Author: Clive Fuentebella   

 

a variant of OSX/MacMaster.D potentially unwanted application (NOD32)

 PLATFORM:

Mac

 OVER ALL RISK RATING:
 DAMAGE POTENTIAL::
 DISTRIBUTION POTENTIAL::
 REPORTED INFECTION:
 INFORMATION EXPOSURE:
Low
Medium
High
Critical

  • Threat Type:
    Potentially Unwanted Application

  • Destructiveness:
    No

  • Encrypted:
    No

  • In the wild::
    Yes

  OVERVIEW

It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File size: 2,524,368 bytes
File type: Mach-O
Memory resident: No
INITIAL SAMPLES RECEIVED DATE: 07 grudnia 2020

Detalles de entrada

It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Otros detalles

Hace lo siguiente:

  • This file is packaged in the PKG installer file.
  • On installation, it is installed on the system at the following path:
    • /Applications/MacMaster.app/Contents/MacOS/MacMaster
  • It sends installation data at the following link after installation:
    • https://parse.dumpmedia.com/parse/classes/McrEvent