PUA.MacOS.Macmaster.C

 Analysis by: Clive Fuentebella

 ALIASES:

a variant of OSX/MacMaster.D potentially unwanted application (NOD32)

 PLATFORM:

Mac

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Potentially Unwanted Application

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File Size:

2,524,368 bytes

File Type:

Mach-O

Memory Resident:

No

Initial Samples Received Date:

07 Dec 2020

Arrival Details

This Potentially Unwanted Application arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Other Details

This Potentially Unwanted Application does the following:

  • This file is packaged in the PKG installer file.
  • On installation, it is installed on the system at the following path:
    • /Applications/MacMaster.app/Contents/MacOS/MacMaster
  • It sends installation data at the following link after installation:
    • https://parse.dumpmedia.com/parse/classes/McrEvent