Linc Davis

Q: MacDefender trojan

I've been following the discussions of this subject, but I have yet to succeed in downloading the trojan or in figuring out how it manages to get installed. I'd appreciate it if someone could send me a direct link. Please don't post the link here or anywhere else on this site. Send it to

 

macdefendertrojan@mailinator.net

 

and reply to this thread so I know It's there. Mailinator is a webmail server that automatically creates a throwaway account when it receives mail for any address in the domain. The received messages are automatically deleted after a few hours, so I need to know when to look. I also need the message subject so I can distinguish it from spam. Anyone can access the message. If you do, please use caution.

 

Instructions on what to Google haven't helped me. My setup is quite locked down and I block a lot of otherwise unwanted content. I need a direct URL.

 

If I get a positive response, I'll try to analyse the trojan in more detail than I've seen here, and post the results in this topic. Thanks.

Mac OS X (10.6.7)

Posted on May 1, 2011 6:36 PM

Close

Q: MacDefender trojan

  • All replies
  • Helpful answers

first Previous Page 5 of 10 last Next
  • by jayv.,

    jayv. jayv. May 9, 2011 12:52 PM in response to ds store
    Level 4 (1,290 points)
    May 9, 2011 12:52 PM in response to ds store

    I have been through all of them and have not found anything that worked. Got a link to the specific post you are referring to?

  • by thomas_r.,

    thomas_r. thomas_r. May 9, 2011 12:58 PM in response to ds store
    Level 7 (30,924 points)
    Mac OS X
    May 9, 2011 12:58 PM in response to ds store

    It's not working anymore.  This malware has gotten to be much harder to find...  I was stumbling across it every few minutes on Google Images a couple days ago.  Now I can't find a single working link.  I'm not sure why that might be, but it's a very good thing, IMO.

  • by jayv.,

    jayv. jayv. May 9, 2011 1:11 PM in response to thomas_r.
    Level 4 (1,290 points)
    May 9, 2011 1:11 PM in response to thomas_r.

    I'm not sure why that might be, but it's a very good thing, IMO.

    I agree, unless they are rebuilding/renaming it again then we might see it back in another form.

    Hopefully people got a bit wiser now as to just clicking everything without thinking.

     

    If you happen to come across it please keep me in mind, mailmethebug@mailinator.com

  • by ds store,

    ds store ds store May 9, 2011 1:01 PM in response to jayv.
    Level 7 (30,395 points)
    May 9, 2011 1:01 PM in response to jayv.

    Pr0digy V. wrote:

     

    I have been through all of them and have not found anything that worked. Got a link to the specific post you are referring to?

     

    Hit the MacRumors forums, the script kiddies there would be glad to email you a altered copy.

  • by WZZZ,

    WZZZ WZZZ May 9, 2011 1:03 PM in response to jayv.
    Level 6 (13,112 points)
    Mac OS X
    May 9, 2011 1:03 PM in response to jayv.

    You really want to leave that email address out in the open like that?

  • by jayv.,

    jayv. jayv. May 9, 2011 1:06 PM in response to WZZZ
    Level 4 (1,290 points)
    May 9, 2011 1:06 PM in response to WZZZ

    Edited the post right as you commented

    There should be a 1:1 messaging feature in this forum!

    (maybe there is now and i have yet to find it, not too familiar with the new design and layout yet)

  • by WZZZ,

    WZZZ WZZZ May 9, 2011 1:11 PM in response to jayv.
    Level 6 (13,112 points)
    Mac OS X
    May 9, 2011 1:11 PM in response to jayv.

    use Mailinator

     

    http://www.mailinator.com/

     

    There is no PM here. If you're going to put up your address, which I don't recommend, at least don't put it up in link form so it can be picked up by a bot. e.g. uty at blah blah. com

  • by jayv.,

    jayv. jayv. May 9, 2011 1:11 PM in response to WZZZ
    Level 4 (1,290 points)
    May 9, 2011 1:11 PM in response to WZZZ

    Thanks for the tip, not sure how the site works exactly but created an address and put it up in the earlier post.

  • by Linc Davis,

    Linc Davis Linc Davis May 9, 2011 1:12 PM in response to jayv.
    Level 10 (207,995 points)
    Applications
    May 9, 2011 1:12 PM in response to jayv.

    I don't have a currently working link to the trojan.

  • by Moof666,

    Moof666 Moof666 May 15, 2011 5:27 AM in response to Linc Davis
    Level 1 (89 points)
    Wireless
    May 15, 2011 5:27 AM in response to Linc Davis

    I wouldn't think everyone who wants a copy of this Trojan is doing a benign research project. A few copy-cats are looking for this, too.

     

    ds store:

    You don't need Text Wrangler, or Terminal as some have suggested, to edit hosts:

    Click the "Go" menu and choose "Go to folder".

    Type: /etc

    Click "Go"

    View as columns. Find "hosts" in the right column. Drag it it the desktop to copy it. Open the copy with TextEdit. Between "127.0.0.1 localhost" and " 255.255.255.255 broadcasthost", make a new line and type "127.0.0.1 bad.ad.site.com". After editing, the text should look something like this:

     

    ##

       1. Host Database

    #

       1. localhost is used to configure the loopback interface

       2. when the system is booting. Do not change this entry.

    ##

    127.0.0.1 localhost

    127.0.0.1 bad.ad.site.com

    255.255.255.255 broadcasthost

    ::1 localhost

     

    Save the hosts file. Drag it back to the same "/etc" window to replace the original hosts file. Click the "Authenticate" button in the message. Type your admin password. Agree to replace the original. Restart.

    You shouldn't remove the "127.0.0.1 localhost" line either. All block site lines should reflect the same IP as localhost (127.0.0.1). Keep it simple.

     

    As for NoScript, the "log in" link for this discussion site uses a redirect now (from discussions.apple.com to daw.apple.com). NoScript blocks this very discussion until you make an allowance.

     

    As "The Hatter" mentions (I think; he's over my head in his lingo), some apps cannot be turned off by Activity Monitor. Shouldn't the developer of Mac Defender be studying ways to make it stick better (reload itself like TechTool Pro)? Then we can't turn it off in Activity Monitor. Safe Boot should still nix it.

     

    Now for my question:

    Why does Mac Defender ask for a password? Couldn't it simply install by letting the user click the "Install" button? If I were a crook, I wouldn't want to make it any more difficult than necessary to get the credit card info... unless... maybe something much more insidious is afoot. This guy may have additional hacks at hand involving stollen passwords, so why is no one suggesting that part of the process of recovering from Mac Defender include changing the admin password?

     

    EDIT: OMG, Apple has added an edit button! Will wonders never cease? And I thought they weren't listening when I griped about Keynote not letting me set a song to play for exactly X number of slides like PowerPoint has done for so many years. I'll be looking for that Keynote update any day now.

  • by thomas_r.,

    thomas_r. thomas_r. May 15, 2011 5:30 AM in response to Moof666
    Level 7 (30,924 points)
    Mac OS X
    May 15, 2011 5:30 AM in response to Moof666

    Now for my question:

    Why does Mac Defender ask for a password?

     

    It doesn't.  There's been a lot of FUD about MacDefender authenticating to root, but it never does.  The Apple installer, used to open and install the components in the .mpkg file the malware is packaged in, requests your admin password so the app can be moved into the Applications folder.   The trojan never gets that kind of access.

  • by Linc Davis,

    Linc Davis Linc Davis May 15, 2011 5:53 AM in response to Moof666
    Level 10 (207,995 points)
    Applications
    May 15, 2011 5:53 AM in response to Moof666

    Why does Mac Defender ask for a password?

     

    It doesn't. The Installer asks for a password.

     

    Couldn't it simply install by letting the user click the "Install" button?

     

    In the form I saw, yes, if the user was a member of the admin group.

     

    This guy may have additional hacks at hand involving stollen passwords, so why is no one suggesting that part of the process of recovering from Mac Defender include changing the admin password?

     

    Because the trojan itself doesn't ask for the password. Everything the Installer does is determined by scripts and is therefore transparent. I looked at those scripts very carefully. They don't steal the password.

     

    The SEO attack on Google is quite sophisticated. The trojan itself is very unsophisticated. It could do a lot of things it doesn't do, either because the dude doesn't know how or because he isn't motivated. He just wants to make a quick score. Of course that may change in the future, or may already have changed.

  • by WZZZ,

    WZZZ WZZZ May 15, 2011 6:46 AM in response to Moof666
    Level 6 (13,112 points)
    Mac OS X
    May 15, 2011 6:46 AM in response to Moof666
    Moof666 wrote: As for NoScript, the "log in" link for this discussion site uses a redirect now (from discussions.apple.com to daw.apple.com). NoScript blocks this very discussion until you make an allowance.

    This really isn't on topic, but I'm not seeing this with NoScript. The log in page is using daw.apple.com. Once log in is completed, there is a redirect to discussions.apple.com. Either Firefox, itself, with a preference setting, or the RefreshBlocker Add-on will block this redirect, but I'm not seeing NoScript getting involved at all. I have apple.com permanently whitelisted in NS.

  • by Mark H. Delfs,

    Mark H. Delfs Mark H. Delfs May 16, 2011 6:07 AM in response to WZZZ
    Level 2 (265 points)
    May 16, 2011 6:07 AM in response to WZZZ

    There's an easy MacDefender kill program at Macupdate that eradicates it and patches Safari to not run "safe" files anymore:

     

    http://www.macupdate.com/app/mac/38520/macdefenderkiller

     

    Easy and free and is great in a lab environment where you have to kill it on multiple machines.

  • by Rayced,

    Rayced Rayced May 17, 2011 9:13 AM in response to Mark H. Delfs
    Level 1 (15 points)
    May 17, 2011 9:13 AM in response to Mark H. Delfs

    Did you tried it? Does this also eradicate the malware from Time Machine's backups?

first Previous Page 5 of 10 last Next