ¾¡£
²Ù×÷ϵͳÍ߽ⲢÏÔʾºìÉ«Åä¾°£¬ÈçÏÂͼËùʾ£º

ËÝÔ´¹ØÁª
1. ͨ¹ý¶Ô¸Ã×éÖ¯ÌṩµÄ±ÈÌرҽ»Ò×µØÖ·£¬¸ú×Ùµ½¸Ã×éÖ¯ÔÚ2024ÄêÄ©ÊÕµ½¼¸±ÊÊܺ¦ÕßÖ§¸¶µÄBTC¡£ËµÃ÷¸Ã×éÖ¯ÒÀ¾ÉÔÚÒÀ¿¿ÀÕË÷Èí¼þÁ¬ÐøÓ¯Àû£º

ͬʱͨ¹ý¶ÔÀúÊ·ÐÅÏ¢µÄͳ¼Æ£¬¿ÉÒÔÊӲ쵽¸Ã×éÖ¯ÔÚÅû¶µÄµØÖ·ÉÏÀۼƻñÀûÔ¼54BTC£¬°´µ±Ç°»ãÂʹÀËãÒÑÁè¼ÝǧÍòÔªÈËÃñ±Ò¡£
2. ͨ¹ý¶Ô³õʼÑù±¾µÄÌØÕ÷½øÐйØÁª£¬·¢ÏÖÒÔÏÂÓë±¾´Î¹¥»÷»î¶¯Ïà¹ØµÄÑù±¾£º
MD5£º
c27fc192811dad928730b24fd8150a03
2e5f24942932190e577319a7e81b83e4
33e884e59a7c1e1d6af5b19a283a04a7
4d4f7bfac3a17767cb9a7f88737b7ef5
061a8f66ec2f86f9668c0c157ed54b6c
5a02e019a2a7920d0b23326a616bf88f
a7389982054233436020f0ada0765a48
ATT&CK
¸ÃÑù±¾Ëù½ÓÄɵĹ¥»÷¼¼Õ½·¨ÓëATT&CKµÄÓ³ÉäÈçϱíËùʾ£º

IoCs