Author: Sabrina Lei Sioting   

 

Trojan.BAT.Qhost.nh (Kaspersky)

 PLATFORM:

Mac OS

 OVER ALL RISK RATING:
 DAMAGE POTENTIAL::
 DISTRIBUTION POTENTIAL::
 REPORTED INFECTION:
Low
Medium
High
Critical

  • Threat Type:
    Trojan

  • Destructiveness:
    No

  • Encrypted:
    No

  • In the wild::
    Yes

  OVERVIEW


  TECHNICAL DETAILS

File size: 111,317 bytes
File type: Other
Memory resident: No
INITIAL SAMPLES RECEIVED DATE: 09 de сентября de 2011

Instalación

Crea las siguientes copias de sí mismo en el sistema afectado:

  • //Library/Receipts/FlashPlayer.pkg

Este malware infiltra el/los siguiente(s) archivo(s):

  • //Library/Receipts/FlashPlayer.pkg/Contents/Archive.bom
  • //Library/Receipts/FlashPlayer.pkg/Contents/Info.plist
  • //Library/Receipts/FlashPlayer.pkg/Contents/PkgInfo
  • //Library/Receipts/FlashPlayer.pkg/Contents/Resources/en.lproj/background
  • //Library/Receipts/FlashPlayer.pkg/Contents/Resources/en.lproj/Description.plist
  • //Library/Receipts/FlashPlayer.pkg/Contents/Resources/package_version
  • //Library/Receipts/FlashPlayer.pkg/Contents/Resources/preinstall - contains the malicious script
  • //~/bzab.km

Crea las carpetas siguientes:

  • //~/

  SOLUTION

Minimum scan engine: 9.200
First VSAPI Pattern File: 8.416.05
First VSAPI Pattern Release Date: 09 de сентября de 2011
Did this description help? Tell us how we did.