« Fake porn code generator
The Mac Trail to 213.182.197 »

More Mac malware

June 18th, 2009

UPDATE:

Totally undetected variant found:

dmg06

From the following site:

dmg05

The Windows version is detected, but not by many vendors:

dmg07

——————————–

As I was browsing different crack sites with a spoofed user agent (Safari) I came across another Jahlav OSX Trojan:

dmg01

See the extension at the bottom of the previous snapshot is for an “.exe” but when I click on the link it converts it into a “.dmg”

dmg02

Very few vendors are detecting this variant:

dmg03

I did some background check on the original crack site. All bad stuff!

IP: 213.182.197.8

IP Country:   Latvia

This IP address resolves to mxs.newhostgroup.ru

34 Hosts on this IP

Number Domain / Host Functions

1. prowarezsite.com

2. prolinesoft.com

3. studiaweb.com

4. inspirationsbymicco.com

5. prosserpianoca.com

6. seexxxfree.info

7. djstevyvee.com

8. topsecretwarez.com

9. therogueelement.net

10. uniquexsoftware.com

11. yourcrackkey.com

12. premieracs.com

13. yoursoftonline.com

14. unix-service.com

15. 2008bloggger.com

16. lyutsifer.ru

17. vipwarezz.com

18. arws.org

19. prava-center.ru

20. zoosexvideo.net

21. kostenlosie.net

22. giveprava.ru

23. dwlsoft.com

24. paysitesmag.com

25. watch-video.info

26. sihuirading.com

27. warezfans.com

28. hacker-pro.net

29. index938.com

30. www.arws.org

31. appz-blog.com

32. klasoft.com

33. warezter.com

34. www.sihuirading.com

More fake codecs from faretransy.com:

dmg04

I will keep monitoring those links and pass on the information to other security folks.

Those links are dangerous, so proceed with caution.

Jerome Segura

    This entry was posted on Thursday, June 18th, 2009 at 10:39 am and is filed under Uncategorized. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (104)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.