OSX_SABPAB.A
OSX.Sabpab (Symantec); OSX/Sabpab-A (Sophos)
Mac OS X

Threat Type: Backdoor
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
Dropped by other malware
This backdoor may be dropped by other malware.
It executes commands from a remote malicious user, effectively compromising the affected system. It connects to a website to send and receive information.
TECHNICAL DETAILS
42,556 bytes
Mach-O
Yes
16 Apr 2012
Compromises system security
Arrival Details
This backdoor may be dropped by the following malware:
- TROJ_MDROP.SBPAB
Installation
This backdoor drops the following files:
- /Library/Preferences/com.apple.PubSabAgent.pfile - backdoor component
- /Library/LaunchAgents/com.apple.PubSabAgent.plist - autostart component
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
- Create processes
- Download and execute file(s)
- Capture screenshot(s)
- Upload file(s) to a remote server
It connects to the following websites to send and receive information:
- rtx556.{BLOCKED}b.com
SOLUTION
9.200
8.916.03
16 Apr 2012
8.917.00
16 Apr 2012
Step 1
Remove malware/grayware files that dropped/downloaded OSX_SABPAB.A
NOTES:
Step 2
Delete the autostart file used by this malware. To delete the autostart file, open a Terminal window and type the following command:
"rm "/Library/LaunchAgents/com.apple.PubSabAgent.plist"
Step 3
Terminate the malware process. To terminate the malware process, open a Terminal window and perform the following:
- Enter the following command:
ps -A
- In the Terminal window, search for a line similar to the following:
{number} ?? Ss {time} /Library/Preferences/com.apple.PubSabAgent.pfile
Take note of the number. This number is the malware process ID (PID) - Enter the following command:
kill {malware PID}
Step 4
Scan your computer with your Trend Micro product to delete files detected as OSX_SABPAB.A. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
To open a Terminal window, double-click Applications > Utilities > Terminal in Finder.
Close Terminal by pressing ⌘ (Command) + Q.
Did this description help? Tell us how we did.