Infection Channel: Dropped by other malware
This backdoor may be dropped by other malware.
It runs certain commands that it receives remotely from a malicious user. Doing this puts the affected computer and information found on the computer at greater risk.
File size: 104,712 bytes
File type: Mach-O
Memory resident: Yes
Initial samples received date: 21 Mar 2012
Payload: Connects to URLs/IPs
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor drops the following copies of itself into the affected system:
- /Users/{user name}/Library/LaunchAgents/checkvir
Autostart Technique
This backdoor drops the following files:
- /Users/{user name}/Library/LaunchAgents/checkvir.plist
Backdoor Routine
This backdoor executes the following command(s) from a remote malicious user:
- Take a screen shot
- Update the C&C server name
- List the contents of a folder and save it as /tmp/launch-0rp.dat. Then upload the file /tmp/launch-0rp.dat.
- Get the file size of a file
- Download a file from a URL
- Execute a command via the shell
- Delete a file
- Download a file and save it as /tmp/xntaskz.gz. Decompress the downloaded file to /tmp/xntaskz. Execute the following command:
/tmp/CurlUpload -f /tmp/xntaskz
It connects to the following URL(s) to send and receive commands from a remote malicious user:
- http://www.{BLOCKED}sbutters.com/cgi-mac/
Download Routine
This backdoor accesses the following websites to download files:
- http://www.{BLOCKED}sbutters.com/CurlUpload
It saves the files it downloads using the following names:
Connect with us on
| | | |