{"id":10639,"date":"2022-04-20T14:34:34","date_gmt":"2022-04-20T11:34:34","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=10639"},"modified":"2022-04-20T14:34:34","modified_gmt":"2022-04-20T11:34:34","slug":"yanlouwang-decryptor","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/yanlouwang-decryptor\/10639\/","title":{"rendered":"Yanluowang k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m i\u00e7in \u015fifre \u00e7\u00f6z\u00fcc\u00fc"},"content":{"rendered":"<p>Dosyalar\u0131n\u0131 hi\u00e7bir \u015fey hemen kurtarmaya yard\u0131mc\u0131 olmasa bile, genellikle fidye yaz\u0131l\u0131m\u0131 kurbanlar\u0131na umutsuzlu\u011fa kap\u0131lmamalar\u0131n\u0131 ve hi\u00e7bir dosyay\u0131 silmemelerini tavsiye ederiz. Sonu\u00e7ta bir g\u00fcn, polis sald\u0131rganlar\u0131n altyap\u0131s\u0131n\u0131 ele ge\u00e7irebilir veya ara\u015ft\u0131rmac\u0131lar k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m algoritmalar\u0131ndaki kusurlar\u0131 ortaya \u00e7\u0131karabilir. \u0130kinciye bir \u00f6rnek, Kaspersky\u2019nin Yanluowang fidye yaz\u0131l\u0131m\u0131 analizi. Uzmanlar\u0131m\u0131z, sald\u0131rganlar\u0131n koduna ihtiya\u00e7 duymadan dosya kurtarmay\u0131 sa\u011flayan bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 buldu. Ancak bu, belirli durumlar i\u00e7in ge\u00e7erli.<\/p>\n<h2>Yanluowang\u2019\u0131n \u015fifreledi\u011fi dosyalar\u0131n \u015fifresi nas\u0131l \u00e7\u00f6z\u00fcl\u00fcr<\/h2>\n<p>Yanluowang k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131ndaki g\u00fcvenlik a\u00e7\u0131\u011f\u0131 sayesinde, bilinen a\u00e7\u0131k metin sald\u0131r\u0131s\u0131 ile dosya \u015fifresi \u00e7\u00f6z\u00fclebilir. Bu y\u00f6ntem, ayn\u0131 metnin iki versiyonu \u2013 biri temiz, biri \u015fifreli \u2013 mevcutsa \u015fifreleme algoritmas\u0131n\u0131 \u00e7\u00f6zebilir. Yani, kurban \u015fifrelenmi\u015f dosyalar\u0131n baz\u0131lar\u0131n\u0131n temiz kopyalar\u0131na sahipse veya bunlar\u0131 nereden alaca\u011f\u0131n\u0131 biliyorsa, y\u00fckseltilmi\u015f <a href=\"https:\/\/noransom.kaspersky.com\/tr\/\" target=\"_blank\" rel=\"noopener\">Rannoh \u015eifre \u00c7\u00f6z\u00fcc\u00fcm\u00fcz<\/a> bunlar\u0131 analiz edebilir ve bilgilerin geri kalan\u0131n\u0131 kurtarabilir.<\/p>\n<p>Bir engel var: Yanluowang, dosyalar\u0131 boyutlar\u0131na ba\u011fl\u0131 olarak biraz farkl\u0131 \u015fekilde bozar. K\u00fc\u00e7\u00fck dosyalar\u0131 (3 GB\u2019den az) tamamen, b\u00fcy\u00fck dosyalar\u0131 ise k\u0131smen \u015fifreler. Yani, \u015fifrelerin \u00e7\u00f6z\u00fclmesi i\u00e7in farkl\u0131 boyutlarda temiz dosyalara ihtiya\u00e7 var. 3 GB\u2019tan k\u00fc\u00e7\u00fck dosyalarda, dosyan\u0131n orijinal ve \u015fifrelenmi\u015f s\u00fcr\u00fcm\u00fcn\u00fcn 1024 bayt veya daha b\u00fcy\u00fck olmas\u0131 yeterli. 3 GB\u2019tan b\u00fcy\u00fck dosyalar\u0131n kurtar\u0131lmas\u0131 i\u00e7in ise, uygun boyutta orijinal dosyalar gerekiyor. Ancak, 3 GB\u2019tan b\u00fcy\u00fck temiz bir dosya bulursan\u0131z, etkilenen t\u00fcm bilgileri kurtarmak genellikle m\u00fcmk\u00fcn.<\/p>\n<h2>Yanluowang nedir ve neden tehlikeli?<\/h2>\n<p>Yanluowang, bilinmeyen sald\u0131rganlar\u0131n b\u00fcy\u00fck \u015firketleri hedef almak i\u00e7in kulland\u0131\u011f\u0131 nispeten yeni bir fidye yaz\u0131l\u0131m\u0131. \u0130lk olarak ge\u00e7en y\u0131l\u0131n sonlar\u0131nda <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-yanluowang-ransomware-used-in-targeted-enterprise-attacks\/\" target=\"_blank\" rel=\"noopener nofollow\">duyuruldu<\/a>. \u015eifreleme s\u00fcrecini tetiklemek i\u00e7in, k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n belirli arg\u00fcmanlar\u0131 almas\u0131 gerekir. Bu da, bir operat\u00f6r\u00fcn sald\u0131r\u0131y\u0131 manuel olarak kontrol etti\u011fini g\u00f6sterir. Yanluowang\u2019\u0131n kurbanlar\u0131 aras\u0131nda ABD, Brezilya ve T\u00fcrkiye\u2019deki \u015firketler bulunuyor.<\/p>\n<p>Yanluowang ile ilgili teknik ayr\u0131nt\u0131lar ve risk g\u00f6stergeleri i\u00e7in <a href=\"https:\/\/securelist.com\/how-to-recover-files-encrypted-by-yanlouwang\/106332\/\" target=\"_blank\" rel=\"noopener\">Secure List g\u00f6nderimizi<\/a> inceleyin.<\/p>\n<h2>Yanluowang\u2019a kar\u015f\u0131 nas\u0131l korunursunuz<\/h2>\n<p>Fidye yaz\u0131l\u0131mlar\u0131na kar\u015f\u0131 temel koruma i\u00e7in standart ipu\u00e7lar\u0131m\u0131z\u0131 dikkate al\u0131n: yaz\u0131l\u0131m\u0131 her zaman g\u00fcncel tutun; veri yedeklerini \u00e7evrimd\u0131\u015f\u0131 depolay\u0131n; <a href=\"https:\/\/k-asap.com\/tr\/?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______&amp;utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=tr_wpplaceholder_nv0092&amp;utm_content=link&amp;utm_term=tr_kdaily_organic_avmwswubv8qh92b\" target=\"_blank\" rel=\"noopener\">\u00e7al\u0131\u015fanlara temel siber g\u00fcvenlik e\u011fitimi<\/a> verin; ba\u011fl\u0131 t\u00fcm cihazlar i\u00e7in <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">fidye yaz\u0131l\u0131mlar\u0131na kar\u015f\u0131 yeterli koruma<\/a> sa\u011flay\u0131n.<\/p>\n<p>Ancak, hedefli sald\u0131r\u0131lar ve hatta manuel kontrol edilen sald\u0131r\u0131lar g\u00f6z \u00f6n\u00fcne al\u0131nd\u0131\u011f\u0131nda, kapsaml\u0131 bir g\u00fcvenlik yakla\u015f\u0131m\u0131na ihtiyac\u0131n\u0131z var. Dolay\u0131s\u0131yla, uzmanlar\u0131m\u0131z ek olarak \u015funlar\u0131 \u00f6neriyor:<\/p>\n<ul>\n<li>\u015e\u00fcpheli ba\u011flant\u0131lar\u0131 zaman\u0131nda tespit etmek i\u00e7in giden trafi\u011fi izlemek;<\/li>\n<li>D\u00fczenli siber g\u00fcvenlik denetimleri yapmak;<\/li>\n<li>SOC \u00e7al\u0131\u015fanlar\u0131n\u0131 <a href=\"https:\/\/opentip.kaspersky.com\/?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______&amp;utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=tr_wpplaceholder_nv0092&amp;utm_content=link&amp;utm_term=tr_kdaily_organic_undefined\" target=\"_blank\" rel=\"noopener nofollow\">mevcut siber tehdit verileri<\/a> hakk\u0131nda bilgilendirmek;<\/li>\n<li>\u00dc\u00e7\u00fcnc\u00fc taraf uzmanlar ile <a href=\"https:\/\/www.kaspersky.com\/enterprise-security\/managed-detection-and-response?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener nofollow\">ba\u011flant\u0131 kurmak<\/a>.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-trial-leadgen\">\n","protected":false},"excerpt":{"rendered":"<p>Kriptanalistlerimiz, Yanluowang&#8217;\u0131n \u015fifreledi\u011fi dosyalar\u0131n \u015fifresini \u00e7\u00f6zmenin bir yolunu buldu.<\/p>\n","protected":false},"author":2581,"featured_media":10640,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[2022,591,2545,828],"class_list":{"0":"post-10639","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-fidye-yazilim","10":"tag-fidye-yazilimi","11":"tag-kripto-kotu-amacli-yazilim","12":"tag-sifre-cozucu"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/yanlouwang-decryptor\/10639\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/yanlouwang-decryptor\/24059\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/yanlouwang-decryptor\/19545\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/yanlouwang-decryptor\/9881\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/yanlouwang-decryptor\/26383\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/yanlouwang-decryptor\/24330\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/yanlouwang-decryptor\/24683\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/yanlouwang-decryptor\/27097\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/yanlouwang-decryptor\/26643\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/yanlouwang-decryptor\/33091\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/yanlouwang-decryptor\/44131\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/yanlouwang-decryptor\/18790\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/yanlouwang-decryptor\/19326\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/yanlouwang-decryptor\/15942\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/yanlouwang-decryptor\/28488\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/yanlouwang-decryptor\/28210\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/yanlouwang-decryptor\/24956\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/yanlouwang-decryptor\/30410\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/yanlouwang-decryptor\/30178\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/fidye-yazilimi\/","name":"Fidye Yaz\u0131l\u0131m\u0131"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2581"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=10639"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10639\/revisions"}],"predecessor-version":[{"id":10641,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10639\/revisions\/10641"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/10640"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=10639"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=10639"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=10639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}