作者hihieveryone (农药解毒中....)
看板AntiVirus
标题[情报] mac新病毒出现 快装防毒软体吧 !!
时间Wed Mar 28 11:08:53 2012
日前 Trojan-Dropper:OSX/Revir.A 漏洞虽已被修复
但很快的Trojan-Dropper:OSX/Revir.C又出现了
MD5:7DBA3A178662E7FF904D12F260F0FFF3
The main binary
- detected as Trojan-Dropper:OSX/Revir.C .conft
- Contains an encrypted payload .confr
- contains a decoy JPG file. The first 2048 bytes
are also used as the RC4 key to decrypt the payload .cnf
- contains the filename to be used when creating the decoy file
http://goo.gl/5AERC
http://goo.gl/YtGlR from f-secure.com
就我目前的了解这支病毒主要是攻击jpg和pdf
这支病毒版本更新的速度还算蛮快的
还没装防毒和自动更新的人快装吧有装有安心
OSX_IMULER.C
http://goo.gl/mf1eH 这支更凶还会更新
它会执行远端恶意使用者指定的下列命令:
Take a screen shot
Update the C&C server name
List the contents of a folder and save it as /tmp/launch-0rp.dat.
Then upload the file /tmp/launch-0rp.dat.
Get the file size of a file
Download a file from a URL
Execute a command via the shell
Delete a file
Download a file and save it as /tmp/xntaskz.gz.
Decompress the downloaded file to /tmp/xntaskz.
Execute the following command:/tmp/CurlUpload -f /tmp/xntaskz
另外一提
MS12-020 这次是高风险的远端漏洞 也是蛮新的 请windows使用者也快更新吧
以上
--
嗨嗨每个人
我的专长:迅速解毒 当机处理 资料救援 取回帐号 系统规划 资讯整合
系统规划:经济,高效能,低污染,节约能源,(降低噪音震动,电磁波,废热,积尘,辐射)
省空间,使用舒适感佳,温暖的键盘与滑鼠 (抗手冰冷) 乡民说收卡是为了培养EQ
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 182.235.70.42
1F:→ hpo14:你还没有劣文喔~~ 03/28 13:22
2F:→ xvid:这位是高手 怎麽会有劣文 >.^ 03/28 14:19
3F:→ bestpika:喔 03/29 00:08
4F:→ sate5232:看推文还在想说是谁....看到签名档就知道了XD 03/29 02:49
※ 编辑: hihieveryone 来自: 182.235.70.42 (03/31 14:30)