{"id":2368,"date":"2016-08-29T04:29:47","date_gmt":"2016-08-29T08:29:47","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=2368"},"modified":"2019-11-15T14:58:00","modified_gmt":"2019-11-15T11:58:00","slug":"wildfire-ransomware-decryptor","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/wildfire-ransomware-decryptor\/2368\/","title":{"rendered":"WildFire fidye yaz\u0131l\u0131m\u0131 &#8216;s\u00f6nd\u00fcr\u00fcld\u00fc&#8217;"},"content":{"rendered":"<p>Saklayacak bir \u015fey yok: fidye yaz\u0131l\u0131m\u0131 ac\u0131l\u0131 bir tehdittir. Ve yak\u0131n zamanda da bitmeyecek \u2013 tabi birka\u00e7 istisna hari\u00e7.<\/p>\n<p><strong>\u0130yi haber<\/strong>: Bu hikaye o istisnalardan biri. Ge\u00e7ti\u011fimiz g\u00fcnlerde, Kaspersky Lab Hollanda polisine yard\u0131m ederek ba\u015fka bir fidye yaz\u0131l\u0131m\u0131 t\u00fcr\u00fcn\u00fc etkisiz hale getirdi \u2013 WildFire, temel olarak Hollanda sakinlerini tehdit eden bir yaz\u0131l\u0131m.<\/p>\n<p>WildFire h\u0131zl\u0131ca paran\u0131z\u0131 almak isteyen a\u00e7g\u00f6zl\u00fc trojanlardan biri \u2013 geciken \u00f6demeler i\u00e7in fazladan para istiyor. \u0130lk sekiz g\u00fcn i\u00e7erisinde 300$, sekiz g\u00fcnden sonra bu rakam \u00fc\u00e7 kat\u0131 oluyor.<\/p>\n<p>Hollanda polisinin Ulusal Y\u00fcksek Teknoloji Su\u00e7 Birimi ele ge\u00e7irilen y\u00f6netim ve kontrol sunucusunda 5,800 adet \u015fifre \u00e7\u00f6zme anahtar\u0131 ele ge\u00e7irdi. Ele ge\u00e7irilen bu keyleri de yeni \u015fifre \u00e7\u00f6z\u00fcc\u00fcm\u00fczde kulland\u0131k. \u015eifre \u00e7\u00f6z\u00fcc\u00fc i\u00e7in <a href=\"http:\/\/nomorenasom.org\" target=\"_blank\" rel=\"noopener nofollow\">nomorenasom.org<\/a>, <a href=\"http:\/\/noransom.kaspersky.com\" target=\"_blank\" rel=\"noopener\">noransom.kaspersky.com<\/a> ve <a href=\"http:\/\/support.kaspersky.com\" target=\"_blank\" rel=\"noopener\">support.kaspersky.com<\/a> adreslerimizi ziyaret edebilirsiniz.<\/p>\n<p>Hollanda polisi ele ge\u00e7irilen zararl\u0131 sunucu ile t\u00fcm WildFire ma\u011fdurlar\u0131na bildirim g\u00f6nderip \u00fccretsiz \u015fifre \u00e7\u00f6z\u00fcc\u00fc arac\u0131m\u0131z\u0131 indirebileceklerini belirten sunucu ile de\u011fi\u015ftirildi.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"tr\" dir=\"ltr\">Shade fidye yaz\u0131l\u0131m\u0131 ile ba\u015f\u0131n\u0131z dertte mi? Bunun i\u00e7in \u00fccretsiz \u00e7\u00f6z\u00fcm\u00fcm\u00fcz var! <a href=\"https:\/\/t.co\/Jn6A54xeZM\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/Jn6A54xeZM<\/a> <a href=\"https:\/\/t.co\/jncYMzV9JP\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/jncYMzV9JP<\/a><\/p>\n<p>\u2014 Kaspersky T\u00fcrkiye (@KasperskyTR) <a href=\"https:\/\/twitter.com\/KasperskyTR\/status\/757850601266872323?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">July 26, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><strong>Hat\u0131rlatma <\/strong><br>\nBa\u015ftan alal\u0131m, WildFire Hollandal\u0131lar\u0131 ve Bel\u00e7ikal\u0131lar\u0131 ya\u015fayanlar\u0131 hedef ald\u0131. Asl\u0131nda kurbanlar\u0131n %90\u2019\u0131ndan fazlas\u0131 Hollanda ve Bel\u00e7ika\u2019da ya\u015fayanlard\u0131.<\/p>\n<p>WildFire \u015fu \u015fekilde yay\u0131ld\u0131, Hollanda\u2019da insanlara kargo tesliminde sorun \u00e7\u0131kt\u0131\u011f\u0131n\u0131 belirten mail g\u00f6nderildi. Bu mailde al\u0131c\u0131 i\u00e7in tekrar tarih ayarlama formu indirme linki bulunuyordu. Sitede Hollanda domaini vard\u0131 ve genel olarak \u00e7ok ikna edici g\u00f6z\u00fck\u00fcyordu.<\/p>\n<p>Kurbanlar siteyi ziyaret ediyor, belgeyi indiriyor, a\u00e7\u0131yor ve zararl\u0131 makrolar\u0131 aktif ediyordu. Bu makrolar WildFire\u2019\u0131 indirmeyi ba\u015flat\u0131yor ve indirdikten sonra \u00e7al\u0131\u015ft\u0131r\u0131yor. Su\u00e7lular\u0131n k\u00f6t\u00fc niyetlerini g\u00f6steriye d\u00f6n\u00fc\u015ft\u00fcrd\u00fckleri yer de bu makronun kodlar\u0131. Makronun kodlar\u0131 Pink Floyd\u2019un \u201cMoney\u201d \u015fark\u0131s\u0131n\u0131n s\u00f6zlerini i\u00e7eriyor.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2370\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2016\/08\/06013951\/wildfire-screen.png\" alt=\"wildfire-screen\" width=\"866\" height=\"447\"><\/p>\n<p>Kendinizi nas\u0131l korursunuz<br>\nSadece bir \u00e7e\u015fit zararl\u0131 yaz\u0131l\u0131m olsayd\u0131 ve tek bir \u015fekilde da\u011f\u0131lsayd\u0131, siber g\u00fcvenlik \u00e7antada keklik olurdu. Maalesef, durum \u00f6yle de\u011fil, milyonlarca farkl\u0131 tehdit var. G\u00fcvende kalmak i\u00e7in, bizim \u00f6nerimizi izleyin;<br>\n1. E\u011fer WildFire\u2019dan etkilendiyseniz, <a href=\"http:\/\/nomoreransom.org\" target=\"_blank\" rel=\"noopener nofollow\">nomoreransom.org<\/a> adresinden \u00fccretsiz \u015fifre \u00e7\u00f6z\u00fcc\u00fcm\u00fcz\u00fc indirin. Bu sitede d\u00fczinelerce fidye yaz\u0131l\u0131m\u0131na kar\u015f\u0131 \u015fifre \u00e7\u00f6z\u00fcc\u00fcler mevcut.<br>\n2. Dosyalar\u0131n\u0131z\u0131n \u015fifresini \u00e7\u00f6zd\u00fckten sonra, bilgisayar\u0131n\u0131z\u0131 tarat\u0131n \u2013 WilFire sisteminize s\u0131zm\u0131\u015f tek fidye yaz\u0131l\u0131m\u0131 olmayabilir. \u00dccretsiz <a href=\"http:\/\/support.kaspersky.com\/8517?_ga=1.184641899.312917906.1457175256\" target=\"_blank\" rel=\"noopener noreferrer\">Kaspersky Virus Removal Tool<\/a>\u2018u indirerek sisteminizi tarayabilirsiniz.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">10 tips to protect your files from ransomware <a href=\"https:\/\/t.co\/o0IpUU9CHb\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/o0IpUU9CHb<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/iteducation?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#iteducation<\/a> <a href=\"https:\/\/t.co\/I47sPIiWFF\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/I47sPIiWFF<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/671348678607642624?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">November 30, 2015<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>3. WildFire sahte mailler ile insanlara bula\u015ft\u0131. Bu y\u00fczden oltalama sald\u0131r\u0131s\u0131n\u0131 anlamay\u0131 \u0131srarla \u00f6neriyoruz. Dikkatli olmak kilit anahtar\u0131m\u0131z. E\u011fer kargodan bir \u015fey beklemiyorsan\u0131z, size kim g\u00f6ndermi\u015f olabilir? S\u00fcrpriz bir paket illa k\u00f6t\u00fc olacak diye bir \u015fey yok, ama sahtekarl\u0131k durumuna kar\u015f\u0131 tetikte olmal\u0131s\u0131n\u0131z. E\u011fer yapabilirseniz, zararl\u0131 yaz\u0131l\u0131m\u0131 sanal makinede a\u00e7\u0131n.<\/p>\n<p>4. E\u011fer sisteminizde bir par\u00e7a dahi fidye yaz\u0131l\u0131m\u0131 bulunduysa, bu sisteminizde ba\u015fka fidye yaz\u0131l\u0131mlar\u0131 da olabilece\u011finin kesin i\u015faretidir. Bu y\u00fczden sisteminizi iyi bir anti vir\u00fcs \u00e7\u00f6z\u00fcm\u00fc ile korumal\u0131s\u0131n\u0131z. Tabi tarafl\u0131 olarak <a href=\"http:\/\/kas.pr\/kdkistr\" target=\"_blank\" rel=\"noopener noreferrer\">Kaspersky Internet Security<\/a> \u00f6neriyoruz, ancak diledi\u011finizi se\u00e7ebilirsiniz. Israrla internete her ba\u011fl\u0131 cihaz\u0131n g\u00fcvenlik yaz\u0131l\u0131m\u0131 ile korunmas\u0131 laz\u0131m: Kurun, \u00e7al\u0131\u015ft\u0131r\u0131n ve g\u00fcncel tutun.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Saklayacak bir \u015fey yok: fidye yaz\u0131l\u0131m\u0131 ac\u0131l\u0131 bir tehdittir. Ve yak\u0131n zamanda da bitmeyecek \u2013 tabi birka\u00e7 istisna hari\u00e7. \u0130yi haber: Bu hikaye o istisnalardan biri. Ge\u00e7ti\u011fimiz g\u00fcnlerde, Kaspersky Lab<\/p>\n","protected":false},"author":522,"featured_media":2369,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1287,1351],"tags":[439,980,827,591,981,438,926,982,447,828,921,623,983],"class_list":{"0":"post-2368","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-blackhat","10":"tag-cryptor","11":"tag-decryptor","12":"tag-fidye-yazilimi","13":"tag-hollanda-polisi","14":"tag-mobile-hacking","15":"tag-nomoreransom","16":"tag-noransom","17":"tag-ransomware","18":"tag-sifre-cozucu","19":"tag-sifreleyici","20":"tag-ucretsiz","21":"tag-wildfire"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/wildfire-ransomware-decryptor\/2368\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/wildfire-ransomware-decryptor\/5540\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/wildfire-ransomware-decryptor\/7593\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/wildfire-ransomware-decryptor\/7553\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/wildfire-ransomware-decryptor\/8976\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/wildfire-ransomware-decryptor\/8836\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/wildfire-ransomware-decryptor\/12828\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/wildfire-ransomware-decryptor\/5998\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/wildfire-ransomware-decryptor\/6494\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/wildfire-ransomware-decryptor\/5286\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/wildfire-ransomware-decryptor\/8524\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/wildfire-ransomware-decryptor\/12348\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/wildfire-ransomware-decryptor\/12828\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/wildfire-ransomware-decryptor\/12828\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/blackhat\/","name":"Blackhat"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2368","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/522"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=2368"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2368\/revisions"}],"predecessor-version":[{"id":7152,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2368\/revisions\/7152"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/2369"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=2368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=2368"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=2368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}