This malicious file disguises itself as an image file in order for users to install and execute its backdoor component.
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Threat Diagram shown below.

This Trojan is disguised as an image file. It arrives as a .ZIP file together with other image files.
Clicking this file executes the malware. It then deletes itself, then drops and opens a real picture file. This is done to trick unsuspecting users into thinking that it is a legitimate file.
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
File size: 39,596 bytes
File type: Mach-O
Initial samples received date: 17 Mar 2012
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
NOTES:
This Trojan is disguised as an image file. It arrives as a .ZIP file together with other image files.
Clicking this file executes the malware. It then deletes itself, then drops and opens a real picture file. This is done to trick unsuspecting users into thinking that it is a legitimate file.
It decrypts its component file {malware path}/.conft to /tmp/.mdworker using the key file {malware path}/.confr. It then executes the dropped file /tmp/.mdworker, which is detected by Trend Micro as OSX_IMULER.C. The key file, {malware path}/.confr, is a .JPG file.
It copies the key file, {malware path}/.confr to {malware path}/TMP0M34JDF8 and /tmp/TMP0M34JDF8.
It drops and executes the file /tmp/launch-IORF98 which opens the image file {malware path}/TMP0M34JDF8, effectively hiding its malicious routines.
It deletes itself after execution.
Connect with us on
| | | |