Janairu 28, 2020

Hawan Taurari Ubangiji: Sabon Malware don Sabuwar Shekaru

Na'urori da tsarin aiki suna canzawa akan lokaci, kuma kamar yadda sukeyi, wasu daga cikin malware masu yawo a yanar gizo sun zama tsofaffi, ba sa iya kutsawa cikin sabbin kariya ko sauke nauyin biyansu a kan wasu hadaddun injina. Don haka, kowane yearsan shekaru, mahaliccin malware suna buƙatar yanke shawara: ƙyale tsofaffin malware su mutu ko sabunta shi don tsara mai zuwa?

Kamar yadda ɗakunan kallon fina-finai suke da sha'awar sake fasalin tsoffin fannoni don matasa, haka ma marubutan malware suke son rayar da tsohuwar ƙirar malware don sabbin na'urori. Amma duk da haka, maimakon mace mai suna Jedi mai cike da damuwa, Pikachu-wanda aka kara da maganin kafeyin, ya kamata masu amfani da na'urar su yi taka tsantsan da Tauraruwa, wani nau'I na kayan kwalliya mai dauke da kayan kwalliya wanda shi ne sabon kayan kwalliyar da zai kawo barazana.

Menene Taurari?

Kafin mu iya tunkarar da keɓaɓɓun kayyakin na StarsLord, yana da mahimmanci a fahimci nau'in malware da wannan harin ya faɗa ciki. Nau'in adaukar kayan kwalliya kamar masu jigilar kayan aiki ne na masifa: Duk da cewa suna iya samun makaman da aka gina su, galibi suna ajiye wasu motocin da aka yi amfani da su don kai harin.

A takaice dai, an tsara masu loda abubuwa don yin sihiri a kan wata na'urar da aka nufa sannan kuma a sanya dukkan wasu masu aiwatar da mummunan aiki, galibi ana samunsu daga uwar garken da ke kula da maharan. Wani lokaci, ana bayyana masu ɗaukar kaya azaman Trojan don samun damar nesa saboda ƙarancin alama suna da haɗari ga masu amfani da halal kuma suna ba maharan ikon sarrafa kayan aiki wanda shine abin da ya dawo da mu zuwa StarsLord.

StarsLord, wanda ake kira StarsLoad da sLoad a takaice, Trojan ne na PowerShell, ma’ana yana da ƙarfi Windows's PowerShell mai amfani da mai amfani, wanda ke sarrafa kansa ayyukan ƙididdiga masu mahimmanci kuma yana taimakawa cikin gudanarwar sanyi.

Ainihi, PowerShell kayan aiki ne mai iko na kayan aiki, kuma maharin da ke sarrafa shi zai iya yin abin da suke so - amma wannan ba sabon abu bane musamman don ɓarnatar da abubuwa. A zahiri, a cikin jerin hare-harenta, StarsLord bai bambanta da waɗanda suka gabace shi ba: Yana girka kanta akan tsarin, yana haɗuwa da sabar sa ta nesa sannan yana zazzage ƙarin ɓarnatarwar. Menene juyin-juya hali shine yadda Taurari ke gujewa kamawa.

StarsLord yayi amfani da wani ingantaccen ɓangaren Windows, wanda ake kira Sabis na Ƙarin Bayani na Intanit (BITS) don canza fayilolin ƙeta a bango, ba tare da gudanar da kowane aikace-aikace ba. Ari, StarsLord na zazzage rubutun PowerShell ta amfani da Fayil ɗin Windows ɗin Windows da ƙari .jpg. Don haka, wasu ayyukan riga-kafi na gwagwarmaya don gano malware a matsayin barazana.

Menene ƙari, StarsLord yana alfahari da kowane irin fasali wanda aka tsara don mamaye da lalata matakan tsaro na mai amfani, don haɗawa da:

  • Gudanarwa, ko taƙaita isa ga abun ciki dangane da wurin mai amfani
  • Bin-sawu, ko bawa maharin bayani game da matakin cutar
  • Hotowa, ko keɓance injunan masu nazari don dakile zurfin fahimtar ayyukan malware

Tare da duk waɗannan fasalolin da suka ci gaba, tabbas StarsLord tamkar wata muhimmiyar mahimmancin juyin halitta ne wanda ya cancanci sabon shekaru goma - amma shin akwai wani abu da masu amfani zasu iya yi don su fita daga kangin ta?

Ta Yaya Masu Amfani zasu Dakatar da Taurari?

Loaders suna ƙaruwa cikin rikitarwa da yaɗuwa saboda godiyarsu da sassauƙa don dacewa da niyyar mai kai hari. Koyaya, saboda masu lodin ba su ba da irin wannan kwarewar ga kowane wanda aka cuta - kuma saboda ayyukan masu lodin ba su da sauƙi ga masu fasaha da fasaha su fahimta - masu amfani ba su da masaniya da masu ɗora kaya kamar yadda suke da sauran nau'ikan malware, kamar ransomware . Abin takaici, wannan yana nufin cewa ba a ba da kuɗi da ƙoƙari da yawa a halin yanzu don hana wannan barazanar ta ƙaruwa.

Abin farin ciki, StarsLord yana da wani abu mai mahimmanci a tare da ɗayan, ƙarin ɓarnatarwar malware da ta zo kafin: yadda ake samun tsarin mai amfani. StarsLord koyaushe yana zuwa kan na'urorin masu amfani a cikin imel, tare da haɗin ZIP.

Abubuwan da imel ɗin keɓaɓɓu ne ga yaren mai amfani kuma yana iya haɗawa da sunan mai amfani da adiresoshin, don ƙarfafa amintarwa da ƙarfafa sauke fayil ɗin da aka haɗe. Sabili da haka, masu amfani zasu iya nisantar StarsLord ta hanyar bin ɗayan mahimman ƙa'idodin tsabtace yanar gizo: Kada ku yi hulɗa tare da saƙonnin da ba zato ba tsammani. Bugu da ƙari, m riga-kafi kariya yakamata ya iya gano barazanar a cikin imel ɗin kafin masu amfani suyi kuskure.

Wataƙila mafi mahimmanci darasi daga Tauraruwa shine: Ko da maimaita sakewa bai yi labarai ba, yana iya haifar da raƙuman ruwa a cikin masana'antar. StarsLord da sauran nau'ikan malware masu ɗauke da kaya suna iya canzawa sosai a cikin watanni da shekaru masu zuwa, suna iya zama wasu daga cikin barazanar da ke cikin yanar gizo. Ta hanyar bin diddigin waɗannan abubuwan da suka faru a farkon, masu amfani na iya sanin abin da ya kamata su nema da kuma yadda za su kasance cikin aminci, duk da cewa yanayin fasahar yana girma yana canjawa.

Game da marubucin 

Imran Uddin


{"email": "Adireshin imel ba daidai ba ne", "url": "Adireshin gidan yanar gizo ba shi da inganci", "required": "Filin da ake buƙata ya ɓace"}