Hacker News

7zip.com Le Dɔwɔnu Vɔ̃ɖiwo Subɔm

7zip.com Le Dɔwɔnu Vɔ̃ɖiwo Subɔm 7zip ƒe numekuku blibo sia na wodzro eƒe akpa veviwo me tsitotsito kple gɔmesese siwo keke ta wu. Nu Vevi Siwo Ŋu Wòalé Be Na Numedzodzroa ku ɖe: Mɔnu veviwo kple dɔwɔwɔwo ...

11 min read Via www.malwarebytes.com

Mewayz Team

Editorial Team

Hacker News

7zip.com le malware subɔm vevie na zãla siwo mesusui o siwo ŋlɔ 7-Zip download URL si le se nu vodadatɔe. Ne wò alo ame aɖe le wò habɔbɔa me yi 7zip.com nyitsɔ laa hele file compression utility xɔŋkɔa dim la, wò dɔwɔɖoɖowo ate ŋu agblẽ eye ahiã be nàwɔ afɔɖeɖe enumake.

Nuka Tututue Le dzɔdzɔm le 7zip.com?

7-Zip kɔmpiuta dɔwɔɖoɖo si le se nu — si nye dɔwɔnu siwo wozãna wu siwo wozãna tsɔ dzraa faɛlwo ɖo le mɔ gbadza nu le xexeame la dometɔ ɖeka — womae le se nu to 7-zip.org dzi, ke menye to 7zip.com dzi o. Internet dzi dedienɔnɔ ŋuti numekulawo ɖo kpe edzi be 7zip.com nye ŋɔŋlɔdzesi ŋɔŋlɔdzesiwo, nyatakakadzraɖoƒe vɔ̃ɖi aɖe si wowɔ be wòalé ezãla siwo tsɔa dzesidenua ƒua gbe ne wole URL ŋutɔŋutɔ ŋlɔm.

Ne amedzrowo ɖi go ɖe 7zip.com la, wotsɔa 7-Zip nyatakakadzraɖoƒe si le se nu ƒe nɔnɔmetata si ŋu kakaɖedzi le la ɖoa wo ŋkume. Axaa srɔ̃a gbãtɔa ƒe ɖoɖo, dzesideŋkɔ, kple eƒe kɔpi ƒe dzesiwo kple nyateƒetoto dziŋɔ aɖe. Ke hã, faɛl siwo wole mamam tso domenyiŋusẽfianu sia me la menye 7-Zip installer vavãtɔ o — wonye trojanized executables siwo wobla kple malware payloads siwo dometɔ aɖewoe nye info-stealers, remote access trojans (RATs), kple credential harvesting software.

Afɔku le amedzidzedzea me vevietɔ elabena ewɔa kakaɖedzi si zãlawo le kɔmpiutadziɖoɖo ƒe adzɔnu xɔŋkɔ aɖe si ŋu ŋkɔ le dzi ŋudɔ. Susu aɖeke manɔ zãla akpa gãtɔ si be woalé ŋku ɖe URL la ŋu nyuie ne wole kɔmpiutadziɖoɖo siwo wozã dedie ƒe geɖe la ƒe kɔpi wɔm o.

Aleke Malware Amedzidzedze Sia Wɔa Dɔe?

Mɔ̃ɖaŋununya ƒe mɔnu si le megbe na 7zip.com ƒe amedzidzedzea kplɔa fefegbalẽ si woŋlɔ ɖi nyuie si nye typosquatting, gake kple ƒuƒoƒo deŋgɔ geɖe siwo na wòwɔa dɔ etɔxɛe:

    ƒe nyawo
  1. Domain ƒe ŋkɔ ŋɔŋlɔ: Amedzidzelawo ŋlɔa 7zip.com — si nye 7-zip.org si le se nu ƒe nuŋɔŋlɔ vodadatɔe si bɔ — eye wotua nyatakakadzraɖoƒe gbãtɔ ƒe nɔnɔmetata si sɔ pɛpɛpɛ.
  2. SEO aɖi: Wotrɔ asi le domenyiŋusẽfianu vɔ̃ɖi la ŋu be wòaɖo nɔƒe le didiƒe ƒe emetsonuwo me na biabia abe "download 7zip" alo "7zip free download," si ana organic traffic dzina ɖe edzi tso didimɔ̃wo gbɔ.
  3. Trojanized installer delivery: Ne èzi download ƒe dzesi ɖesiaɖe dzi le nyatakakadzraɖoƒea la, ana executable si me 7-Zip installer ŋutɔŋutɔ (be woaƒo asa na ɖikeke) kple malware ƒe akpa ɣaɣlawo siaa le.
  4. Silent payload execution: Ne wonya wɔ dɔ ko la, malware la ɖoa madzudzɔmadzudzɔe ɖe ɖoɖoa dzi, zi geɖe la, ewɔa megbedɔwɔwɔ siwo ɖea nyagbe ɣaɣla siwo wodzra ɖo, browser cookies, cryptocurrency wallet data, kple dɔwɔƒea ƒe ɖaseɖigbalẽwo ɖa.
  5. Sedede kple dziɖuɖu ƒe kadodo: Malware telefonwo nyea aƒe na amedzidzela ƒe dɔwɔƒe siwo dzi wokpɔna, si wɔnɛ be woate ŋu akpɔ mɔ̃ siwo ŋu dɔlélea le le didiƒe le ɣeyiɣi didi aɖe le nugblẽfexeɖoɖo gbãtɔ megbe.
ƒe nyawo

Afɔɖeɖe geɖe ƒe mɔnu sia fia be zãla siwo de dzesi nane si mebɔ o le eɖoɖo vɔ megbe gɔ̃ hã ate ŋu menya be woɖo megbeʋɔtru ɖe yewoƒe ɖoɖoa dzi xoxo o.

Amekae Le Afɔku Me Wu Tso 7zip.com Malware Dɔwɔna Me?

Togbɔ be ame ɖekaɖeka ɖesiaɖe zãla le afɔku me hã la, ŋɔdzia nu sẽ ŋutɔ na dɔwɔƒewo kple habɔbɔwo. Dɔwɔɖoɖodzikpɔlawo, dɔwɔlawo, kple IT dɔwɔlawo ɖea dɔwɔnuwo abe 7-Zip ene ɖe dɔwɔƒe ƒe mɔ̃wo, dɔwɔƒewo, kple nuto siwo me woama wo me enuenu. Nuwuƒe ɖeka si dɔlékui le le dɔwɔƒe ƒe kadodo me ateŋu anye ƒuta ta na axadziʋuʋu, ransomware ƒe dɔwɔwɔ, alo nyatakakawo ɖeɖe ɖa si akpɔ ŋusẽ ɖe habɔbɔ bliboa dzi.

ƒe nyawo

"Typosquatting amedzidzedze ɖe kɔmpiutadziɖoɖo ƒe domenyinyi siwo dzi woka ɖo ŋu tsi tre ɖi na ŋɔdzinu siwo wobu nu tsɛe wu dometɔ ɖeka le dɔwɔƒe ƒe dedienɔnɔ me. URL ɖeka si womeŋlɔ vodadatɔe o ateŋu agblẽ habɔbɔ blibo ƒe network me le gaƒoƒo aɖewo me."

💡 DID YOU KNOW?

Mewayz replaces 8+ business tools in one platform

CRM · Invoicing · HR · Projects · Booking · eCommerce · POS · Analytics. Free forever plan available.

Start Free →
ƒe nyawo

Adzɔha suewo kple dɔwɔƒe yeyewo koŋue le afɔku me elabena zi geɖe la, dedienɔnɔ ƒe ƒuƒoƒo siwo tsɔ wo ɖokui na be woalé ŋku ɖe nusiwo fia be wogblẽ nu le wo ŋu la menɔa wo si o. Dɔwɔla siwo le wo ɖokui si, dɔwɔla siwo le didiƒe, kple amesiame si le dɔwɔnu geɖewo dzi kpɔm le mɔ̃ geɖe dzi — ezãla siwo ƒe susu nɔa dɔwɔwɔ ŋu tututu siwo ɖoa ŋu ɖe dɔwɔƒe siwo le dɔ wɔm abe 7-Zip ene ŋu gbesiagbe — dzea ŋgɔ nukpɔkpɔ geɖe.

Aleke Nàte Ŋu Akpɔ Wò Dɔwɔƒe Ta Tso Typosquatting Malware Me?

Takpɔkpɔ tso amedzidzedze abe 7zip.com ƒe dɔwɔwɔ ene me bia be woatsɔ mɔ̃ɖaŋununya ƒe dziɖuɖu kple amegbetɔ ƒe sidzedze ƒo ƒu. Afɔɖeɖe siwo gbɔna ɖea wò habɔbɔa ƒe nukpɔkpɔ dzi kpɔtɔna ŋutɔ:

    ƒe nyawo
  • Lé ŋku ɖe URLwo ŋu ɣesiaɣi hafi nàwɔ kɔmpiutadziɖoɖowo ƒe kɔpi. De dzesi nyatakakatsoƒe siwo dziɖuɖua da asi ɖo. 7-Zip ŋutɔŋutɔ le 7-zip.org ɖeɖeko.
  • Zã DNS ƒe ʋuʋu ƒe kuxiwo gbɔkpɔnu siwo xea mɔ na domenyinyi vɔ̃ɖi siwo wonya le network ƒe ɖoɖo nu hafi zãlawo ateŋu atsɔ axaa gɔ̃ hã.
  • Na nuwuƒe didi kple ŋuɖoɖo (EDR) dɔwɔnuwo nawɔ dɔ siwo ateŋu ade dzesi dɔwɔwɔ ƒe nuwɔna si mebɔ o si trojanized installers ʋã.
  • Wɔ dedienɔnɔ ŋuti nyanyanana hehexɔxɔ edziedzi ale be ƒuƒoƒoa me tɔ ɖesiaɖe nase afɔku si le ŋɔŋlɔdzesiwo ŋɔŋlɔ me gɔme eye wòanya alesi woaɖo kpe kɔpitsoƒewo dzi.
  • Dzro kɔmpiuta dɔwɔɖoɖo siwo woda ɖe eme nyitsɔ laa le nuwuƒewo katã. Ne wò ƒuƒoƒoa me tɔ aɖe ate ŋu ayi 7zip.com la, bu mɔ̃ mawo be woate ŋu agblẽ nu le wo ŋu eye nàdze nudzɔdzɔwo gbɔ kpɔkpɔ ƒe ɖoɖowo gɔme enumake.
ƒe nyawo |

Nukae Wòle Be Nàwɔ Ne Èyi 7zip.com?

Ne èsusu be yeɖe kɔmpiutadziɖoɖowo tso 7zip.com la, wɔ nu enumake. Ðe mɔ̃ si ŋu wògblẽ nu le la ɖa le wò network la ŋu be wòagakaka ɖe axadzi o. Zã dɔlékuiwutike kple dɔlékui vɔ̃ɖiwo ƒe dɔwɔnu si ŋu ŋkɔ le nàtsɔ awɔ scan bliboa. Trɔ nyagbe ɣaɣla siwo katã wodzra ɖo ɖe web-browser me le mɔ̃ si ŋu wòku ɖo la dzi — tsɔ gadzraɖoƒe, e-mail, kple asitsanyawo ɖo nɔƒe gbãtɔ. Dzro wò web-browser ƒe ɖaseɖigbalẽ siwo wodzra ɖo me eye nàna nu geɖe ƒe kpeɖodzi nawɔ dɔ le akɔnta veviwo katã dzi. Gblɔ nudzɔdzɔa na wò IT alo dedienɔnɔ ƒe ƒuƒoƒoa eye nàbu eŋu be yeawɔ dɔ kple nudzɔdzɔwo gbɔ kpɔkpɔ ƒe dɔwɔƒe aɖe nenye be ɖewohĩ wokpɔ asitsanyatakaka veviwo.

Mègasusu be faɛl si woɖe ɖe go la ɖeɖeɖa akpɔ kuxia gbɔ o. Malware payload geɖewo ɖoa persistence mɔnuwo si tsia agbe le software ɖeɖeɖa kple system gbugbɔgadzedze gɔ̃ hã me.

Nyabiase Siwo Wobiana Enuenu

Ðe 7-Zip ŋutɔ nye ɖoɖowɔɖi si me afɔku le?

Ao. 7-Zip kɔmpiutadziɖoɖo si le se nu, si woate ŋu akpɔ tso 7-zip.org la nye faɛlwo dzraɖoƒe si dzi woate ŋu aka ɖo, si woate ŋu azã le mɔ vovovowo nu, eye wozãe dedie tso gbaɖegbe ke. Afɔkua le aʋatso nyatakakadzraɖoƒe si nye 7zip.com, si maa installer la ƒe aʋatso tɔtrɔ siwo wotsɔ kpe ɖe kɔmpiutadziɖoɖo vɔ̃ɖiwo ŋu la gbɔ. Wɔ 7-Zip ƒe kɔpi ɣesiaɣi tso domenyiŋusẽfianu si dziɖuɖua ɖo si dzi woŋlɔ nu ɖo la me ɖeɖeko: 7-zip.org.

Aleke mawɔ anya ne malware si tso 7zip.com gakpɔtɔ le dɔ wɔm le nye dɔwɔɖoɖoa dzi?

Dzesi siwo bɔ dometɔ aɖewoe nye CPU alo network ƒe dɔwɔna si mebɔ o, dɔwɔwɔ yeye siwo mènya o siwo le dɔ wɔm le Dɔdzikpɔla me, web-browser ƒe blewu, akɔntabubu ƒe ʋuʋu le vome, alo nuxlɔ̃ame siwo tso wò dɔlékuiwutikewo gbɔ. Gake egbegbe nyatakakawo-fila geɖe wɔa dɔ le ɖoɖoezizi me. Ne èɖee tso 7zip.com la, bu mɔ̃a be edze afɔku metsɔ le dzesi siwo woate ŋu akpɔ me o eye nàwɔ ʋɔnudrɔ̃ƒe ƒe numekuku blibo.

Ðe asitsatsa dzikpɔkpɔ ƒe mɔnu zazã ateŋu akpeɖe ŋu be woaɖe dedienɔnɔ ƒe afɔku sia ƒomevi dzi akpɔtɔa?

Ẽ. Asitsahabɔbɔ siwo le teƒe ɖeka siwo kpɔa kɔmpiutadziɖoɖowo ƒeƒle, dɔwɔlawo ƒe mɔɖeɖe dzi kpɔkpɔ, kple dɔwɔwɔ ƒe dzidzenuwo dzi ɖea alesi wòanya wɔ be dɔwɔlawo nakpɔ dɔwɔnuwo tso ame bubuwo ƒe nyatakakadzraɖoƒe siwo womekpɔ kpɔ o dzi kpɔtɔna. Ne kɔmpiutadziɖoɖowo ƒe kɔpiwɔwɔ kple wo dzi dada le titina ɖoɖo aɖe si me dedienɔnɔ ŋuti ɖoɖo siwo wotu ɖe eme le dzi la, amedzidzedze ƒe anyigba na ŋɔŋlɔdzesiwo ƒe dɔwɔwɔwo dzi ɖena kpɔtɔna ŋutɔ.


ƒe nyawo

Wò dɔwɔƒea takpɔkpɔ tso ŋɔdzidonamewo abe 7zip.com malware campaign ene me bia dɔwɔnu nyuitɔ, hehe nyuitɔ, kple dɔwɔwɔ ƒe gɔmeɖoanyi nyuitɔ. Mewayz naa wò ƒuƒoƒoa kpɔa asitsatsa ƒe dɔwɔɖoɖo ɖeka, si le dedie — modules 207 siwo wotsɔ wɔ ɖekae siwo ƒo nu tso nusianu ŋu tso ƒuƒoƒoa dzikpɔkpɔ dzi va ɖo dɔwɔwɔ ƒe nuwo wɔwɔ le wo ɖokui si dzi — ale be nèzãa ɣeyiɣi ʋɛ aɖewo tsɔ ɖɔa afɔkuwo ɖo eye nèzãa ɣeyiɣi geɖe tsɔ tua woe. Zãla siwo wu 138,000 ka ɖe Mewayz dzi be wòawɔ woƒe dɔwɔnawo nyuie eye wòanɔ dedie.

Dze wò Mewayz mɔzɔzɔ gɔme egbea le app.mewayz.com — ɖoɖowo dzea egɔme tso $19/ɣleti ko dzi.

Try Mewayz Free

All-in-one platform for CRM, invoicing, projects, HR & more. No credit card required.

Start managing your business smarter today

Join 30,000+ businesses. Free forever plan · No credit card required.

Ready to put this into practice?

Join 30,000+ businesses using Mewayz. Free forever plan — no credit card required.

Start Free Trial →

Ready to take action?

Start your free Mewayz trial today

All-in-one business platform. No credit card required.

Start Free →

14-day free trial · No credit card · Cancel anytime