Journals / Uluslararası Yönetim Bilişim Sistemleri ve Bilgisayar Bilimleri Dergisi / 2018 / Cilt: 2 - Sayı: 2

DETECTION, TECHNICAL ANALYSIS AND SOLUTION OF TESLACRYPT RANSOMWARE VIRUS

TESLACRYPT FİDYE YAZILIM VİRÜSÜNÜN TESPİTİ, TEKNİK ANALİZİ VE ÇÖZÜMÜ

Pages
87–94
DOI
—

Abstract

Although the rapid developments in information technologies have facilitated numerous things in the lives of Internet users, these developments also allow malicious people to reach their goals faster. Malicious software that completely drift away from their initial design goal are now being designed by professional criminals for a wide range of applications from cyber terrorism to ransom demands. These criminals reach their goals easily by developing a variety of methods and tactics, and the possibility of being exposed to this situation becomes the worst nightmare for the users. Recently, a new generation of Ransomware, known as TeslaCrypt, has begun to be seen worldwide. TeslaCrypt reaches users through e-mail and encrypts many files in the system after execution of its payload found in the e-mail attachment. It demands ransom to allow access to encrypted files of the user. Although there are continuing works to find a solution to this problem caused by TeslaCrypt, there is still no definitive solution. This study discusses the detection of TeslaCrypt threat, and technical analysis on its infiltration into the target system and file-directory actions in the system and solution. The analysis has been performed by both static and dynamic methods. As a result of the study, it was shown that the passwords caused by the ransomware virus broke the password.

Özet

Bilişim teknolojilerinde yaşanan hızlı gelişmeler internet kullanıcılarının hayatında pek çok şeyi kolaylaştırmışken, kötü niyetli kişilerinde amaçlarına daha hızlı ulaşması için yeni olanaklar sağlamaktadır. İlk tasarım amacından tamamen uzaklaşan zararlı yazılımlar, günümüzde profesyonel suçlular tarafından siber terörizmden fidye istemeye kadar geniş bir uygulama alanı için tasarlanmaktadır. Bu suçlular çok çeşitli yöntemler ve taktikler geliştirerek amaçlarına kolaylıkla ulaşmakta, bu duruma maruz kalma olasılığı kullanıcıların korkulu rüyası haline gelmektedir. Son günlerde dünya genelinde TeslaCrypt olarak adlandırılan yeni nesil fidye yazılım siber saldırı vakaları görülmeye başlamıştır. TeslaCrypt, kullanıcılara e-mail yoluyla ulaşarak ekinde bulunan zararlı yazılımın çalıştırılması ile sistemdeki birçok dosyayı şifrelemektedir. Kullanıcının şifrelenmiş dosyalara erişim sağlayabilmesi için fidye göndermesini istemektedir. TeslaCrypt’nin sebep olduğu bu durum için çalışmalar devam etmekle birlikte hala kesin çözüm bulunamamıştır. Bu çalışma, TeslaCrypt tehditinin tespiti, hedef sisteme sızma, sistemdeki dosya-dizin hareketlerinin teknik analizini ve çözümünü içermektedir. İncelemeler; hem statik hem de dinamik yöntemlerle gerçekleştirilmiştir. Çalışma sonucunda fidye yazılımının neden olduğu şifrelerin kırılabilir olduğu gösterilmiştir.

Keywords: Zararlı Yazılım Analizi, Fidye Yazılımı, Kriptokitleyici