--
F-Secure has posted news about a new Trojan horse for Mac OS X. It is currently being called "BASH/QHost.WB". Using the standard malware naming system, the official name should be Trojan.OSX.BASH/QHost.WB.A. So far I am unaware of why it is being given a 3-part name. Most likely there will be the usual proliferation of other names across the anti-malware community before a final name is established.
F-Secure's report is well documented and worth reading here:
Trojan: BASH/QHost.WB
Why I'm laughing, heehee: Of all the software to fake for Mac OS X, it is HILARIOUS that these malware rats chose the Adobe FlashPlayer installer. Is there any more hated software for Mac OS X than Adobe Flash?! Oops. I don't see this Trojan becoming very proliferated. But there are always victims, so it is worth documenting what this thing does.
So far there is no documentation as to where the Trojan is found. As usual, double-check the source of ALL your software. NEVER install anything you've been sent or randomly picked up off the net without verifying it as legitimate. Obviously, the safest place to pick up the Adobe FlashPlayer software is directly from Adobe. Also keep in mind that Adobe FlashPlayer has historically been found to be profoundly insecure. Be absolutely certain you are installing the most recent version of FlashPlayer and check Adobe at least once a month for security updates.
When installing the fake FlashPlayer.pkg file, it looks like Apple's standard installer, fooling you that it is legitimate.
After installation, Trojan.OSX.BASH/QHost.WB.A takes over your 'hosts' file and damages it to dump your web browsers to a phishing site located in the Netherlands. The malware can easily damage the hosts file for further fake forwarding in the future. (Say that 10 times!). The Mac OS X hosts file is located here:
/private/etc/hosts
You can read about the purpose of the hosts file here:
Hosts (file) @ Wikipedia
The current version hijacks a series of Google web addresses. If you read F-Secure's notes you'll see that there are detectable differences between the real Google pages and the fake phishing pages.
Using the phishing site results in bogus search results. Clicking on the result URLs only returns you back to the phishing site. Meanwhile, however, the bogus site nails your browser with a series of pop-up pages which it grabs from a nefarious remote server.
At this time, the pop-up remote server is not providing any information to the phishing site. Possibly, this is a prototype malware being used either for demonstration purposes or to prove a hacking method to the hacking community. No doubt we will know more about the situation in the near future.
Most likely, Apple will be integrating a signature for Trojan.OSX.BASH/QHost.WB.A into their XProtect anti-malware system in Mac OS X 10.6 and 10.7. At the moment of my posting this article, Apple has not yet updated their XProtect.plist file.
Share and Enjoy!
:-Derek
Total Pageviews
Home
F-Secure
FlashPlayer
Google
hosts file
phishing
pop-up
prototype
Trojan.OSX.BASH/QHost.WB.A
New: Trojan.OSX.BASH/QHost.WB.A, Posing as FlashPlayer.pkg Installer (heehee!)
New: Trojan.OSX.BASH/QHost.WB.A, Posing as FlashPlayer.pkg Installer (heehee!)
Unknown
19:37
Subscribe to:
Post Comments (Atom)
Follow us on facebook
Popular Posts
-
This is very easy and simple method to trace phone number not only at India its at worldwide. This is possible due to service and applicatio...
-
What is BackTrack 5 Backtrack is a very popular linux distribution for penetration testing. It has hundreds of tools for pentesting and ha...
-
When creating a Facebook account, the system automatically assigns the user an identification number, known as the Facebook ID. Facebook al...
-
This is Opera Mini Hanler v7.5 which is released for Android OS . With this hacked version, you can browse Internet for free with Airtel,Air...
-
Media player without installation. Download Portable Winamp Full (14.5 MB) Download Portable Winamp Lite (8.1 MB) Extract and run Winamp...
-
You must have enjoyed YouTube videos on the official YouTube app on your Android device, but the downside with the app is slow buffering and...
-
Ipadian iOS emulators for Windows allow you to run your favorite iOS apps on your Windows computer. Isn't cool to have your iPad apps ru...
-
Professional photographer's essential toolbox without installation. English, German, Spanish, French, Italian, Japanese, Korean, Dutch,...
-
Viber Free Calls Viber Free Call and Text Messanging Service With Viber you can Create free call with other viber user.No more Balance cuts ...
-
Facebook is our Social Life . Everybody want backup of your life so its not possible but backup of your FB Social Life is Possible. There a...
No comments:
Post a Comment