Infection Channel: Dropped by other malware
This backdoor may be dropped by other malware.
It runs certain commands that it receives remotely from a malicious user. Doing this puts the affected computer and information found on the computer at greater risk. It connects to a website to send and receive information.
File size: 95,828 bytes
File type: Mach-O
Memory resident: Yes
Initial samples received date: 29 Mar 2012
Payload: Compromises system security
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor drops the following copies of itself into the affected system:
Autostart Technique
This backdoor drops the following files:
- /Users/{user name}/Library/LaunchAgents/com.apple.FolderActionsxl.plist
Backdoor Routine
This backdoor executes the following command(s) from a remote malicious user:
- Delete a file
- Terminate a process
- Get operating system version, user name, and machine name
- Get list of processes
- List directory contents
- Send a file to the C&C server
- Receive a file from the C&C server
- Execute a file
- Uninstall itself
- Open a remote shell (/bin/sh)
It connects to the following websites to send and receive information:
- {BLOCKED}bet2012.{BLOCKED}p.net:80
Connect with us on
| | | |