Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

OSX_DNSCHAN.A

BugsAlert Home > OSX_DNSCHAN.A
 
 

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

OSX_DNSCHAN.A Behavior Diagram

This Trojan can be downloaded from http://{BLOCKED}odec.com/download/ultracodec{number}.dmg.

It arrives on the affected system as a DMG file. A DMG file is a mountable disk image created in Mac OS X commonly used for software installers downloaded from the Internet.

It tricks the user into thinking that a legitimate video codec program is being installed. It even includes an End User License Agreement (EULA) to complete its scam.

Upon completion of its installation routine, this Trojan drops a malicious Bash script files detected by Trend Micro as UNIX_DNSCHAN.A.

Two versions of this malware exists (Windows and Mac OS version). One of the two versions can be downloaded on the same remote site depending on the browser and operating system used.

When using a Windows platform to connect to the malicious Web site, the downloaded file also uses a .DMG extension. However, examining its contents would show that it is an EXE file.




Original Source: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=OSX_DNSCHAN.A

Learn more about OSX_DNSCHAN.A
 
Tags: osx dnschan.a

Related Items

      CVE-2007-6578 (PHP_ZLink)

      CVE-2008-3516 (presenter)

      JS_AGENT.CVL

      CVE-2008-4446 (nucleus)

      CVE-2008-3687 (Xen, xen_flask_module)

      CVE-2008-3744 (Drupal)

      CVE-2008-1372 (bzip2)

 

Pixel