OSX.Sabpab (Symantec); OSX/Sabpab-A (Sophos)
Mac OS X
Dropped by other malware
This backdoor may be dropped by other malware.
It executes commands from a remote malicious user, effectively compromising the affected system. It connects to a website to send and receive information.
42,556 bytes
Mach-O
Yes
16 Apr 2012
Compromises system security
Arrival Details
This backdoor may be dropped by the following malware:
Installation
This backdoor drops the following files:
Backdoor Routine
This backdoor executes the following commands from a remote malicious user:
It connects to the following websites to send and receive information:
9.200
8.916.03
16 Apr 2012
8.917.00
16 Apr 2012
Step 1
Remove malware/grayware files that dropped/downloaded OSX_SABPAB.A
NOTES:
Step 2
Delete the autostart file used by this malware. To delete the autostart file, open a Terminal window and type the following command:
"rm "/Library/LaunchAgents/com.apple.PubSabAgent.plist"
Step 3
Terminate the malware process. To terminate the malware process, open a Terminal window and perform the following:
ps -A
{number} ?? Ss {time} /Library/Preferences/com.apple.PubSabAgent.pfile
Take note of the number. This number is the malware process ID (PID)kill {malware PID}
Step 4
Scan your computer with your Trend Micro product to delete files detected as OSX_SABPAB.A. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
To open a Terminal window, double-click Applications > Utilities > Terminal in Finder.
Close Terminal by pressing ⌘ (Command) + Q.