{"id":2670,"date":"2016-11-24T02:37:22","date_gmt":"2016-11-24T07:37:22","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=2670"},"modified":"2019-11-15T14:54:59","modified_gmt":"2019-11-15T11:54:59","slug":"ransoc-ransomware","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/ransoc-ransomware\/2670\/","title":{"rendered":"Ransoc: ikna edici tehdit"},"content":{"rendered":"<p>Bilgisayar\u0131n\u0131zda aniden \u015f\u00f6yle rahats\u0131z edici bir mesaj\u0131n belirdi\u011fini hayal edin: \u201cBilgisayar\u0131n\u0131zda yasad\u0131\u015f\u0131 i\u00e7erik tespit edilmi\u015ftir. 20 y\u0131l hapis ve 200.000$ ile yarg\u0131lanacaks\u0131n\u0131z. \u0130\u00e7eri\u011fi uzaktan sildirmek i\u00e7in 100$\u2019l\u0131k Bitcoin g\u00f6nderebilirsiniz. FBI.\u201d<\/p>\n<p>\u201c\u00c7ok beklersin! Bu numaray\u0131 yemezler! Tek bir kuru\u015f dahi alamazs\u0131n! Bilgisayar\u0131mdan seni kald\u0131rmak i\u00e7in kullanabilece\u011fim <a href=\"https:\/\/www.kaspersky.com\/blog\/kaspersky-windowsunlocker-2\/12275\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">\u00f6zel bir ara\u00e7<\/a> var!\u201d<\/p>\n<p>Buna benzeyen kilitleyiciler 2012 \u2013 2014 aras\u0131nda olduk\u00e7a yayg\u0131nd\u0131 ancak \u015fimdi ak\u0131ll\u0131 cihazlar\u0131 hedef al\u0131yorlar. Kilitleyiciler bilgisayarladan uzakla\u015f\u0131p <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/mobile-ransomware-2016\/2238\/\" target=\"_blank\" rel=\"noopener noreferrer\">ak\u0131ll\u0131 telefonlara bula\u015fmaya ba\u015flad\u0131<\/a>. \u00c7\u00fcnk\u00fc telefonlarda bu kilitleyicilerle u\u011fra\u015fmak daha zor.<\/p>\n<p>Yine de kilitleyiciler tamamen bilgisayarlardan vazge\u00e7mi\u015f de\u011filler \u2013 son derece ikna edici bir bi\u00e7ime evrildiler. <a href=\"https:\/\/www.proofpoint.com\/uk\/threat-insight\/post\/ransoc-desktop-locking-ransomware-ransacks-local-files-social-media-profiles\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Yeni ke\u015ffedilen<\/a> Ransoc kilitleyicisi, kilitleyicilerdeki bu evrimin ilgin\u00e7 bir \u00f6rne\u011fi.<\/p>\n<p>Ransoc ile s\u0131radan kilitleyicilerin en temel fark\u0131, Ransoc\u2019un son derece ikna edici olmas\u0131d\u0131r. Bu fidye yaz\u0131l\u0131m\u0131 kullan\u0131c\u0131n\u0131n internet taray\u0131c\u0131s\u0131na eri\u015fmesini engelliyor, sosyal medya hesaplar\u0131ndaki ki\u015fisel bilgileri ve foto\u011fraflar\u0131 kullan\u0131yor. Ek olarak, fidye yaz\u0131l\u0131m\u0131n\u0131n talepleri daha mant\u0131kl\u0131. Bu nas\u0131l olabilir?<\/p>\n<p>Ransoc yaz\u0131l\u0131m\u0131 kurban\u0131n bilgisayar\u0131na bula\u015ft\u0131ktan sonra (genellikle yeti\u015fkin sitelerinden bula\u015f\u0131yor), sisteminizi tarayarak herhangi yasal olmayan bir \u015fey (\u00e7ocuk pornosu, orijinal olmayan m\u00fczik ya da film) olup olmad\u0131\u011f\u0131n\u0131 kontrol ediyor. Ransoc ayr\u0131ca kurban\u0131n Skype, Facebook ve LinkedIn profillerini de kontrol ediyor. Buldu\u011fu ki\u015fisel bilgilerle kullan\u0131c\u0131ya \u015fantaj yap\u0131yor.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/Tip?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#Tip<\/a> of the week: Fighting screen lockers with <a href=\"https:\/\/twitter.com\/kaspersky?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">@kaspersky<\/a> products <a href=\"https:\/\/t.co\/SAS4x4ve9o\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/SAS4x4ve9o<\/a> <a href=\"https:\/\/t.co\/11SGH4e8nR\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/11SGH4e8nR<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/738735944132636673?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">June 3, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Sonu\u00e7 olarak, kurbanlar ikna edici ve korkutucu bir bildirim al\u0131yorlar: \u0130\u015fte bak, elimizde ki\u015fisel bilgilerin ve yasa d\u0131\u015f\u0131 i\u015flerinin listesi var. Rancos kullan\u0131c\u0131y\u0131 kirli \u00e7ama\u015f\u0131rlar\u0131n\u0131 sosyal medya hesaplar\u0131nda herkese a\u00e7\u0131k bir \u015fekilde payla\u015fmakla tehdit ediyor. E\u011fer kullan\u0131c\u0131da yasa d\u0131\u015f\u0131 bir veri yoksa, Trojan hi\u00e7bir \u015fekilde \u015fantaj yapm\u0131yor. Asl\u0131nda biraz yasa d\u0131\u015f\u0131 \u015fekilde adaleti sa\u011fl\u0131yor denebilir.<\/p>\n<p>Ek olarak, her 100 milisaniyede bir Ransoc sisteminizi kontrol ederek regedit, msconfig ya da taskmgr\u2019\u0131 a\u00e7\u0131p a\u00e7mad\u0131\u011f\u0131n\u0131z\u0131 kontrol ediyor, a\u00e7maya \u00e7al\u0131\u015f\u0131rsan\u0131z kendisi kapat\u0131yor.<\/p>\n<p>Ransoc hakk\u0131ndaki di\u011fer ilgin\u00e7 \u015fey ise, su\u00e7lular\u0131n paray\u0131 banka havalesi olarak istemesi. Bu olay bir yandan bu i\u015fin arkas\u0131ndakileri tespit etmeyi kolayla\u015ft\u0131r\u0131yor. Ama di\u011fer bir yandan, su\u00e7lular FBI yetkilisi gibi davran\u0131yor, dolay\u0131s\u0131yla Bitcoin istemektense bu y\u00f6ntem daha ikna edici.<\/p>\n<p>T\u00fcm olay\u0131 \u00f6zetlemek gerekirse, Ransoc \u00fc\u00e7 y\u0131l \u00f6nce pop\u00fcler olan <strong>locker 2.0<\/strong>\u2018\u0131n g\u00fcncellenmi\u015f ve geli\u015fmi\u015f halidir.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kis-trial-ransomware\">\n<p>Bu \u015fifreleyici durdurman\u0131n iki yolu var.<\/p>\n<p>1. Sakin olun ve bu sosyal m\u00fchendislik numaralar\u0131na inanmay\u0131n. Bu ne iddia ederlerse etsinler, kolluk kuvveti mensubu de\u011filler. Sadece fidye yaz\u0131l\u0131m\u0131n\u0131 biraz geli\u015ftirmi\u015f su\u00e7lular.<br>\n2. Cihazlar\u0131n\u0131zda g\u00fcvenilir bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc kullan\u0131n. <a href=\"https:\/\/www.kaspersky.com.tr\/internet-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kismd___\" target=\"_blank\" rel=\"noopener\">Kaspersky Internet Security<\/a>, Ransoc\u2019u tespit ederek harekete ge\u00e7meden \u00f6nce engeller. E\u011fer cihaz\u0131n\u0131zda trojan varsa, Kasperksy Internet Security yard\u0131m\u0131yla hepsinden kurtulabilirsiniz.<br>\nE\u011fer de\u011fi\u015fik fidye yaz\u0131l\u0131mlar\u0131 hakk\u0131nda daha fazla bilgi istiyorsan\u0131z, \u015fu g\u00f6nderimize g\u00f6z at\u0131n.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bilgisayar\u0131n\u0131zda aniden \u015f\u00f6yle rahats\u0131z edici bir mesaj\u0131n belirdi\u011fini hayal edin: \u201cBilgisayar\u0131n\u0131zda yasad\u0131\u015f\u0131 i\u00e7erik tespit edilmi\u015ftir. 20 y\u0131l hapis ve 200.000$ ile yarg\u0131lanacaks\u0131n\u0131z. \u0130\u00e7eri\u011fi uzaktan sildirmek i\u00e7in 100$\u2019l\u0131k Bitcoin g\u00f6nderebilirsiniz. FBI.\u201d<\/p>\n","protected":false},"author":696,"featured_media":2671,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[591,1053,1076,1077,447,537,889],"class_list":{"0":"post-2670","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-fidye-yazilimi","9":"tag-kilitleyiciler","10":"tag-lockers","11":"tag-ransoc","12":"tag-ransomware","13":"tag-tehditler","14":"tag-trojanlar"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/ransoc-ransomware\/2670\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/ransoc-ransomware\/5720\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/ransoc-ransomware\/10488\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/ransoc-ransomware\/8006\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/ransoc-ransomware\/8007\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/ransoc-ransomware\/9571\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/ransoc-ransomware\/9370\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/ransoc-ransomware\/13636\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/ransoc-ransomware\/13505\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/ransoc-ransomware\/6335\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/ransoc-ransomware\/6833\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/ransoc-ransomware\/5710\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/ransoc-ransomware\/9257\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/ransoc-ransomware\/13320\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/ransoc-ransomware\/13636\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/ransoc-ransomware\/13505\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/ransoc-ransomware\/13505\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/fidye-yazilimi\/","name":"Fidye Yaz\u0131l\u0131m\u0131"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2670","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/696"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=2670"}],"version-history":[{"count":4,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2670\/revisions"}],"predecessor-version":[{"id":7110,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2670\/revisions\/7110"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/2671"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=2670"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=2670"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=2670"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}