AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.html?storyid=4361
Last Updated: 2008-04-30 09:27:16 UTC - "Back in November last year we published a diary about Mac DNS changer malware*. The main idea about this was to let Mac users aware that the bad guys are not ignoring this platform any more… the way it was packed showed that the attackers meant real business. All the malware did was change local DNS servers to couple of servers in a known bad network, and tell the command and control server that a new victim is ready… Only couple of anti-virus programs detected the original sample (a DMG file). This improved a bit over the time, so when I tested the sample again today on VirusTotal, 10 anti-virus programs detected it… it changes the DNS servers and reports to a C&C server. However, one thing I noticed was that the attackers started obfuscating the installation code… it was enough to fool almost *all* anti-virus programs – according to VirusTotal, this new sample was detected by only 2 (!!) AV programs… same network as before, so make sure that you are monitoring any DNS requests going there since they indicate you have infected machines on your network…"
* http://isc.sans.org/diary.html?storyid=3595
Last Updated: 2007-11-02 02:36:39 UTC …(Version: 2) - "… This is a professional attempt at attacking Mac systems… The second thing that folks at Sunbelt noticed ( http://sunbeltblog.blogspot.com/2007/10/sc…mac-trojan.html ) is that when they sent a sample to VirusTotal there were 0 (zero, nada, nilch) products that detected this…"
(More detail at each URL above)

- http://isc.sans.org/diary.html?storyid=4361
Last Updated: 2008-04-30 09:27:16 UTC - "Back in November last year we published a diary about Mac DNS changer malware*. The main idea about this was to let Mac users aware that the bad guys are not ignoring this platform any more… the way it was packed showed that the attackers meant real business. All the malware did was change local DNS servers to couple of servers in a known bad network, and tell the command and control server that a new victim is ready… Only couple of anti-virus programs detected the original sample (a DMG file). This improved a bit over the time, so when I tested the sample again today on VirusTotal, 10 anti-virus programs detected it… it changes the DNS servers and reports to a C&C server. However, one thing I noticed was that the attackers started obfuscating the installation code… it was enough to fool almost *all* anti-virus programs – according to VirusTotal, this new sample was detected by only 2 (!!) AV programs… same network as before, so make sure that you are monitoring any DNS requests going there since they indicate you have infected machines on your network…"
* http://isc.sans.org/diary.html?storyid=3595
Last Updated: 2007-11-02 02:36:39 UTC …(Version: 2) - "… This is a professional attempt at attacking Mac systems… The second thing that folks at Sunbelt noticed ( http://sunbeltblog.blogspot.com/2007/10/sc…mac-trojan.html ) is that when they sent a sample to VirusTotal there were 0 (zero, nada, nilch) products that detected this…"
(More detail at each URL above)