{"id":2479,"date":"2016-10-05T03:43:02","date_gmt":"2016-10-05T07:43:02","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=2479"},"modified":"2019-11-15T14:56:50","modified_gmt":"2019-11-15T11:56:50","slug":"polyglot-decryptor","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/polyglot-decryptor\/2479\/","title":{"rendered":"Marsjoke: Fidye yaz\u0131l\u0131m\u0131 ve \u00e7\u00f6z\u00fcm\u00fc"},"content":{"rendered":"<p>Hemen hemen her g\u00fcn yeni bir fidye yaz\u0131l\u0131m\u0131 t\u00fcr\u00fcyor. Fidye yaz\u0131l\u0131mlar\u0131n\u0131 yapanlar kolluk kuvvetlerinin dahi bu konuda fazla dikkat etmesine ra\u011fmen hala bu \u015fekilde kolay para kazanabilece\u011fini d\u00fc\u015f\u00fcn\u00fcyorlar.<\/p>\n<p>Asl\u0131na bakarsan\u0131z \u015fu an piyasada \u00e7ok say\u0131da fidye yaz\u0131l\u0131m\u0131 var. Bu sebeple fidye yaz\u0131l\u0131mlar\u0131 kendilerini tekrar etmeye ve di\u011fer yaz\u0131l\u0131mlara benzemeye ba\u015flad\u0131lar. \u00d6rnek olarak, son ke\u015ffedilen fidye yaz\u0131l\u0131m\u0131 <a href=\"https:\/\/securelist.com\/blog\/research\/76182\/polyglot-the-fake-ctb-locker\/\" target=\"_blank\" rel=\"noopener noreferrer\">Trojan-cryptor Polyglot<\/a> ki biz ona MarsJoke diyoruz, \u00fcnl\u00fc <a href=\"https:\/\/www.kaspersky.com\/blog\/new-version-ctb-locker\/7310\/\" target=\"_blank\" rel=\"noopener nofollow\">CTB-Locker<\/a>\u2018\u0131n tam anlam\u0131yla \u2018\u00e7akmas\u0131\u2019.<\/p>\n<p>Polyglot\u2019ta CTB-Locker\u2019\u0131n bir\u00e7ok izini g\u00f6rebilirsiniz. Aray\u00fcz\u00fc anlams\u0131z \u015fekilde eski trojana benziyor. Kurban\u0131n ekran g\u00f6r\u00fcnt\u00fcs\u00fcn\u00fc ayn\u0131 \u015fekilde de\u011fi\u015ftiriyor. T\u0131pk\u0131 CTB-Locker\u2019\u0131n yapt\u0131\u011f\u0131 gibi, kurban\u0131n 5 dosyas\u0131n\u0131n \u015fifresini \u00e7\u00f6zerek bu i\u015fi yapabildi\u011fini g\u00f6steriyor.<\/p>\n<p>Polyglot\u2019un kurbanlar\u0131 y\u00f6nlendirdi\u011fi bilgilendirme ekranlar\u0131 da CTB-Locker\u2019\u0131n ayn\u0131s\u0131. Yaz\u0131l\u0131 metinler kopyala yap\u0131\u015ft\u0131r yap\u0131lm\u0131\u015f gibi duruyor. Hatta internet ba\u011flant\u0131s\u0131 bulunmad\u0131\u011f\u0131 zaman verdi\u011fi hata ekran\u0131 da ayn\u0131.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2481\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2016\/10\/06013900\/polyglot-comparison-screen.png\" alt=\"polyglot-comparison-screen\" width=\"1572\" height=\"514\"><\/p>\n<p>\u0130ki \u015fifreleyici de ayn\u0131 algoritmay\u0131 kullan\u0131yor \u2013 tabi Polyglot\u2019un algoritmas\u0131 biraz daha g\u00fc\u00e7l\u00fc.<\/p>\n<p>Polyglot genellikle spam mailler arac\u0131l\u0131\u011f\u0131yla da\u011f\u0131t\u0131l\u0131yor \u2013 \u00f6nemli bir dosya gibi g\u00f6z\u00fcken bir mail olarak geliyor. Ama tabi, anlad\u0131\u011f\u0131n\u0131z \u00fczere ortada \u00f6nemli bir dosya yok \u2013 sadece \u00e7al\u0131\u015ft\u0131r\u0131labilir zararl\u0131 yaz\u0131l\u0131m var. Polyglot bilgisayara y\u00fcklendi\u011finde kontrol ve y\u00f6netim paneline ba\u011fl\u0131yor bula\u015ft\u0131\u011f\u0131 bilgisayar hakk\u0131nda bilgi veriyor. Bizim denememizde 0.7 bitcoins istedi (Bu yakla\u015f\u0131k 320$ ediyor, bu da yakla\u015f\u0131k 971 TL ediyor).<\/p>\n<p>CTB-Locker ile Polyglot aras\u0131ndaki belki de tek g\u00f6rsel uyu\u015fmazl\u0131k, CTB \u015fifreledi\u011fi dosyalar\u0131n uzant\u0131s\u0131n\u0131 genellikle .ctbl ya da .ctb2 yaparken MarsJoke\/Polyglot uzant\u0131lar\u0131n\u0131 oldu\u011fu gibi b\u0131rak\u0131yor.<\/p>\n<p>Polyglot ve CTB-Locker aras\u0131ndaki bu kadar benzerli\u011fe ra\u011fmen, her ikisi de tamamen farkl\u0131 fidye yaz\u0131l\u0131m\u0131 \u00e7e\u015fitleri. Neredeyse hi\u00e7 ipucu b\u0131rakm\u0131yorlar. Uzmanlar\u0131m\u0131z CTB-Locker\u2019\u0131n g\u00f6r\u00fcn\u00fc\u015f\u00fc taklit etmesinden dolay\u0131, Polyglot\u2019un yap\u0131mc\u0131lar\u0131n\u0131n ara\u015ft\u0131rmac\u0131lar\u0131 \u2018ayn\u0131 ki\u015filerin\u2019 yapt\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcnd\u00fcrmeye \u00e7al\u0131\u015ft\u0131klar\u0131n\u0131 d\u00fc\u015f\u00fcn\u00fcyor.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-2482\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2016\/10\/06013859\/polyglot-comparison-screen2.png\" alt=\"polyglot-comparison-screen2\" width=\"1571\" height=\"515\"><\/p>\n<p>Bildi\u011finiz gibi, CTB-Locker\u2019\u0131n \u015fifreledi\u011fi dosyalar\u0131 fidye \u00f6deme harici bilinen bir \u00e7\u00f6z\u00fcm y\u00f6ntemi yok. Bu y\u00fczden Polyglot ve CTB-Locker ayn\u0131 \u015fekilde de\u011ferlendirilemez. Polyglot\u2019un yaz\u0131l\u0131mc\u0131lar\u0131, anahtar olu\u015fturucu (key generator) b\u00f6l\u00fcm\u00fcn\u00fcn yaz\u0131l\u0131m\u0131nda hata yapm\u0131\u015flar, bu hata da Kaspersky Lab ara\u015ft\u0131rmac\u0131lar\u0131n\u0131n \u00e7\u00f6z\u00fcm olu\u015fturmas\u0131na sebep oldu \u2013 \u015fifrelenmi\u015f dosyalar\u0131n\u0131z\u0131n hepsini \u00e7\u00f6zebilece\u011finiz \u00fccretsiz bir ara\u00e7.<\/p>\n<p>Polyglot\/MarsJoke taraf\u0131ndan \u015fifrelenmi\u015f dosyalar\u0131n\u0131z\u0131 a\u00e7mak i\u00e7in, \u00fccretsiz RannohDecryptor arac\u0131n\u0131n\u0131 (version 1.9.3.0 ya da daha yeni) <a href=\"https:\/\/noransom.kaspersky.com\/?_ga=1.53297067.2016803411.1475150380\" target=\"_blank\" rel=\"noopener\">noransom.kaspersky.com<\/a> adresinden indirin, dosyalar\u0131n\u0131z\u0131 kurtar\u0131n.<\/p>\n<p>D\u00fcr\u00fcst olmak gerekirse, Polyglot\/MarsJoke konusunda biraz \u015fansl\u0131yd\u0131k. Fidye yaz\u0131l\u0131m\u0131 yarat\u0131c\u0131lar\u0131 s\u00fcrekli olarak yaz\u0131l\u0131mlar\u0131n\u0131 geli\u015ftirir ve g\u00fcnceller. \u00d6rne\u011fin; Biz <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/cryptxxx-ransomware\/2047\/\" target=\"_blank\" rel=\"noopener\">CryptXXX<\/a>\u2018i 3 defa \u00e7\u00f6zd\u00fckten sonra, program yaz\u0131l\u0131mc\u0131lar\u0131 algoritmay\u0131 \u00f6yle de\u011fi\u015ftirdiler ki, olu\u015fturdu\u011fumuz ara\u00e7lar \u015fifrelerini \u00e7\u00f6zemedi. Belki Polyglot\u2019un yarat\u0131c\u0131lar\u0131 da ayn\u0131 \u015feyi yaparlar. Yani bu olay da \u015fu anlama geliyor: bunlar\u0131 \u00e7\u00f6zen \u00fccretsiz ara\u00e7lar\u0131m\u0131z\u0131n olmas\u0131 sizi g\u00fcvende tutmaz, her an geli\u015febilirler.<\/p>\n<p>Fidye yaz\u0131l\u0131mlar\u0131na kar\u015f\u0131 g\u00fcvende kalman\u0131n en iyi yolu, bilgisayar\u0131n\u0131za bula\u015fmadan \u00f6nce engellemektir. Bunu da yapabilecek <a href=\"http:\/\/kas.pr\/kdkistr\" target=\"_blank\" rel=\"noopener\">Kaspersky Internet Security<\/a> gibi g\u00fcvenilir bir anti vir\u00fcs \u00e7\u00f6z\u00fcm\u00fcne ihtiyac\u0131n\u0131z var.<\/p>\n<p>Ayr\u0131ca g\u00fcvenli\u011finizi artt\u0131rmak i\u00e7in, s\u0131k\u00e7a verilerinizi yedekleyin ve \u015f\u00fcpheli linklere, dosyalara, sitelere t\u0131klamay\u0131n.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hemen hemen her g\u00fcn yeni bir fidye yaz\u0131l\u0131m\u0131 t\u00fcr\u00fcyor. Fidye yaz\u0131l\u0131mlar\u0131n\u0131 yapanlar kolluk kuvvetlerinin dahi bu konuda fazla dikkat etmesine ra\u011fmen hala bu \u015fekilde kolay para kazanabilece\u011fini d\u00fc\u015f\u00fcn\u00fcyorlar. Asl\u0131na bakarsan\u0131z<\/p>\n","protected":false},"author":696,"featured_media":2480,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[1018,1019,980,1020,1021,591,352,1023,447,1022,921,241,1024],"class_list":{"0":"post-2479","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-arac","9":"tag-tools","10":"tag-cryptor","11":"tag-ctb-locker","12":"tag-decryption","13":"tag-fidye-yazilimi","14":"tag-kaspersky-lab","15":"tag-marsjoke","16":"tag-ransomware","17":"tag-sifre-cozme","18":"tag-sifreleyici","19":"tag-trojan","20":"tag-zipcryptor"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/polyglot-decryptor\/2479\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/polyglot-decryptor\/7736\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/polyglot-decryptor\/7743\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/polyglot-decryptor\/7790\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/polyglot-decryptor\/9217\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/polyglot-decryptor\/9075\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/polyglot-decryptor\/13245\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/polyglot-decryptor\/13138\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/polyglot-decryptor\/6119\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/polyglot-decryptor\/6607\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/polyglot-decryptor\/5468\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/polyglot-decryptor\/8841\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/polyglot-decryptor\/12751\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/polyglot-decryptor\/13245\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/polyglot-decryptor\/13138\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/polyglot-decryptor\/13138\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/arac\/","name":"#ara\u00e7"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2479","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/696"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=2479"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2479\/revisions"}],"predecessor-version":[{"id":7134,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2479\/revisions\/7134"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/2480"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=2479"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=2479"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=2479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}