设为首页 - 加入收藏 ASP站长网(Aspzz.Cn)- 科技、建站、经验、云计算、5G、大数据,站长网!
热搜: 数据 手机 公司
当前位置: 首页 > 服务器 > 安全 > 正文

勒索病毒WannaCry深度技术分析(3)

发布时间:2017-05-22 14:19 所属栏目:53 来源:雷锋网
导读:另外一个样本除了修改了"Kill Switch"域名,还修改了病毒携带勒索模块。经过测试勒索代码已经被修改坏了,无法运行。如下图: 除了以上两个样本,火绒还截获另一个人为修改的” WannaCry “样本,同样被修改的不能

另外一个样本除了修改了"Kill Switch"域名,还修改了病毒携带勒索模块。经过测试勒索代码已经被修改坏了,无法运行。如下图:

除了以上两个样本,火绒还截获另一个人为修改的” WannaCry “样本,同样被修改的不能运行,火绒依然可以检测。SHA256如下:

99c0d50b088df94cb0b150a203de6433cb97d4f8fd3b106ce442757c5faa35c4

截止到本篇分析完成火绒还没截获所谓关闭“Kill Switch”开关的病毒样本。

四、附录

样本SHA256

Worm

24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c

32f24601153be0885f11d62e0a8a2f0280a2034fc981d8184180c5d3b1b9e8cf

C8d816410ebfb134ee14d287a34cea9d34d627a2c5e16234ab726cf9fde47ec6

Ransom

ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa

4a468603fdcb7a2eb5770705898cf9ef37aade532a7964642ecd705a74794b79

2ca2d550e603d74dedda03156023135b38da3630cb014e3d00b1263358c5f00d

e2d1e34c79295e1163481b3683633d031cab9e086b9ae2ac5e30b08def1b0b47

ec9d3423338d3a0bfccacaf685366cfb8a9ece8dedbd08e8a3d6446a85019d3a

f5cbff5c100866dd744dcbb68ee65e711f86c257dfcc41790a8f63759220881e

f7c7b5e4b051ea5bd0017803f40af13bed224c4b0fd60b890b6784df5bd63494

88be9ee3ce0f85086aec1f2f8409247e8ab4a2a7c8a07af851f8df9814adeee5

5d26835be2cf4f08f2beeff301c06d05035d0a9ec3afacc71dff22813595c0b9

e989935bb173c239a2b3c855161f56de7c24c4e7a79351d3a457dbf082b84d7b

4d67e6c708062e970d020413e460143ed92bebd622e4b8efd6d6a9fdcd07bda8

eeb9cd6a1c4b3949b2ff3134a77d6736b35977f951b9c7c911483b5caeb1c1fb

24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c

c365ddaa345cfcaff3d629505572a484cff5221933d68e4a52130b8bb7badaf9

32f24601153be0885f11d62e0a8a2f0280a2034fc981d8184180c5d3b1b9e8cf

C8d816410ebfb134ee14d287a34cea9d34d627a2c5e16234ab726cf9fde47ec6

fc626fe1e0f4d77b34851a8c60cdd11172472da3b9325bfe288ac8342f6c710a

be22645c61949ad6a077373a7d6cd85e3fae44315632f161adc4c99d5a8e6844

1be0b96d502c268cb40da97a16952d89674a9329cb60bac81a96e01cf7356830

c354a9a0bbb975c15e884916dce251807aae788e68725b512a95f7b580828c64

6bf1839a7e72a92a2bb18fbedf1873e4892b00ea4b122e48ae80fac5048db1a7

e0ec1ad116d44030ad9ef5b51f18ff6160a227a46ffcf64693335c7fb946fad6

63c8a30963265353532d80a41cae5d54b31e5c2d6b2a92551d6f6dcadd0dedeb

b4d607fae7d9745f9ced081a92a2dcf96f2d0c72389a66e20059e021f0b58618

67eedfe3f13e2638de7d028aaf1e116410562cc5d15a9e62a904f758770dc6bf

5f2b33deee53390913fd5fb3979685a3db2a7a1ee872d47efc4f8f7d9438341f

01b628fa60560c0cb4a332818cb380a65d0616d19976c084e0c3eaa433288b88

16493ecc4c4bc5746acbe96bd8af001f733114070d694db76ea7b5a0de7ad0ab

d8a9879a99ac7b12e63e6bcae7f965fbf1b63d892a8649ab1d6b08ce711f7127

7e369022da51937781b3efe6c57f824f05cf43cbd66b4a24367a19488d2939e4

9b60c622546dc45cca64df935b71c26dcf4886d6fa811944dbc4e23db9335640

a1d23db1f1e3cc2c4aa02f33fec96346d9d5d5039ffc2ed4a3c65c34b79c5d93

ceb51f66c371b5233e474a605a945c05765906494cd272b0b20b5eca11626c61

3dcbb0c3ede91f8f2e9efb0680fe0d479ff9b9cd94906a86dec415f760c163e1

043e0d0d8b8cda56851f5b853f244f677bd1fd50f869075ef7ba1110771f70c2

b66db13d17ae8bcaf586180e3dcd1e2e0a084b6bc987ac829bbff18c3be7f8b4

940dec2039c7fca4a08d08601971836916c6ad5193be07a88506ba58e06d4b4d

b3c39aeb14425f137b5bd0fd7654f1d6a45c0e8518ef7e209ad63d8dc6d0bac7

aee20f9188a5c3954623583c6b0e6623ec90d5cd3fdec4e1001646e27664002c

a141e45c3b121aa084f23ebbff980c4b96ae8db2a8d6fde459781aa6d8a5e99a

09a46b3e1be080745a6d8d88d6b5bd351b1c7586ae0dc94d0c238ee36421cafa

7966d843e5760ece99bd32a15d5cd58dc71b1324fdc87e33be46f377486a1b4b

11d0f63c06263f50b972287b4bbd1abe0089bc993f73d75768b6b41e3d6f6d49

5d8123db7094540954061ab1fbc56eedcd9e01110b62d0f54206e3e75a39776a

11011a590796f6c52b046262f2f60694310fa71441363d9116ada7248e58509a

9cc32c94ce7dc6e48f86704625b6cdc0fda0d2cd7ad769e4d0bb1776903e5a13

4186675cb6706f9d51167fb0f14cd3f8fcfb0065093f62b10a15f7d9a6c8d982

5ad4efd90dcde01d26cc6f32f7ce3ce0b4d4951d4b94a19aa097341aff2acaec

b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25

63bd325cc229226377342237f59a0af21ae18889ae7c7a130fbe9fd5652707af

a50d6db532a658ebbebe4c13624bc7bdada0dbf4b0f279e0c151992f7271c726

2584e1521065e45ec3c17767c065429038fc6291c091097ea8b22c8a502c41dd

b47e281bfbeeb0758f8c625bed5c5a0d27ee8e0065ceeadd76b0010d226206f0

c1f929afa37253d28074e8fdaf62f0e3447ca3ed9b51203f676c1244b5b86955

4c69f22dfd92b54fbc27f27948af15958adfbc607d68d6ed0faca394c424ccee

201f42080e1c989774d05d5b127a8cd4b4781f1956b78df7c01112436c89b2c9

22ccdf145e5792a22ad6349aba37d960db77af7e0b6cae826d228b8246705092

5dee2ac983640d656f9c0ef2878ee34cda5e82a52d3703f84278ac372877346d

1e6753f948fa648ef9e0d85795b7f090968ee1f240efc0628283776ea55ccb0f

7bb9ea2c0f53fa96883c54fa4b107764a6319f6026e4574c9feec2cb7d9e7d21

9174c0772a5f871e58c385c01eea1ed4b706675bf9bd6aa1667b9d3c40acb6fc

3e6de9e2baacf930949647c399818e7a2caea2626df6a468407854aaa515eed9

a3900daf137c81ca37a4bf10e9857526d3978be085be265393f98cb075795740

ca29de1dc8817868c93e54b09f557fe14e40083c0955294df5bd91f52ba469c8

57c12d8573d2f3883a8a0ba14e3eec02ac1c61dee6b675b6c0d16e221c3777f4

fc626fe1e0f4d77b34851a8c60cdd11172472da3b9325bfe288ac8342f6c710a

190d9c3e071a38cb26211bfffeb6c4bb88bd74c6bf99db9bb1f084c6a7e1df4e

31c2024d0df684a968115e4c3fc5703ef0ea2de1b69ece581589e86ba084568a

0bb221bf62d875cca625778324fe5bd6907640f6998d21f3106a0447aabc1e3c

e14f1a655d54254d06d51cd23a2fa57b6ffdf371cf6b828ee483b1b1d6d21079

e8450dd6f908b23c9cbd6011fe3d940b24c0420a208d6924e2d920f92c894a96

aea79945c0f2f60de43193e1973fd30485b81d06f3397d397cb02986b31e30d9

9fb39f162c1e1eb55fbf38e670d5e329d84542d3dfcdc341a99f5d07c4b50977

78e3f87f31688355c0f398317b2d87d803bd87ee3656c5a7c80f0561ec8606df

7c465ea7bcccf4f94147add808f24629644be11c0ba4823f16e8c19e0090f0ff

24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c

2ddc29a646c1579e79c0b4cc86a5d0c9ed57af6ff240e959b17cdcf77d863026

4b76e54de0243274f97430b26624c44694fbde3289ed81a160e0754ab9f56f32

498b8b889bb1f02a377a6a8f0e39f9db4e70cccad820c6e5bc5652e989ae6204

f8812f1deb8001f3b7672b6fc85640ecb123bc2304b563728e6235ccbe782d85

dff26a9a44baa3ce109b8df41ae0a301d9e4a28ad7bd7721bbb7ccd137bfd696

593bbcc8f34047da9960b8456094c0eaf69caaf16f1626b813484207df8bd8af

149601e15002f78866ab73033eb8577f11bd489a4cea87b10c52a70fdf78d9ff

ac7f0fb9a7bb68640612567153a157e91d457095eadfd2a76d27a7f65c53ba82

雷锋网注:本文由火绒安全授权雷锋网宅客频道转载

雷锋网版权文章,未经授权禁止转载。

(编辑:ASP站长网)

网友评论
推荐文章
    热点阅读