Author: kathleenno   

 

Trojan-Downloader.OSX.FavDonw.c (Kaspersky); OSX/FakeAV-DWN (Sophos); Trojan-Downloader.OSX.Fav.A (Clamav); Trojan-Downloader.OSX.FavDonw (Ikarus)

 PLATFORM:

Mac OS

 OVER ALL RISK RATING:
 DAMAGE POTENTIAL::
 DISTRIBUTION POTENTIAL::
 REPORTED INFECTION:
Low
Medium
High
Critical

  • Threat Type:
    Trojan

  • Destructiveness:
    No

  • Encrypted:
    No

  • In the wild::
    Yes

  OVERVIEW


  TECHNICAL DETAILS

File size: 71,680 bytes
File type: Other
Memory resident: Yes
INITIAL SAMPLES RECEIVED DATE: 06 de czerwca de 2011
PAYLOAD: Displays fake alerts

Instalación

Infiltra los archivos siguientes:

  • //Application/dShield.app/
  • //Application/dShield.app/Contents
  • //Application/dShield.app/Contents/Info.plist
  • //Application/dShield.app/Contents/MacOS/
  • //Application/dShield.app/Contents/MacOS/dShield
  • //Application/dShield.app/Contents/PkgInfo
  • //Application/dShield.app/Contents/Resources/{resource files}

  SOLUTION

Minimum scan engine: 8.900
First VSAPI Pattern File: 8.206.08
First VSAPI Pattern Release Date: 06 de czerwca de 2011
Did this description help? Tell us how we did.