{"id":8431,"date":"2020-06-10T14:25:40","date_gmt":"2020-06-10T11:25:40","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=8431"},"modified":"2020-06-10T14:25:40","modified_gmt":"2020-06-10T11:25:40","slug":"fake-djvu-ransomware-decryptor","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/fake-djvu-ransomware-decryptor\/8431\/","title":{"rendered":"\u015eifrelenmi\u015fi \u015fifrelemek: STOP \u015fifre \u00e7\u00f6z\u00fcc\u00fcdeki Zorab Truva At\u0131"},"content":{"rendered":"<p>\u0130nsanlar fidye yaz\u0131l\u0131mlar\u0131n\u0131n dosyalar\u0131n\u0131 \u015fifreledi\u011fini fark edince ne yaparlar? Muhtemelen ilk \u00f6nce pani\u011fe kap\u0131l\u0131r, ard\u0131ndan endi\u015fe eder, sonra da sald\u0131rganlara herhangi bir fidye \u00f6demeden veri kurtarman\u0131n yollar\u0131n\u0131 ararlar (<a href=\"https:\/\/www.kaspersky.com.tr\/blog\/no-no-ransom\/2582\/\" target=\"_blank\" rel=\"noopener\">bu beyhude bir \u00e7aba olsa da<\/a>). Ba\u015fka bir deyi\u015fle, \u00e7evrimi\u00e7i bir \u00e7\u00f6z\u00fcm bulmak i\u00e7in sorunu Google\u2019larlar veya sosyal a\u011flar \u00fczerinden tavsiye isterler. K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 STOP\/Djvu kurbanlar\u0131na yard\u0131m etmeyi ama\u00e7layan bir araca yerle\u015ftiren <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-ransomware-decryptor-double-encrypts-desperate-victims-files\/\" target=\"_blank\" rel=\"noopener nofollow\">Zorab Truva At\u0131<\/a> yarat\u0131c\u0131lar\u0131n\u0131n istedi\u011fi de tam olarak buydu.<\/p>\n<h2>Yem olarak sahte STOP \u015fifre \u00e7\u00f6z\u00fcc\u00fc<\/h2>\n<p>Siber su\u00e7lular, verileri \u015fifreleyen ve s\u00fcr\u00fcme ba\u011fl\u0131 olarak de\u011fi\u015ftirilen dosyalara djvu, .djvus, .djvuu, .tfunde, ve .uudjvu gibi bir uzant\u0131 atayan STOP\/Djvu fidye yaz\u0131l\u0131m\u0131 kurbanlar\u0131n\u0131n zaten kar\u015f\u0131la\u015ft\u0131\u011f\u0131 sorunlar\u0131 daha da k\u00f6t\u00fcle\u015ftirmeye karar vermi\u015flerdi. Zorab\u2019\u0131n yarat\u0131c\u0131lar\u0131, bu dosyalar\u0131n \u015fifresini \u00e7\u00f6zd\u00fc\u011f\u00fcn\u00fc iddia ettikleri yard\u0131mc\u0131 bir program yay\u0131nlad\u0131, ancak bu program asl\u0131nda dosyalar\u0131 tekrar \u015fifreliyordu.<\/p>\n<p>Ger\u00e7ekten de STOP\u2019\u0131n \u00f6nceki s\u00fcr\u00fcmleri taraf\u0131ndan g\u00fcvenli\u011fi ihlal edilen dosyalar\u0131n \u015fifresi \u00e7\u00f6z\u00fclebiliyordu; Emsisoft Ekim 2019\u2019da bir <a href=\"https:\/\/www.emsisoft.com\/ransomware-decryption-tools\/stop-djvu\" target=\"_blank\" rel=\"noopener nofollow\">ara\u00e7 yay\u0131nlam\u0131\u015ft\u0131<\/a>. Ancak modern s\u00fcr\u00fcmler, mevcut teknolojinin k\u0131ramayaca\u011f\u0131 daha g\u00fcvenilir bir \u015fifreleme algoritmas\u0131 kullan\u0131yor. Yani en az\u0131ndan \u015fimdilik, STOP\/Djvu\u2019nun modern versiyonlar\u0131 i\u00e7in herhangi bir \u015fifre \u00e7\u00f6zme program\u0131 mevcut de\u011fil.<\/p>\n<p>\u201c\u015eimdilik\u201d diyoruz, \u00e7\u00fcnk\u00fc \u015fifre \u00e7\u00f6zme ara\u00e7lar\u0131 iki durumdan birinde ortaya \u00e7\u0131k\u0131yor: Ya siber su\u00e7lular \u015fifreleme algoritmas\u0131nda bir hata yap\u0131yor (veya sadece zay\u0131f bir \u015fifre kullan\u0131yor) ya da polis, sunucular\u0131n\u0131 buluyor ve ele ge\u00e7iriyor. Elbette, i\u00e7erik olu\u015fturucular anahtarlar\u0131 g\u00f6n\u00fcll\u00fc olarak da yay\u0131nlayabilirler, ancak bu pek muhtemel de\u011fildir. Yay\u0131nlasalar bile, bilgi g\u00fcvenli\u011fi \u015firketleri yine de kurbanlar\u0131n verilerini geri y\u00fcklemek i\u00e7in kullanabilece\u011fi kullan\u0131\u015fl\u0131 bir yard\u0131mc\u0131 program olu\u015fturmak zorundad\u0131r. Shade fidye yaz\u0131l\u0131m\u0131n\u0131n vurdu\u011fu dosyalar i\u00e7in yay\u0131nlanan anahtarlar i\u00e7in de b\u00f6yle oldu ve bu y\u0131l <a href=\"https:\/\/noransom.kaspersky.com\/tr\/\" target=\"_blank\" rel=\"noopener\">Nisan ay\u0131nda bir \u015fifre \u00e7\u00f6zme program\u0131 yay\u0131nlad\u0131k<\/a>.<\/p>\n<h2>Bir \u015fifre \u00e7\u00f6z\u00fcc\u00fcn\u00fcn sahte olup olmad\u0131\u011f\u0131 nas\u0131l anla\u015f\u0131l\u0131r<\/h2>\n<p>Ad\u0131 san\u0131 belli olmayan, anonim iyi niyetli ki\u015filerin bir \u015fifre \u00e7\u00f6zme yard\u0131mc\u0131 program\u0131 yaratmas\u0131, bilinmeyen bir siteye yerle\u015ftirmesi veya bir forum veya sosyal a\u011fda do\u011frudan bir ba\u011flant\u0131 sa\u011flamas\u0131 olas\u0131l\u0131\u011f\u0131 \u00e7ok d\u00fc\u015f\u00fckt\u00fcr. Ger\u00e7ek yard\u0131mc\u0131 programlar\u0131, bilgi g\u00fcvenli\u011fi \u015firketlerinin web sitelerinde veya <a href=\"https:\/\/www.nomoreransom.org\/en\/index.html\" target=\"_blank\" rel=\"noopener nofollow\">nomoreransom.org<\/a> gibi fidye yaz\u0131l\u0131mlar\u0131yla sava\u015fmaya adanm\u0131\u015f \u00f6zel portallarda bulabilirsiniz. Ba\u015fka bir yerde bulunan ara\u00e7lara \u015f\u00fcpheyle yakla\u015f\u0131n.<\/p>\n<p>Siber su\u00e7lular pani\u011fe g\u00fcvenir; dosyalar\u0131n\u0131 bir \u015fifreleyiciye kapt\u0131ran birinin dosyalar\u0131 kurtarmak i\u00e7in her \u015feyi yapabilece\u011fini d\u00fc\u015f\u00fcn\u00fcrler. Bir arac\u0131n iyi niyetli oldu\u011funa inansan\u0131z bile, sakin ve objektif kalman\u0131z ve siteyi d\u00fczg\u00fcn bir \u015fekilde do\u011frulaman\u0131z \u00f6nemlidir. Ger\u00e7ekli\u011fi konusunda herhangi bir \u015f\u00fcpheniz varsa o araca dokunmay\u0131n.<\/p>\n<h2>Zorab ve di\u011fer fidye yaz\u0131l\u0131mlar\u0131na kar\u015f\u0131 kendinizi nas\u0131l koruyabilirsiniz<\/h2>\n<ul>\n<li>Kaynaklar\u0131na g\u00fcvenmiyorsan\u0131z \u015f\u00fcpheli ba\u011flant\u0131lar\u0131 izlemeyin veya y\u00fcr\u00fct\u00fclebilir dosyalar\u0131 \u00e7al\u0131\u015ft\u0131rmay\u0131n. Bir \u015fifre \u00e7\u00f6z\u00fcc\u00fc ar\u0131yorsan\u0131z en g\u00fcvenilir kaynaklar, yani aramaya ba\u015flaman\u0131z gereken yerler; <a href=\"https:\/\/noransom.kaspersky.com\/tr\/\" target=\"_blank\" rel=\"noopener\">noransom.kaspersky.com<\/a>, <a href=\"https:\/\/www.nomoreransom.org\/\" target=\"_blank\" rel=\"noopener nofollow\">nomoreransom.org<\/a> (birka\u00e7 \u015firket taraf\u0131ndan y\u00fcr\u00fct\u00fclen ortak bir proje) ve di\u011fer g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc sa\u011flay\u0131c\u0131lar\u0131n\u0131n siteleri olacakt\u0131r. Ba\u015fka bir yerde bir yard\u0131mc\u0131 program bulursan\u0131z kullanmay\u0131 d\u00fc\u015f\u00fcnmeden \u00f6nce yazarlar\u0131n\u0131n ve yay\u0131nland\u0131\u011f\u0131 sitenin do\u011frulu\u011funu kontrol etmenizi \u015fiddetle tavsiye ederiz.<\/li>\n<li><a href=\"https:\/\/www.kaspersky.com.tr\/blog\/how-to-backup\/4212\/\" target=\"_blank\" rel=\"noopener\">\u00d6nemli dosyalar\u0131n yedek kopyalar\u0131n\u0131 olu\u015fturun<\/a>.<\/li>\n<li>Bilinen fidye yaz\u0131l\u0131mlar\u0131n\u0131 tespit eden ve bilinmeyen bir \u015feyle kar\u015f\u0131la\u015ft\u0131\u011f\u0131nda dosyalar\u0131 de\u011fi\u015ftirme giri\u015fimlerini tan\u0131mlayan ve engelleyen <a href=\"https:\/\/www.kaspersky.com.tr\/internet-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kismd___\" target=\"_blank\" rel=\"noopener\">g\u00fcvenilir bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc<\/a> kullan\u0131n.<\/li>\n<\/ul>\n<p>Fidye yaz\u0131l\u0131mlar\u0131ndan korkan ancak di\u011fer korumalara g\u00fcvenen \u015firketler i\u00e7in de ba\u011f\u0131ms\u0131z <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/kaspersky-anti-ransomware-tool-for-business\/?utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=tr_KB_nv0092&amp;utm_content=link&amp;utm_term=tr_kdaily_organic_cdw92oxvuhcab46\" target=\"_blank\" rel=\"noopener\">Kaspersky Anti-Ransomware Tool<\/a> yaz\u0131l\u0131m\u0131n\u0131 sunuyoruz. Kaspersky Anti-Ransomware Tool, \u00e7o\u011fu g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fcyle uyumlu olarak bu savunma hatlar\u0131n\u0131 a\u015fabilecek tehditleri tespit eder.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kartb2b\">\n","protected":false},"excerpt":{"rendered":"<p>Siber su\u00e7lular, STOP Truva At\u0131 taraf\u0131ndan \u015fifrelenen dosyalar\u0131n \u015fifresini \u00e7\u00f6zmek i\u00e7in bir ara\u00e7 k\u0131l\u0131\u011f\u0131nda gizledikleri bir fidye yaz\u0131l\u0131m\u0131n\u0131 yay\u0131yor.<\/p>\n","protected":false},"author":2581,"featured_media":8432,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1194,1727,1351],"tags":[591,926,982,1304],"class_list":{"0":"post-8431","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-smb","9":"category-threats","10":"tag-fidye-yazilimi","11":"tag-nomoreransom","12":"tag-noransom","13":"tag-sifre-cozuculer"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/fake-djvu-ransomware-decryptor\/8431\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/fake-djvu-ransomware-decryptor\/21423\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/fake-djvu-ransomware-decryptor\/16888\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/fake-djvu-ransomware-decryptor\/8328\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/fake-djvu-ransomware-decryptor\/22519\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/fake-djvu-ransomware-decryptor\/20664\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/fake-djvu-ransomware-decryptor\/19068\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/fake-djvu-ransomware-decryptor\/22906\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/fake-djvu-ransomware-decryptor\/21919\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/fake-djvu-ransomware-decryptor\/28554\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/fake-djvu-ransomware-decryptor\/35824\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/fake-djvu-ransomware-decryptor\/15047\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/fake-djvu-ransomware-decryptor\/15582\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/fake-djvu-ransomware-decryptor\/13550\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/fake-djvu-ransomware-decryptor\/24238\/"},{"hreflang":"zh","url":"https:\/\/www.kaspersky.com.cn\/blog\/fake-djvu-ransomware-decryptor\/11571\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/fake-djvu-ransomware-decryptor\/28621\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/fake-djvu-ransomware-decryptor\/25531\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/fake-djvu-ransomware-decryptor\/22450\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/fake-djvu-ransomware-decryptor\/27706\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/fake-djvu-ransomware-decryptor\/27548\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/fidye-yazilimi\/","name":"Fidye Yaz\u0131l\u0131m\u0131"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8431","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2581"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=8431"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8431\/revisions"}],"predecessor-version":[{"id":8433,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8431\/revisions\/8433"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/8432"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=8431"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=8431"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=8431"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}