Infection Channel: Dropped by other malware
This malware arrives as payload of an email campaign that makes use of Pro-Tibetan sentiments. It uses the said subject or content to lure users into opening the email for this malware to be downloaded or executed on the affected user's system.
To get a one-glance comprehensive view of the behavior of this Backdoor, refer to the Threat Diagram shown below.

This backdoor may be dropped by other malware.
It executes commands from a remote malicious user, effectively compromising the affected system. It connects to a website to send and receive information.
File size: 60,100 bytes
File type: Mach-O
Memory resident: Yes
Initial samples received date: 09 Apr 2012
Payload: Compromises system security, Connects to URLs/IPs
Arrival Details
This backdoor may be dropped by the following malware:
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
- Create or delete folders
- Downlad and execute file
- List drives and files
- Manipulate files
- Open an instance of bash shell where a remote malicious user may execute commands
- Search folders
- Upload files to its server
It connects to the following websites to send and receive information:
NOTES:
This malware drops its backdoor component /Library/Audio/Plug-Ins/AudioServer. It creates the property list file /Library/LaunchAgents/com.apple.DockActions.plist in order to execute itself every at system startup.
It reports system infection by sending the following information to its C&C server:
Connect with us on
| | | |