Infection Channel: Dropped by other malware
This malware is the Flashback Mac Trojan Horse that installed by exploiting two certain Java vulnerabilities.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan may be dropped by other malware.
It executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system. As of this writing, the said sites are inaccessible.
It deletes itself after execution.
File size: Varies
File type: Mach-O
Initial samples received date: 24 Feb 2012
Payload: Downloads files
Arrival Details
This Trojan may be dropped by the following malware:
Download Routine
This Trojan accesses the following websites to download files:
- http://{BLOCKED}.{BLOCKED}6.139.211/jcounter/
It saves the files it downloads using the following names:
It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system.
As of this writing, the said sites are inaccessible.
Other Details
This Trojan deletes itself after execution.
NOTES:
It does not perform its download routine if one of the following files or folders are present:
- /Library/Little Snitch
- /Developer/Applications/Xcode.app/Contents/MacOS/Xcode
Connect with us on
| | | |