[FSec] Mac Trojan Disables XProtect Updates

Newsfeed

Nachrichtenbote
There's something new brewing in Mac malware development (again).

Recent analysis has revealed to us that Trojan-Downloader:OSX/Flashback.C disables the automatic updater component of XProtect, Apple's built-in OS X anti-malware application.

First, Flashback.C decrypts the paths of XProtectUpdater files that are hardcoded in its body:

fbc_xprotectupdater_plist.jpg

Flashback.C decrypts the path of the plist file of XProtectUpdater

fbc_xprotectupdater.jpg

Flashback.C decrypts the path of the XProtectUpdater binary

The malware then unloads the XProtectUpdater daemon:

fbc_unload_1.jpg


fbc_unload_2.jpg


Finally, the malware overwrites the XProtectUpdater files with a " " character:

fbc_wipe_xprotectupdater_plist.jpg

Flashback.C overwrites the plist file of XProtectUpdater

fbc_wipe_xprotectupdater.jpg

Flashback.C overwrites the XProtectUpdater binary

The action described above wipes out certain files, thus, preventing XProtect from automatically receiving future updates.

Attempting to disable system defenses is a very common tactic for malware to take mdash; and built-in defenses are naturally going to be the first target on any computing platform.

Threat Solutions post by — Brod
On 19/10/11 At 07:46 AM

Weiterlesen...
 
Zurück
Oben