{"id":1309,"date":"2014-12-04T09:42:49","date_gmt":"2014-12-04T09:42:49","guid":{"rendered":"http:\/\/www.kodcafe.com\/?p=1309"},"modified":"2014-12-04T09:42:49","modified_gmt":"2014-12-04T09:42:49","slug":"ttnet-faturali-virus-dikkat-cryptolocker","status":"publish","type":"post","link":"https:\/\/www.kodcafe.com\/?p=1309","title":{"rendered":"Ttnet fatural\u0131 viruse dikkat. (Cryptolocker)"},"content":{"rendered":"<p>\u00dclkemizdeki internet kullan\u0131c\u0131lar\u0131n\u0131 hedef alan KriptoKilit sald\u0131r\u0131lar\u0131 daha \u00f6nce de ger\u00e7ekle\u015fmi\u015fti. Fakat bu sefer KriptoKilit g\u00fcncel s\u00fcr\u00fcm\u00fc ile daha b\u00fcy\u00fck bir tehdit olarak kar\u015f\u0131m\u0131za \u00e7\u0131kt\u0131. Kendini a\u00e7\u0131k bir \u015fekilde CryptoLocker olarak tan\u0131tan bu yeni zararl\u0131 yaz\u0131l\u0131m, yine kullan\u0131c\u0131lara ait belli uzant\u0131lara sahip dosyalar\u0131 \u015fifrelemekte ve bu verilerin kurtar\u0131lmas\u0131 i\u00e7in kullan\u0131c\u0131lardan \u201c\u015eifre \u00e7\u00f6zme yaz\u0131l\u0131m\u0131\u201d ad\u0131nda bir yaz\u0131l\u0131m sat\u0131n almalar\u0131n\u0131 istemektedir.<\/p>\n<p>Bula\u015fma \u015eekli<br \/>\nZararl\u0131 yaz\u0131l\u0131m fatura epostalar\u0131 \u015feklinde kullan\u0131c\u0131lara eposta g\u00f6ndermektedir.<br \/>\n<!--more--><\/p>\n<p><a href=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/ttnet.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1310\" src=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/ttnet.png\" alt=\"ttnet\" width=\"558\" height=\"424\" \/><\/a><\/p>\n<p style=\"text-align: center;\">\u015eekil -1<\/p>\n<p>\u015eekil 1- CryptoLocker Taraf\u0131ndan Kullan\u0131c\u0131lara G\u00f6nderilen Eposta<\/p>\n<p>\u015eekil 1\u2019de g\u00f6sterildi\u011fi \u00fczere fatura tutar\u0131 y\u00fcksek bir miktard\u0131r. Faturan\u0131n y\u00fcksek tutar\u0131ndan \u00f6t\u00fcr\u00fc fatura hakk\u0131nda bilgi almak isteyen kullan\u0131c\u0131lar faturay\u0131 g\u00f6rmek istediklerinde \u015eekil 2\u2019 de g\u00f6sterilen web adresine y\u00f6nlendirilmektedirler.<\/p>\n<p><a href=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1311\" src=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-2.png\" alt=\"sekil-2\" width=\"572\" height=\"424\" \/><\/a><\/p>\n<p>\u015eekil -2<br \/>\n\u015eekil 2- Fatura \u0130ndirme Sayfas\u0131<\/p>\n<p>Kap\u00e7ay\u0131 girip indir butonuna t\u0131klan\u0131ld\u0131\u011f\u0131nda \u201c.zip\u201d uzant\u0131l\u0131 bir dosya indirmektedir. Bu dosyan\u0131n i\u00e7inde ise \u201c.exe\u201d uzant\u0131l\u0131 fatura dosyas\u0131 bulunmaktad\u0131r.<\/p>\n<p><a href=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-3.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1312\" src=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-3.jpg\" alt=\"sekil-3\" width=\"472\" height=\"313\" \/><\/a>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u015fekil -3<br \/>\n\u015eekil 3-\u0130ndirilen Zararl\u0131 Dosya<\/p>\n<p>\u0130ndirilen bu zararl\u0131 yaz\u0131l\u0131m \u00e7al\u0131\u015ft\u0131r\u0131ld\u0131\u011f\u0131nda ise zararl\u0131 yaz\u0131l\u0131m kullan\u0131c\u0131n\u0131n bilgisayar\u0131na bula\u015fmakta ve i\u00e7i bo\u015f olmayan .doc, .docx, .pdf, .txt, .7z, .rar, .zip tipinde olan dosyalar \u015fifrelenmektedir. \u015eifrelenen dosyalar\u0131n yeni uzant\u0131lar\u0131 .encrypted olmaktad\u0131r. \u015eekil 4\u2019te bu durum g\u00f6sterilmektedir.<\/p>\n<p><a href=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1313\" src=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-4.png\" alt=\"sekil-4\" width=\"630\" height=\"226\" \/><\/a>\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0\u015eekil -4<br \/>\n\u015eekil 4- \u015eifrelenen Veriler<\/p>\n<p>Art\u0131k \u00f6nemli bilgileriniz dosyalar\u0131n\u0131z \u015fifrelenmi\u015ftir. \u00c7\u00f6zmek yana yana program arayacaks\u0131n\u0131z. Virus sizi kurban sectikten sonra sizi yonlendirecektir bu programa,<\/p>\n<p>\u015eekil 5- Verilerin \u015eifrelenmesinden Sonra Ekrana \u00c7\u0131kan G\u00f6r\u00fcnt\u00fc<\/p>\n<p><a href=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1314\" src=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-5.png\" alt=\"sekil-5\" width=\"578\" height=\"538\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>\u015eekil-5<\/p>\n<p>Zararl\u0131 yaz\u0131l\u0131m bilgisayardaki verileri \u015fifreleme i\u015flemini bitirdikten sonra ekrana \u015eekil 5\u2019teki gibi bir sayfa \u00e7\u0131karmaktad\u0131r. G\u00f6r\u00fcld\u00fc\u011f\u00fc \u00fczere zararl\u0131 yaz\u0131l\u0131m \u015fifrelenen veriler kar\u015f\u0131l\u0131\u011f\u0131nda \u015eifre \u00e7\u00f6zme yaz\u0131l\u0131m\u0131 ad\u0131 alt\u0131nda bir yaz\u0131l\u0131m\u0131n sat\u0131n al\u0131nmas\u0131n\u0131 istemektedir.<\/p>\n<p><a href=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1315\" src=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-6.png\" alt=\"sekil-6\" width=\"576\" height=\"579\" \/><\/a><\/p>\n<p>\u015eekil -6<br \/>\n\u015eekil 6- \u015eifre \u00c7\u00f6zme Yaz\u0131l\u0131m\u0131 Sat\u0131n Alma \u015eekli ve Tutar\u0131<\/p>\n<p>\u015eekil 5\u2019 te \u00e7\u0131kan g\u00f6r\u00fcnt\u00fcdeki linke t\u0131kland\u0131\u011f\u0131nda asl\u0131nda tor a\u011f\u0131 \u00fczerinde olan fakat bir tor proxy hizmeti veren sunucu \u00fczerinden eri\u015filebilen \u015eekil 6\u2019 daki gibi ki\u015fiye \u00f6zel bir web sayfas\u0131na y\u00f6nlendirilme yap\u0131lmaktad\u0131r.<\/p>\n<p>\u015eifre \u00e7\u00f6zme yaz\u0131l\u0131m\u0131n\u0131n sat\u0131n al\u0131nmas\u0131 konusunda ise 96 saat i\u00e7inde sat\u0131n al\u0131m\u0131 durumunda 2398 liradan 1198 liraya kadar indirim yapmaktad\u0131r.<\/p>\n<p>Zararl\u0131 yaz\u0131l\u0131m ilk yay\u0131ld\u0131\u011f\u0131nda antivir\u00fcs firmalar\u0131n\u0131n b\u00fcy\u00fck bir \u00e7o\u011funlu taraf\u0131ndan tan\u0131nmam\u0131\u015ft\u0131r. Virustotal sonu\u00e7lar\u0131 \u015eekil 7\u2019de g\u00f6sterilmektedir.<\/p>\n<p><a href=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1316\" src=\"http:\/\/www.kodcafe.com\/wp-content\/uploads\/2014\/12\/sekil-7.png\" alt=\"sekil-7\" width=\"550\" height=\"480\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>\u015eekil 7- Antivir\u00fcs Firmalar\u0131n\u0131n CryptoLocker Sonu\u00e7lar\u0131<\/p>\n<p>Dikkat Edilmesi Gerekenler<br \/>\nCryptoLocker gibi eposta yoluyla gelen zararl\u0131 yaz\u0131l\u0131mlardan etkilenmemek i\u00e7in gelen eposta adreslerine \u00e7ok dikkat edilmelidir. \u015eekil 8\u2019de ger\u00e7ek bir ttnet fatura eposta adresi ile \u015eekil 9\u2019da zararl\u0131 yaz\u0131l\u0131m\u0131n\u0131n eposta adresleri g\u00f6sterilmektedir.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\">TTNET GER\u00c7EK ADRES\u0130<\/p>\n<p style=\"text-align: center;\">https\/\/:efatura.ttnet.com.tr<\/p>\n<p style=\"text-align: center;\">\n<p style=\"text-align: center;\">SAHTE TTNET URL ADRES\u0130<\/p>\n<p style=\"text-align: center;\">http\/\/:efatura.ttnet-fatura.info<\/p>\n<p style=\"text-align: center;\">http\/\/:efatura.ttnet-fatura.biz<\/p>\n<p style=\"text-align: center;\">\n<p>TTNet&#8217;in fatura g\u00f6r\u00fcnt\u00fcleme adresi &#8220;https\/\/:efatura.ttnet.com.tr&#8221; iken zararl\u0131 yaz\u0131l\u0131m\u0131n kulland\u0131\u011f\u0131 ise &#8220;efatura.ttnet-fatura.info&#8221; ve \u201cefatura.ttnet-fatura.biz&#8221; adresleridir.<\/p>\n<p>Eposta olarak g\u00f6nderilen faturalar\u0131n uzant\u0131lar\u0131na dikkat edilmelidir. CyrptoLocker zararl\u0131 yaz\u0131l\u0131m\u0131 bir .exe dosyas\u0131d\u0131r. Oysaki TTNet faturalar\u0131 pdf \u015feklinde g\u00f6stermektedir.<\/p>\n<p>Kaynak: tubitakbilgem<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u00dclkemizdeki internet kullan\u0131c\u0131lar\u0131n\u0131 hedef alan KriptoKilit sald\u0131r\u0131lar\u0131 daha \u00f6nce de ger\u00e7ekle\u015fmi\u015fti. Fakat bu sefer KriptoKilit g\u00fcncel s\u00fcr\u00fcm\u00fc ile daha b\u00fcy\u00fck bir tehdit olarak kar\u015f\u0131m\u0131za \u00e7\u0131kt\u0131. Kendini a\u00e7\u0131k bir \u015fekilde CryptoLocker olarak tan\u0131tan bu yeni zararl\u0131 yaz\u0131l\u0131m, yine kullan\u0131c\u0131lara ait belli uzant\u0131lara sahip dosyalar\u0131 \u015fifrelemekte ve bu verilerin kurtar\u0131lmas\u0131 i\u00e7in kullan\u0131c\u0131lardan \u201c\u015eifre \u00e7\u00f6zme yaz\u0131l\u0131m\u0131\u201d ad\u0131nda bir [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1317,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,15],"tags":[96,434,459],"class_list":["post-1309","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-genel","category-guvenlik","tag-cyrptolocker","tag-ttnet","tag-virus"],"_links":{"self":[{"href":"https:\/\/www.kodcafe.com\/index.php?rest_route=\/wp\/v2\/posts\/1309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kodcafe.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kodcafe.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kodcafe.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kodcafe.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1309"}],"version-history":[{"count":0,"href":"https:\/\/www.kodcafe.com\/index.php?rest_route=\/wp\/v2\/posts\/1309\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kodcafe.com\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/www.kodcafe.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kodcafe.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1309"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kodcafe.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}