x404.co.uk
http://x404.co.uk/forum/

New OS X DNS changer
http://x404.co.uk/forum/viewtopic.php?f=19&t=2255
Page 1 of 1

Author:  ProfessorF [ Wed Aug 12, 2009 9:54 pm ]
Post subject:  New OS X DNS changer

Another threat relying on the ol' 'Check-The-Box-To-Install-Malware' vector:

Quote:
TrendMicro is reporting on a newly discovered 4th member of the OSX_JAHLAV malware family.

The latest variant is once again relying on social engineering, this time spreading under a QuickTime Player update (QuickTimeUpdate.dmg) with a DNS changer component enabling the malware authors to redirect and monitor the traffic of the victim.

More info on OSX_JAHLAV.D:
The Trojan contains component files detected as UNIX_JAHLAV.D and obfuscated scripts detected as PERL_JAHLAV.F. The Perl script then downloads a file from a malicious site and stores it as /tmp/{random 3 numbers}, detected as UNIX_DNSCHAN.AA, which allows a malicious user to monitor the affected user’s activities. This may also cause the user to be redirected to phishing sites or sites where other malware may be downloaded from.



Source

Author:  jonbwfc [ Thu Aug 13, 2009 1:47 pm ]
Post subject:  Re: New OS X DNS changer

So you'd have to download an update to quicktime via some method other than software update to get this? Why do that?

Unless of course you thought you were getting quicktime pro without having to pay for it....

Jon

Author:  bobbdobbs [ Thu Aug 13, 2009 2:21 pm ]
Post subject:  Re: New OS X DNS changer

jonbwfc wrote:
So you'd have to download an update to quicktime via some method other than software update to get this? Why do that?


because mr or mrs or ms or esquire etc average doesnt think that everything is dangerous and all too often will just click OK.

Author:  gavomatic57 [ Thu Aug 13, 2009 3:15 pm ]
Post subject:  Re: New OS X DNS changer

jonbwfc wrote:
So you'd have to download an update to quicktime via some method other than software update to get this? Why do that?

Unless of course you thought you were getting quicktime pro without having to pay for it....

Jon


I'm no expert on this, but it may also catch the hackintoshers who can't get software update to work!

Author:  saspro [ Thu Aug 13, 2009 3:33 pm ]
Post subject:  Re: New OS X DNS changer

It's hidden inside some pirate software.

Author:  themcman1 [ Fri Aug 14, 2009 8:15 pm ]
Post subject:  Re: New OS X DNS changer

People will install it because you can't get a virus on a Mac. Ever.

Page 1 of 1 All times are UTC
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/