« Trojan Downloader 3/41 on VT
Fake codec targets Russian users »

New VARIANT of Mac Jahlav Trojan

July 20th, 2009

I found a new Mac Trojan this morning from the following domains:

simplexdoom.com

paxxtiger.com

detailedus.com

Only 3 vendors on VirusTotal are detecting it: F-Secure, Kaspersky and Sophos.

vt7

I am part of the Mac_Exchange list so I will share this one with them as well as our regular partners.

Jerome Segura

Malware ID: f7c4e75ee56bdac710675daa5fd9ed0d.zip

UPDATE:

S!Ri commented on that post, and he makes some fair points:

This not new. DNS.Changer is old.

On Windows system, creators are using Nullsoft installer + stubs. It’s just a shell used to bypass virus control. It’s is why all Antivirus are late. They have to found a new signature each time. Once they have one, it’s too late there is a new domain and the shell have change again…

Try to unpack the Nullsoft packer to get the infection:

http://www.virustotal.com/analisis/1…cfd-1248123897

http://www.threatexpert.com/report.a…2720d8d387b723

MacOS dropper is also using this kind of shell trick. Don’t try to use a hash to identify the infection, some bits are modified on the server. You’ll get a new hash. Virus Total won’t find the hash in the database and will submit it to its scanner test, makes you think the file is new…

    This entry was posted on Monday, July 20th, 2009 at 10:11 am and is filed under Uncategorized. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    2.      by
    • (2) comments
    • |
    • Add your comments




ParetoLogic, a Microsoft Certified Partner

 

RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site
Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • URL Clearing House
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (4)
  • Botnets (3)
  • Conferences (4)
  • DDos (1)
  • Exploits (48)
  • Fake codecs (38)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (2)
  • Mac security (15)
  • Malware Trends (69)
  • Phishing (8)
  • Podcast (1)
  • ransomware (5)
  • Research (46)
  • Rogue software (53)
  • Rootkits (2)
  • scams (9)
  • Social Networking (6)
  • Uncategorized (118)
  • Wireless Security (2)
  • world map (1)



 
 
 
Microsoft is a registered trademark of Microsoft Corporation in the United States and/or other countries.

© 2010 ParetoLogic Inc.