Hacker News

7zip.com Yana Bada Malware

7zip.com Yana Bada Malware Wannan cikakken bincike na 7zip yana ba da cikakken bincike na ainihin abubuwan da ke tattare da shi da kuma fa'ida. Mahimman wuraren Mayar da hankali Tattaunawar ta ta'allaka ne akan: Tsarin mahimmanci da matakai ...

9 min read Via www.malwarebytes.com

Mewayz Team

Editorial Team

Hacker News

7zip.com yana ba da malware sosai ga masu amfani da ba su ji ba waɗanda suka yi kuskuren rubuta halal ɗin 7-Zip zazzage URL. Idan kai ko wani a cikin ƙungiyar ku kwanan nan ya ziyarci 7zip.com yana neman mashahurin kayan aiki na matsa fayil, na'urorin ku na iya lalacewa kuma ana buƙatar daukar matakin gaggawa.

Mene Ainihi Ke Faruwa a 7zip.com?

Halatta software ta 7-Zip - ɗaya daga cikin kayan aikin buɗe tushen fayil ɗin da aka fi amfani da shi a duniya - ana rarraba su bisa hukuma ta 7-zip.org, ba 7zip.com ba. Masu binciken tsaro na intanet sun tabbatar da cewa 7zip.com yanki ne na buga rubutu, wani rukunin yanar gizo mara kyau da aka tsara don kama masu amfani da ke sauke saƙar yayin buga ainihin URL.

Lokacin da baƙi suka sauka akan 7zip.com, ana gabatar da su tare da kwafi mai gamsarwa na halaltaccen gidan yanar gizon 7-Zip. Shafin yana kwaikwayi shimfidar wuri na asali, alamar alama, da maɓallin zazzagewa tare da daidaito mai ban tsoro. Duk da haka, fayilolin da ake rarrabawa daga wannan yanki ba ainihin mai sakawa na 7-Zip ba ne - an haɗa su tare da kayan aikin malware wanda ya haɗa da masu satar bayanai, trojans masu nisa (RATs), da software na girbi.

Harin yana da haɗari musamman saboda yana cin amanar mai amfani ga sanannen, sanannen alamar software. Yawancin masu amfani ba za su sami dalilin bincika URL ɗin a hankali ba yayin zazzage software da suka yi amfani da shi lafiya tsawon shekaru.

Yaya Wannan Harin Malware Yayi Aiki?

Tsarin fasaha da ke bayan harin 7zip.com yana biye da ingantaccen littafin wasan buga rubutu, amma tare da ƙwararrun yadudduka da yawa waɗanda ke sa ya yi tasiri musamman:

  1. Rijistan yanki: Mahara sun yi rajistar 7zip.com - kuskuren gama gari na halaltacciyar 7-zip.org - kuma suna gina madaidaicin clone na ainihin rukunin yanar gizon.
  2. Sakamakon SEO: An inganta yankin malicious don matsayi a cikin sakamakon bincike don tambayoyi kamar "zazzagewa 7zip" ko "zazzagewar 7zip kyauta," haɓaka zirga-zirgar kwayoyin halitta daga injunan bincike.
  3. Bayar da mai sakawa: Danna kowane maɓallin zazzagewa a rukunin yanar gizon yana ba da aikin aiwatarwa wanda ya ƙunshi duka ainihin mai sakawa 7-Zip (don guje wa zato) da ɓoyayyun abubuwan malware.
  4. Kisa ba tare da izini ba: Da zarar an gudu, malware yana kafa dagewa akan tsarin, galibi yana aiwatar da tsarin baya wanda ke fitar da adana kalmomin shiga, kukis mai bincike, bayanan walat na cryptocurrency, da takaddun shaida na kamfani.
  5. Sadarwar Umurni da Sarrafa: Wayoyin malware suna zuwa gida ga sabar masu sarrafa maharan, suna ba da damar shiga nesa zuwa injinan kamuwa da cuta tun bayan sasantawar farko.

Wannan tsarin matakai da yawa yana nufin cewa hatta masu amfani da suka lura da wani abu da ba a saba gani ba bayan shigarwa na iya zama rashin sanin cewa an riga an kafa kofa a tsarin su.

Wanene Yafi Haɗari Daga Yaƙin Malware na 7zip.com?

Duk da yake kowane mai amfani yana cikin haɗari, barazanar ta fi girma ga kasuwanci da ƙungiyoyi. Masu gudanar da tsarin, masu haɓakawa, da ƙwararrun IT akai-akai suna zazzage kayan aiki kamar 7-Zip akan injunan aiki, sabobin, da mahalli masu raba. Ƙarshen ƙarshen kamuwa da cuta guda ɗaya a cikin hanyar sadarwar kamfani na iya zama bakin teku don motsi ta gefe, aika kayan fansa, ko haɓaka bayanan da ke shafar ƙungiyar gaba ɗaya.

"Hare-haren da ake kai wa amintattun wuraren software suna wakiltar ɗaya daga cikin mafi girman barazanar da ba a iya ƙima ba a cikin tsaron kasuwancin. URL ɗin da ba daidai ba zai iya lalata dukkan hanyar sadarwar ƙungiyar cikin sa'o'i."

Kananan sana'o'i da masu farawa suna da rauni musamman saboda galibi basu da ƙwararrun ƙungiyoyin tsaro don sa ido kan alamun sasantawa. Masu zaman kansu, ma'aikata masu nisa, da duk wanda ke sarrafa kayan aiki da yawa a cikin injuna da yawa - daidai da nau'ikan masu amfani da aka mayar da hankali kan yawan aiki waɗanda ke dogaro da kayan aiki kamar 7-Zip kullum - suna fuskantar haɓakar fallasa.

💡 DID YOU KNOW?

Mewayz replaces 8+ business tools in one platform

CRM · Invoicing · HR · Projects · Booking · eCommerce · POS · Analytics. Free forever plan available.

Start Free →

Ta Yaya Zaku Iya Kare Kasuwancin Ku Daga Bugawa Malware?

Kariya daga hare-hare kamar yaƙin neman zaɓe na 7zip.com yana buƙatar haɗakar sarrafa fasaha da wayar da kan ɗan adam. Matakan da ke gaba suna rage tasirin ƙungiyar ku sosai:

  • Koyaushe tabbatar da URLs kafin zazzage software. Alamar tushe na hukuma. Ainihin 7-Zip yana keɓancewar a 7-zip.org.
  • Yi amfani da hanyoyin tacewa na DNSwanda ke toshe sanannun wuraren ƙeta a matakin cibiyar sadarwa kafin masu amfani su iya loda shafin.
  • Kwantar da kayan aikin gano ƙarshen wuri da amsa (EDR) waɗanda za su iya nuna sabon yanayin tsari wanda masu sakawa trojanized suka jawo.
  • Gudanar da horar da wayar da kai kan tsarodon haka kowane memba na kungiya ya fahimci hadarin buga rubutu kuma ya san yadda ake tantance hanyoyin saukewa.
  • Audit kwanan nan an shigar da software a duk wuraren ƙarshe. Idan wani a cikin ƙungiyar ku mai yiwuwa ya ziyarci 7zip.com, ɗauki waɗannan injinan a matsayin mai yuwuwar yin sulhu kuma fara hanyoyin mayar da martani nan da nan.
Bayan matakan mayar da martani, gina al'adar tsaro-tunani na farko a cikin ƙungiyar ku shine mafi tsayin tsaro daga aikin injiniyan zamantakewa da hare-hare na yanki.

Me Ya Kamata Ka Yi Idan Ka Ziyarci 7zip.com?

Idan kuna zargin kun zazzage software daga 7zip.com, yi aiki nan take. Cire haɗin injin da abin ya shafa daga hanyar sadarwar ku don hana yaɗuwar gefe. Gudanar da cikakken bincike ta amfani da ingantaccen riga-kafi da kayan aikin anti-malware. Canja duk kalmomin shiga da aka adana a cikin masu bincike akan na'urar da abin ya shafa - ba da fifikon banki, imel, da asusun kasuwanci. Yi bitar bayanan da aka adana na mazuruftar ku kuma ba da damar tantance abubuwa da yawa akan duk mahimman asusu. Bayar da rahoton abin da ya faru ga IT ko ƙungiyar tsaro kuma la'akari da shiga ƙwararrun sabis na amsa abin da ya faru idan ƙila an sami isa ga bayanan kasuwanci masu mahimmanci.

Kada ku ɗauka cewa cire fayil ɗin da aka sauke yana warware matsalar. Yawancin kayan aikin malware suna kafa hanyoyin dagewa waɗanda ke tsira daga cire software har ma da sake kunna tsarin.

Tambayoyin da ake yawan yi

Shin 7-Zip kanta shiri ne mai haɗari?

A'a. Halaltaccen software na 7-Zip, wanda ake samu daga 7-zip.org, amintaccen rumbun adana fayil ne mai buɗewa tare da dogon tarihin amintaccen amfani. Haɗarin ya ta'allaka ne gaba ɗaya tare da rukunin yanar gizo na jabu a 7zip.com, wanda ke rarraba nau'ikan mai sakawa na jabu tare da malware. Koyaushe zazzage 7-Zip na musamman daga yankin da aka saurara: 7-zip.org.

Ta yaya zan san idan malware daga 7zip.com yana aiki akan tsarina?

Alamomin gama gari sun haɗa da sabon CPU ko ayyukan cibiyar sadarwa, sabbin hanyoyin da ba a sani ba da ke gudana a cikin Task Manager, raguwar bincike, kulle asusun ba zato, ko faɗakarwa daga software na riga-kafi. Koyaya, yawancin masu satar bayanai na zamani suna aiki shiru. Idan kun zazzage daga 7zip.com, ku bi na'urar kamar yadda aka daidaita ba tare da la'akari da alamun da ake iya gani ba kuma kuyi cikakken binciken bincike.

Shin amfani da dandalin sarrafa kasuwanci na iya taimakawa wajen rage irin wannan haɗarin tsaro?

Iya. Tsakanin dandamalin kasuwanci na kasuwanci waɗanda ke sarrafa siyan software, ikon samun damar ma'aikata, da daidaita ayyukan aiki suna rage yuwuwar ma'aikata samun kayan aikin daga rukunin yanar gizo na ɓangare na uku da ba a tantance su ba. Lokacin da zazzagewar software da yarda suke ƙarƙashin tsarin tsakiya tare da ginanniyar tsare-tsaren tsaro, yanayin harin don kamfen buga rubutu yana raguwa sosai.


Kare kasuwancin ku daga barazanar kamar yaƙin neman zaɓe na 7zip.com malware yana buƙatar kayan aikin da suka dace, ingantaccen horo, da ingantaccen tushe na aiki. Mewayz yana ba ƙungiyar ku haɗin kai, amintaccen tsarin aiki na kasuwanci - 207 hadedde kayayyaki waɗanda ke rufe komai daga gudanarwar ƙungiya zuwa sarrafa kansa na aiki - don haka kuna ciyar da ƙarancin lokaci don daidaita rashin ƙarfi da ƙarin gina lokaci. Sama da masu amfani da 138,000 sun amince da Mewayz don gudanar da ayyukansu cikin inganci da tsaro.

Fara tafiya Mewayz yau a app.mewayz.com — shirye-shiryen suna farawa daga $19 kawai a wata.

Try Mewayz Free

All-in-one platform for CRM, invoicing, projects, HR & more. No credit card required.

Start managing your business smarter today

Join 30,000+ businesses. Free forever plan · No credit card required.

Ready to put this into practice?

Join 30,000+ businesses using Mewayz. Free forever plan — no credit card required.

Start Free Trial →

Ready to take action?

Start your free Mewayz trial today

All-in-one business platform. No credit card required.

Start Free →

14-day free trial · No credit card · Cancel anytime