This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Mac DNS changer malware

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.html?storyid=4361
Last Updated: 2008-04-30 09:27:16 UTC - "Back in November last year we published a diary about Mac DNS changer malware*. The main idea about this was to let Mac users aware that the bad guys are not ignoring this platform any more… the way it was packed showed that the attackers meant real business. All the malware did was change local DNS servers to couple of servers in a known bad network, and tell the command and control server that a new victim is ready… Only couple of anti-virus programs detected the original sample (a DMG file). This improved a bit over the time, so when I tested the sample again today on VirusTotal, 10 anti-virus programs detected it… it changes the DNS servers and reports to a C&C server. However, one thing I noticed was that the attackers started obfuscating the installation code… it was enough to fool almost *all* anti-virus programs – according to VirusTotal, this new sample was detected by only 2 (!!) AV programs… same network as before, so make sure that you are monitoring any DNS requests going there since they indicate you have infected machines on your network…"
* http://isc.sans.org/diary.html?storyid=3595
Last Updated: 2007-11-02 02:36:39 UTC …(Version: 2) - "… This is a professional attempt at attacking Mac systems… The second thing that folks at Sunbelt noticed ( http://sunbeltblog.blogspot.com/2007/10/sc…mac-trojan.html ) is that when they sent a sample to VirusTotal there were 0 (zero, nada, nilch) products that detected this…"

(More detail at each URL above)

:ph34r:
Update…

Windows-malware already exists in some ZLOB variants (fake codecs) that will attempt the DNS client hijack - one reference:
- http://ca.com/us/securityadvisor/pest/pest.aspx?id=453119651
Latest DAT Release 03 13 2008 - "This fake codec is actually a hijacker that will change your DNS settings whether you acquire your IP settings through DHCP or set your IP information manually. This hijacker will attempt to re-route all your DNS queries through 85.255.x.29 or 85.255.x.121 (RBN)…. rogue DNS servers…"

-or- SpybotS&D
- http://www.safer-networking.org/en/updateh…2007-02-02.html
Win32.DNSChanger
- http://www.safer-networking.org/en/updateh…2007-03-14.html
Zlob.DNSChanger

:ph34r: