{"id":8156,"date":"2020-04-29T14:14:03","date_gmt":"2020-04-29T11:14:03","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=8156"},"modified":"2020-04-29T14:14:03","modified_gmt":"2020-04-29T11:14:03","slug":"covid-fake-delivery-service-spam-phishing","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/covid-fake-delivery-service-spam-phishing\/8156\/","title":{"rendered":"Karantina d\u00f6nemi s\u0131ras\u0131nda sahte teslimatlar"},"content":{"rendered":"<p>Koronavir\u00fcs pandemisi taraf\u0131ndan etkilenmemi\u015f bir insan etkinli\u011fi alan\u0131 bulmak zor olacakt\u0131r ve ekspres teslimat hizmetleri bu duruma bir istisna de\u011fildir. \u00dclkeler aras\u0131ndaki ula\u015f\u0131m ak\u0131\u015flar\u0131 kesintiye u\u011frad\u0131. \u0130nsanlar ve \u015firketler hem yurti\u00e7inde hem de yurtd\u0131\u015f\u0131ndan mal sipari\u015f etmeye devam ettik\u00e7e kargo u\u00e7aklar\u0131nda say\u0131 <a href=\"https:\/\/www.forbes.com\/sites\/tedreed\/2020\/04\/18\/demand-for-air-cargo-capacity-is-urgent-and-huge---who-will-step-in-to-fill-it\/\" target=\"_blank\" rel=\"noopener nofollow\">konusunda s\u0131k\u0131nt\u0131lar meydana geldi<\/a>. Hatta baz\u0131 e\u015fyalara olan <a href=\"https:\/\/www.nst.com.my\/business\/2020\/03\/579210\/covid-19-malaysias-top-glove-overwhelmed-international-orders\" target=\"_blank\" rel=\"noopener nofollow\">talep artt\u0131<\/a>.<\/p>\n<p>Talepte olan ani y\u00fckseli\u015fler nakil s\u00fcrelerinin uzamas\u0131na neden oluyor. Sonu\u00e7 olarak, m\u00fc\u015fteriler g\u00fcncellenmi\u015f g\u00f6nderim durumuyla ilgili kuryelerden \u00f6z\u00fcr mesajlar\u0131 almaya al\u0131\u015ft\u0131lar. Son zamanlarda, bir dizi sahte site ve s\u00f6zde teslimat hizmetlerinden koronavir\u00fcs\u00fc konu alan e-posta g\u00f6zlemledik. Doland\u0131r\u0131c\u0131lar, insanlar\u0131 doland\u0131rmak i\u00e7in <a href=\"https:\/\/securelist.com\/scammers-delivery-service-exclusively-dangerous\/66515\/\" target=\"_blank\" rel=\"noopener\">hem test edilip onaylanm\u0131\u015f hem de yeni hilelere<\/a> ba\u015fvuruyor.<\/p>\n<h2>K\u00f6t\u00fc ama\u00e7l\u0131 ekleri olan spam<\/h2>\n<p>Spam g\u00f6nderenler, ma\u011fdurlar\u0131 k\u00f6t\u00fc ama\u00e7l\u0131 e-posta ekleri a\u00e7maya ikna etmek i\u00e7in kendilerini teslimat hizmeti \u00e7al\u0131\u015fanlar\u0131 olarak g\u00f6sterebilir. Klasik hile, var\u0131\u015f noktas\u0131na gelen bir paketi almak i\u00e7in al\u0131c\u0131n\u0131n \u00f6nce maildeki eki okumas\u0131 veya onaylamas\u0131 gerekti\u011fini s\u00f6ylemektir.<\/p>\n<p>\u00d6rne\u011fin, bozuk bir dil ile yaz\u0131lm\u0131\u015f sahte teslimat bildirimi e-postas\u0131nda pandemi nedeniyle bir paketin teslim edilemeyece\u011fini s\u00f6yl\u00fcyor ve al\u0131c\u0131n\u0131n depoya gelip bizzat almas\u0131 gerekti\u011fi s\u00f6yleniyor.<\/p>\n<p>Depo adresi ve di\u011fer detaylar\u0131n ekte oldu\u011fu s\u00f6yleniyor e\u011fer a\u00e7\u0131l\u0131rsa bilgisayara bir Remcos arka kap\u0131s\u0131 a\u00e7\u0131l\u0131yor. Siber su\u00e7lular daha sonra bilgisayar\u0131n bir botnet\u2019e kat\u0131lmas\u0131n\u0131 sa\u011flayabilir, veri \u00e7alabilir veya ba\u015fka k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar y\u00fckleyebilir.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-8163 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2020\/04\/28180348\/covid-delivery-service-spam-screen-1-1024x407.png\" alt=\"\" width=\"1024\" height=\"407\"><\/p>\n<p>Ba\u015fka bir sahte teslimat e-postas\u0131n\u0131n yazarlar\u0131, \u015firketin bir etiketleme hatas\u0131 nedeniyle paketi teslim edemedi\u011fini iddia ederek benzer bir numara kullan\u0131yorlar. Ma\u011fdurdan, asl\u0131nda Remcos ailesinin ba\u015fka bir \u00fcyesini i\u00e7eren ekteki bilgileri do\u011frulamas\u0131 istenir.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-8164 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2020\/04\/28180431\/covid-delivery-service-spam-screen-2-1024x300.png\" alt=\"\" width=\"1024\" height=\"300\"><\/p>\n<p>Bazen spam g\u00f6nderenler g\u00fcvenilirlik eklemek i\u00e7in iletiye dok\u00fcman resimlerini ekler. A\u015fa\u011f\u0131daki \u00f6rnekte, doland\u0131r\u0131c\u0131lar e-posta metnine k\u00fc\u00e7\u00fck bir resim ekledi. Bu k\u00fc\u00e7\u00fck resim bir makbuz gibi g\u00f6r\u00fcn\u00fcyordu, ancak okumak i\u00e7in \u00e7ok k\u00fc\u00e7\u00fckt\u00fc ve t\u0131kland\u0131\u011f\u0131nda boyutu de\u011fi\u015fmiyordu. B\u00f6ylece al\u0131c\u0131dan ad\u0131nda \u201c.jpg\u201d olan k\u00f6t\u00fc ama\u00e7l\u0131 eki a\u00e7maya y\u00f6nlendiriyordu.<\/p>\n<p>Al\u0131c\u0131n\u0131n e-posta istemcisi dosyan\u0131n ger\u00e7ek uzant\u0131s\u0131n\u0131 g\u00f6r\u00fcnt\u00fclemezse, bu olaydaki gibi al\u0131c\u0131lar bu eki a\u00e7abilirler. Ama bu ek asl\u0131nda casus yaz\u0131l\u0131m Noon\u2019u i\u00e7eren y\u00fcr\u00fct\u00fclebilir ACE ar\u015fividir.<\/p>\n<p>Kurban\u0131 acele ettirmek i\u00e7in siber su\u00e7lular, koliyi soka\u011fa \u00e7\u0131kma yasa\u011f\u0131ndan \u00f6nce teslim etmek i\u00e7in acilen eksik bilgilere ihtiya\u00e7 duyduklar\u0131n\u0131 s\u00f6yl\u00fcyorlar.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-8165 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2020\/04\/28180508\/covid-delivery-service-spam-screen-3-1024x564.png\" alt=\"\" width=\"1024\" height=\"564\"><\/p>\n<p>Yeni olmayan ancak \u00f6zellikle mevcut ortamla ilgili olan ba\u015fka bir k\u00f6t\u00fc ama\u00e7l\u0131 e-posta konusu teslimat gecikmeleridir. Senaryo olduk\u00e7a makuldur: Doland\u0131r\u0131c\u0131lar, kurban\u0131 Bsymem Truva At\u0131 i\u00e7eren bir eke y\u00f6nlendirir. Bu Truva At\u0131 y\u00fcr\u00fct\u00fcl\u00fcrse sald\u0131rganlar\u0131n cihaz\u0131n kontrol\u00fcn\u00fc ele ge\u00e7irmesine ve veri \u00e7almas\u0131na izin verir. \u0130letinin alt k\u0131sm\u0131nda, posta g\u00fcvenli\u011fi \u00e7\u00f6z\u00fcm\u00fc taraf\u0131ndan tarand\u0131\u011f\u0131 ve k\u00f6t\u00fc niyetli dosya veya ba\u011flant\u0131 i\u00e7ermedi\u011fi bildirilen bir bildirim bulunur. Bu bildirim, al\u0131c\u0131y\u0131 yanl\u0131\u015f bir g\u00fcvenlik hissine kap\u0131lmas\u0131 i\u00e7in tasarlanm\u0131\u015ft\u0131r.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-8166 size-full\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2020\/04\/28180616\/covid-delivery-service-spam-screen-4.png\" alt=\"\" width=\"1014\" height=\"689\"><\/p>\n<p>Bir\u00e7ok spam g\u00f6ndenler, normal posta \u015fablonlar\u0131nda COVID-19\u2019dan bahseder. Ancak baz\u0131lar\u0131 \u00f6zellikle karantinalara ve pandeminin h\u0131zla yay\u0131lmas\u0131na odaklan\u0131r.<\/p>\n<p>Bir \u00f6rnekte h\u00fck\u00fcmet, \u00fclkeye her t\u00fcrl\u00fc mal\u0131n ithalat\u0131n\u0131 yasaklam\u0131\u015ft\u0131, bu y\u00fczden paket g\u00f6nderene iade edilmi\u015fti.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-8167 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2020\/04\/28180648\/covid-delivery-service-spam-screen-5-1024x503.png\" alt=\"\" width=\"1024\" height=\"503\"><\/p>\n<p>Ekte, vir\u00fcsle ilgili sa\u011fl\u0131k k\u0131s\u0131tlamalar\u0131 ortadan kalkt\u0131ktan sonra yeniden g\u00f6nderim iste\u011finde bulunmak i\u00e7in s\u00f6zde bir sipari\u015f takip numaras\u0131 bulunuyor. Ancak dosyay\u0131 a\u00e7mak, sald\u0131rganlar\u0131n bilgisayara uzaktan eri\u015fmesini sa\u011flayan Androm arka kap\u0131s\u0131n\u0131 kurma riskini ta\u015f\u0131yor.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"ksc\">\n<h2>Kimlik av\u0131<\/h2>\n<p>Kimlik av\u0131 sald\u0131r\u0131lar\u0131 konusunda uzmanla\u015fm\u0131\u015f doland\u0131r\u0131c\u0131lar da teslimat piyasas\u0131 karma\u015fas\u0131ndan yararlan\u0131yor. Sahte izleme sayfalar\u0131n\u0131n yan\u0131 s\u0131ra resmi sitelerin inand\u0131r\u0131c\u0131 kopyalar\u0131n\u0131 tespit ettik. Hepsi elbette koronavir\u00fcsten bahsediyordu.<\/p>\n<p>\u00d6rne\u011fin, bir teslimat hizmeti m\u00fc\u015fterilerinin hesaplar\u0131n\u0131 hedefleyen kimlik avc\u0131lar\u0131, pandemi hakk\u0131nda en son haberler de dahil olmak \u00fczere \u015firketin resmi ana sayfas\u0131n\u0131 ayr\u0131nt\u0131l\u0131 bir \u015fekilde kopyalad\u0131.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-8168 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2020\/04\/28180725\/covid-delivery-service-spam-screen-6-7-1024x495.png\" alt=\"\" width=\"1024\" height=\"495\"><\/p>\n<p>En son koronavir\u00fcs haberlerinden bahseden di\u011fer sitelerin klonu olan bu site, di\u011fer siteler kadar detayl\u0131 bilgiler i\u00e7eriyor.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-8169 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2020\/04\/28180747\/covid-delivery-service-spam-screen-8-1024x439.png\" alt=\"\" width=\"1024\" height=\"439\"><\/p>\n<p>Paketleri izlemek i\u00e7in bu sahte portal\u0131n yazarlar\u0131, telif hakk\u0131 sat\u0131r\u0131na COVID-19\u2019u da eklediler. Bu sayfada, kimlik bilgilerini girmek i\u00e7in bir form ve \u201cortak\u201d e-posta hizmetlerinin bir listesi gibi \u00e7ok az bilgi yer al\u0131yor. Tabi ki, bu kaynakta kimlik bilgilerini girmek bu bilgileri doland\u0131r\u0131c\u0131lara g\u00f6nderiyor ve pakete neler oldu\u011funu kimse bilmiyor.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-8170 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2020\/04\/28180807\/covid-delivery-service-spam-screen-9-1024x576.png\" alt=\"\" width=\"1024\" height=\"576\"><\/p>\n<h2>Hilelere kanmamak<\/h2>\n<p>Salg\u0131n\u0131n arka plan\u0131na ve \u00e7ok say\u0131da ger\u00e7ek paket gecikmesine s\u00f6z konusu oldu\u011funda sahte siteler ve e-postalar\u0131n ba\u015far\u0131 elde etme \u015fans\u0131 y\u00fcksektir. Ger\u00e7ekten bir paket bekliyorsan\u0131z veya diyelim ki g\u00f6nderi detaylar\u0131 i\u015f e-postan\u0131za g\u00f6nderildiyse ve bir meslekta\u015f\u0131n\u0131z\u0131n sipari\u015fi vermi\u015f olabilece\u011fini d\u00fc\u015f\u00fcnmek i\u00e7in bir nedeniniz varsa bu sitelerin ba\u015far\u0131 \u015fans\u0131n\u0131 daha da artt\u0131r\u0131r. Bu duruma yakalanmamak i\u00e7in:<\/p>\n<ul>\n<li>G\u00f6nderenin adresine dikkatlice bak\u0131n. \u0130leti \u00fccretsiz bir e-posta hizmetinden geliyorsa veya posta kutusu ad\u0131nda anlams\u0131z karakterler i\u00e7eriyorsa b\u00fcy\u00fck olas\u0131l\u0131kla sahte bir e-postad\u0131r. Ancak, <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/36c3-fake-emails\/7644\/\" target=\"_blank\" rel=\"noopener\">g\u00f6nderen adresini taklit etmenin m\u00fcmk\u00fcn oldu\u011funu unutmay\u0131n<\/a>.<\/li>\n<li>Metne dikkat edin. B\u00fcy\u00fck bir \u015firket asla k\u00f6t\u00fc bi\u00e7imlendirilmi\u015f metin ve yanl\u0131\u015f dilbilgisi i\u00e7eren e-postalar g\u00f6ndermez.<\/li>\n<li>G\u00f6nderen \u00fczerinde \u0131srar ederse, teslimat hizmetlerinden gelen e-postalardaki ekleri a\u00e7may\u0131n. Bunun yerine, kurye web sitesinden ki\u015fisel hesab\u0131n\u0131za giri\u015f yap\u0131n veya takip numaras\u0131n\u0131 kontrol etmek i\u00e7in taray\u0131c\u0131n\u0131za servisin adresini manuel olarak girin. Bir ba\u011flant\u0131y\u0131 t\u0131klatman\u0131z\u0131 isteyen bir e-posta ald\u0131ysan\u0131z da bunu yap\u0131n.<\/li>\n<li>Bir mesaj koronavir\u00fcsten bahsediyorsa \u00f6zel dikkat g\u00f6sterin. Siber su\u00e7lular dikkat \u00e7ekmek i\u00e7in g\u00fcndemdeki konular\u0131 kullan\u0131r, bu nedenle bu t\u00fcr mesajlara uymak i\u00e7in asla acele etmemelisiniz.<\/li>\n<li>K\u00f6t\u00fc ama\u00e7l\u0131 ekleri alg\u0131layan ve kimlik av\u0131 web sitelerini engelleyen bir <a href=\"https:\/\/www.kaspersky.com.tr\/advert\/security-cloud?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____ksc___\" target=\"_blank\" rel=\"noopener\">g\u00fcvenilir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc<\/a> y\u00fckleyin.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"ksc\">\n","protected":false},"excerpt":{"rendered":"<p>Doland\u0131r\u0131c\u0131lar salg\u0131n s\u0131ras\u0131nda teslimat problemlerini kendi \u00e7\u0131karlar\u0131 i\u00e7in nas\u0131l kullan\u0131yorlar ve bu numaralardan nas\u0131l ka\u00e7\u0131nabiliriz<\/p>\n","protected":false},"author":2481,"featured_media":8157,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[519,1074,2112,240,537,1986],"class_list":{"0":"post-8156","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-ipuclari-2","9":"tag-kimlik-avi","10":"tag-koronavirus","11":"tag-spam","12":"tag-tehditler","13":"tag-truva-atlari"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/covid-fake-delivery-service-spam-phishing\/8156\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/covid-fake-delivery-service-spam-phishing\/20854\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/covid-fake-delivery-service-spam-phishing\/16530\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/covid-fake-delivery-service-spam-phishing\/8170\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/covid-fake-delivery-service-spam-phishing\/21611\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/covid-fake-delivery-service-spam-phishing\/19828\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/covid-fake-delivery-service-spam-phishing\/18581\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/covid-fake-delivery-service-spam-phishing\/22536\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/covid-fake-delivery-service-spam-phishing\/21490\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/covid-fake-delivery-service-spam-phishing\/28248\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/covid-fake-delivery-service-spam-phishing\/35125\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/covid-fake-delivery-service-spam-phishing\/14745\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/covid-fake-delivery-service-spam-phishing\/15106\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/covid-fake-delivery-service-spam-phishing\/13393\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/covid-fake-delivery-service-spam-phishing\/23839\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/covid-fake-delivery-service-spam-phishing\/28217\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/covid-fake-delivery-service-spam-phishing\/25350\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/covid-fake-delivery-service-spam-phishing\/22130\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/covid-fake-delivery-service-spam-phishing\/27430\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/covid-fake-delivery-service-spam-phishing\/27266\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/spam\/","name":"spam"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8156","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2481"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=8156"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8156\/revisions"}],"predecessor-version":[{"id":8173,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8156\/revisions\/8173"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/8157"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=8156"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=8156"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=8156"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}