Analysé par: Sabrina Lei Sioting   

 

Trojan.BAT.Qhost.nh (Kaspersky)

 Plate-forme:

Mac OS

 Overall Risk:
 Dommages potentiels: :
 Distribution potentielle: :
 reportedInfection:
Faible
Medium
Élevé
Critique

  • Type de grayware:
    Trojan

  • Destructif:
    Non

  • Chiffrement:
    Non

  • In the wild::
    Oui

  Overview


  Détails techniques

File size: 111,317 bytes
File type: Other
Memory resident: Non
Date de réception des premiers échantillons: 09 septembre 2011

Installation

Schleust die folgenden Eigenkopien in das betroffene System ein:

  • //Library/Receipts/FlashPlayer.pkg

Schleust folgende Komponentendateien ein:

  • //Library/Receipts/FlashPlayer.pkg/Contents/Archive.bom
  • //Library/Receipts/FlashPlayer.pkg/Contents/Info.plist
  • //Library/Receipts/FlashPlayer.pkg/Contents/PkgInfo
  • //Library/Receipts/FlashPlayer.pkg/Contents/Resources/en.lproj/background
  • //Library/Receipts/FlashPlayer.pkg/Contents/Resources/en.lproj/Description.plist
  • //Library/Receipts/FlashPlayer.pkg/Contents/Resources/package_version
  • //Library/Receipts/FlashPlayer.pkg/Contents/Resources/preinstall - contains the malicious script
  • //~/bzab.km

Erstellt die folgenden Ordner:

  • //~/

  Solutions

Moteur de scan minimum: 9.200
First VSAPI Pattern File: 8.416.05
First VSAPI Pattern Release Date: 09 septembre 2011
Participez à notre enquête!