{"id":7500,"date":"2019-12-16T12:42:16","date_gmt":"2019-12-16T09:42:16","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=7500"},"modified":"2019-12-16T12:42:16","modified_gmt":"2019-12-16T09:42:16","slug":"attack-on-online-retail","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/attack-on-online-retail\/7500\/","title":{"rendered":"K\u00fc\u00e7\u00fck \u00f6l\u00e7ekli \u00e7evrimi\u00e7i perakendecilere y\u00f6nelik tehlikeli mektuplar"},"content":{"rendered":"<p>Siber su\u00e7lular s\u0131kl\u0131kla \u00e7ok k\u00fc\u00e7\u00fck \u015firketleri hedef se\u00e7er. K\u00fc\u00e7\u00fck i\u015fletmeler g\u00fcvenlik sistemlerine b\u00fcy\u00fck yat\u0131r\u0131mlar yapmaz, \u00e7o\u011funlukla bir BT uzmanlar\u0131 bile yoktur ve en \u00f6nemlisi yaln\u0131zca bir veya iki bilgisayarla \u00e7al\u0131\u015f\u0131yor olma olas\u0131l\u0131klar\u0131 y\u00fcksektir. Bu da onlar\u0131 siber su\u00e7lular\u0131n \u00e7o\u011funlukla arad\u0131\u011f\u0131 t\u00fcrde bilgilere sahip birer hedef haline getirir. Teknolojilerimiz k\u0131sa bir s\u00fcre \u00f6nce k\u00fc\u00e7\u00fck \u00e7evrimi\u00e7i ma\u011fazalar\u0131 hedef alan bir sald\u0131r\u0131 daha tespit etti. Sosyal m\u00fchendislik y\u00f6ntemlerini kullanan sald\u0131rganlar, bu t\u00fcrden k\u00fc\u00e7\u00fck i\u015fletmelerin sahiplerini bilgisayarlar\u0131nda k\u00f6t\u00fc ama\u00e7l\u0131 komut dosyalar\u0131 y\u00fcr\u00fctmek i\u00e7in zorlamaya \u00e7al\u0131\u015f\u0131yor.<\/p>\n<h2>Sosyal m\u00fchendislik<\/h2>\n<p>Bu sald\u0131r\u0131n\u0131n en ilgin\u00e7 taraf\u0131, sald\u0131rganlar\u0131n bir ma\u011faza \u00e7al\u0131\u015fan\u0131n\u0131 k\u00f6t\u00fc ama\u00e7l\u0131 bir dosya indirip a\u00e7mak \u00fczere kand\u0131rmak i\u00e7in ba\u015fvurduklar\u0131 oyun. Sipari\u015f i\u00e7in \u00f6deme yapm\u0131\u015f fakat sipari\u015fi alamam\u0131\u015f bir m\u00fc\u015fteri k\u0131l\u0131\u011f\u0131nda bir mektup g\u00f6nderiyorlar. Postanede bir sorun \u00e7\u0131kt\u0131\u011f\u0131n\u0131 s\u00f6yleyerek ma\u011fazadan baz\u0131 bilgileri i\u00e7eren bir belge doldurmas\u0131n\u0131 istiyorlar (g\u00f6nderici bilgileri, takip numaras\u0131, vb.). Hangi i\u015f insan\u0131 b\u00f6yle bir mektubu g\u00f6rmezden gelebilir?<\/p>\n<p>D\u00fczg\u00fcn olmasa da olduk\u00e7a anla\u015f\u0131labilir bir \u0130ngilizceyle yaz\u0131lm\u0131\u015f olan mektup, Google Docs\u2019ta bar\u0131nd\u0131r\u0131lan bir nesneye ba\u011flant\u0131 i\u00e7eriyor. Ba\u011flant\u0131ya t\u0131klad\u0131\u011f\u0131n\u0131zda bir ar\u015fiv indiriliyor ve elbette ar\u015fivde k\u00f6t\u00fc ama\u00e7l\u0131 bir dosya var. Bu vakada bu k\u00f6t\u00fc ama\u00e7l\u0131 dosya .xlsx uzant\u0131l\u0131.<\/p>\n<h2>Teknik a\u00e7\u0131dan bak\u0131ld\u0131\u011f\u0131nda<\/h2>\n<p>Sald\u0131r\u0131 basit ama etkili. Birincisi, e-postan\u0131n kitlesel olarak g\u00f6nderilmedi\u011fi belli: Mesaj\u0131n metni \u00f6zel olarak \u00e7evrimi\u00e7i ma\u011fazalara y\u00f6nelik yaz\u0131lm\u0131\u015f ve b\u00fcy\u00fck olas\u0131l\u0131kla uygun bir listeye g\u00f6nderiliyor. \u0130kincisi, e-posta k\u00f6t\u00fc ama\u00e7l\u0131 bir unsur i\u00e7ermiyor. Yaln\u0131zca birka\u00e7 sat\u0131rl\u0131k bir metin ve me\u015fru bir hizmete y\u00f6nlendiren bir ba\u011flant\u0131dan ibaret. Otomatik e-posta filtreleri b\u00f6yle bir mesaj\u0131 b\u00fcy\u00fck olas\u0131l\u0131kla durdurmaz. \u0130stenmeyen e-posta de\u011fil, kimlik av\u0131 de\u011fil, en \u00f6nemlisi de k\u00f6t\u00fc ama\u00e7l\u0131 ekler i\u00e7ermiyor.<\/p>\n<p>XLSX dosyas\u0131, uzak bir servisten y\u00fcr\u00fct\u00fclebilir bir dosya indirip \u00e7al\u0131\u015ft\u0131ran bir komut dosyas\u0131 i\u00e7eriyor. Bu komut dosyas\u0131, sistemlerimizin <a href=\"https:\/\/securelist.com\/it-threat-evolution-q2-2018-statistics\/87170\/\" target=\"_blank\" rel=\"noopener\">May\u0131s 2018\u2019den bu yana<\/a> tan\u0131d\u0131\u011f\u0131 bankac\u0131l\u0131k truva at\u0131, DanaBot. Mod\u00fcler bir yap\u0131ya sahip olan bu k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m, trafi\u011fi kesmesini ve \u015fifreleri, hatta kripto para c\u00fczdanlar\u0131n\u0131 \u00e7almas\u0131n\u0131 sa\u011flayan ilave eklentiler indirebiliyor. Bu yaz\u0131 yaz\u0131ld\u0131\u011f\u0131 s\u0131rada bu k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m en tehlikeli 10 bankac\u0131l\u0131\u011fa y\u00f6nelik k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m ailesi aras\u0131nda yer al\u0131yor (<a href=\"https:\/\/securelist.com\/it-threat-evolution-q3-2019-statistics\/95269\/\" target=\"_blank\" rel=\"noopener\">2019\u2019un \u00fc\u00e7\u00fcnc\u00fc \u00e7eyre\u011fi istatistiklerine g\u00f6re<\/a>).<\/p>\n<p>Bu sald\u0131r\u0131n\u0131n hedefinde \u00e7ok k\u00fc\u00e7\u00fck d\u00fckkanlar bulunuyor, dolay\u0131s\u0131yla \u00e7al\u0131\u015fan\u0131n e-postay\u0131 okudu\u011fu ve vir\u00fcs\u00fcn bula\u015ft\u0131\u011f\u0131 bilgisayar\u0131n ayn\u0131 zamanda bankac\u0131l\u0131k i\u015flemleri i\u00e7in kullan\u0131lan ana cihaz olma ihtimali \u00e7ok y\u00fcksek. Di\u011fer bir deyi\u015fle bu bilgisayar b\u00fcy\u00fck olas\u0131l\u0131kla sald\u0131rganlar\u0131n arad\u0131\u011f\u0131 bilgileri i\u00e7eriyor.<\/p>\n<h2>G\u00fcvenli\u011finizi nas\u0131l sa\u011flayabilirsiniz?<\/h2>\n<p>Birincisi, b\u00fct\u00fcn bilgisayaralar g\u00fcvenilir bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fcne ihtiya\u00e7 duyar. G\u00fcvenlik teknolojilerimiz yaln\u0131zca DanaBot\u2019u tespit etmekle kalmaz (Trojan-Banker.Win32.Danabot olarak), ayn\u0131 zamanda HEUR:Trojan.Script.Generic sezgisel tan\u0131s\u0131yla bu truva at\u0131n\u0131 indiren komut dosyalar\u0131n\u0131 da kaydeder. Bu sayede Kaspersky \u00e7\u00f6z\u00fcmlerine sahip bilgisayarlar, b\u00f6yle bir sald\u0131r\u0131y\u0131 truva at\u0131 cihaza indirilmeden \u00f6nce durdurabilir.<\/p>\n<p>\u0130kincisi, \u00e7ok kullan\u0131lan programlar\u0131 zaman\u0131nda g\u00fcncellemelisiniz. \u0130\u015fletim sistemi ve ofis programlar\u0131 g\u00fcncellemeleri, en b\u00fcy\u00fck \u00f6nceli\u011fe sahip olmal\u0131d\u0131r. Sald\u0131rganlar genelde k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131 iletmek i\u00e7in bu yaz\u0131l\u0131mlardaki g\u00fcvenlik a\u00e7\u0131klar\u0131ndan faydalan\u0131r.<\/p>\n<p>\u00c7ok k\u00fc\u00e7\u00fck \u015firketler i\u00e7in <a href=\"https:\/\/kas.pr\/ksostr\" target=\"_blank\" rel=\"noopener\">Kaspersky Small Office Security<\/a> \u00e7\u00f6z\u00fcm\u00fcn\u00fc \u00f6neriyoruz. Bu \u00e7\u00f6z\u00fcm \u00f6zel y\u00f6netim becerileri gerektirmiyor, truva atlar\u0131na kar\u015f\u0131 g\u00fcvenilir koruma sa\u011fl\u0131yor ve yayg\u0131n \u00fc\u00e7\u00fcnc\u00fc taraf uygulamalar\u0131n\u0131n s\u00fcr\u00fcmlerini kontrol ediyor.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"ksos\">\n","protected":false},"excerpt":{"rendered":"<p>Siber su\u00e7lular k\u00fc\u00e7\u00fck \u00e7evrimi\u00e7i ma\u011fazalar\u0131n \u00e7al\u0131\u015fanlar\u0131n\u0131 k\u00f6t\u00fc ama\u00e7l\u0131 dosyalar\u0131 a\u00e7maya ikna ederek ma\u011fazalara sald\u0131r\u0131yor.<\/p>\n","protected":false},"author":700,"featured_media":7501,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194,1727],"tags":[2079,1921,1660],"class_list":{"0":"post-7500","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"category-smb","10":"tag-cevrimici-magazalar","11":"tag-e-posta","12":"tag-sosyal-muhendislik"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/attack-on-online-retail\/7500\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/attack-on-online-retail\/18321\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/attack-on-online-retail\/15219\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/attack-on-online-retail\/7314\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/attack-on-online-retail\/20048\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/attack-on-online-retail\/18408\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/attack-on-online-retail\/16788\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/attack-on-online-retail\/20783\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/attack-on-online-retail\/19538\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/attack-on-online-retail\/25903\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/attack-on-online-retail\/31786\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/attack-on-online-retail\/13529\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/attack-on-online-retail\/13810\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/attack-on-online-retail\/12596\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/attack-on-online-retail\/21772\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/attack-on-online-retail\/26435\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/attack-on-online-retail\/24719\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/attack-on-online-retail\/20757\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/attack-on-online-retail\/25630\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/attack-on-online-retail\/25462\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/cevrimici-magazalar\/","name":"\u00e7evrimi\u00e7i ma\u011fazalar"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/7500","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/700"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=7500"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/7500\/revisions"}],"predecessor-version":[{"id":7504,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/7500\/revisions\/7504"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/7501"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=7500"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=7500"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=7500"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}