Aug11 |
2:41 am (UTC-7) | by
Det Caraig (Technical Communications) |
A Domain Naming System (DNS)-changing Trojan targeting Macs is currently making the rounds disguised as MacCinema Installer (detected by Trend Micro as OSX_JAHLAV.D. This is the latest variant of OSX_JAHLAV.C, which was identified in June.
![]() |
The Trojan is supposedly a QuickTime Player update with the file name QuickTimeUpdate.dmg. As with its earlier variants, users are prompted to download the malware when trying to view certain online videos from .com domains with the IP address, 91.214.45.73 such as:
- allincorx
- bigdron
- cikaredo
- civilizxx
- comeandtryx
- deribrowns
- draxxtermania
- givendream
- hitrowzone
- jumborad
- ltdkeeper
- operationelx
- oxxadox
- paxxtiger
- rednetx
- rstdeals
- simplexdoom
- sinisteer
- tdenuwas
- tniredrum
- ufapeace
If infected, a victim’s Web traffic can then be diverted to the website of the attacker’s choosing.
The Trojan contains component files detected as UNIX_JAHLAV.D and obfuscated scripts detected as PERL_JAHLAV.F. The Perl script then downloads a file from a malicious site and stores it as /tmp/{random 3 numbers}, detected as UNIX_DNSCHAN.AA, which allows a malicious user to monitor the affected user’s activities. This may also cause the user to be redirected to phishing sites or sites where other malware may be downloaded from.
Trend Micro Advanced Threats Researcher Feike Hacquebord notes the domain names have been set up such that when the main IP goes or is taken down, cybercriminals can easily move the backend to another IP address without the need to change code or scripts.
It would serve Mac users well to stay away from the above-mentioned domains and IP addresses or be wary of prompts to download software updates that do not come from Apple’s legitimate website.
Mac users are protected by the Smart Protection Network through Trend Micro Security for Mac and Smart Surfing for Mac.
Share this article |
|






Pingback: Data Security Podcast Episode 66, Aug 17 2009 « Data Security Podcast
Pingback: Mac security: MacCinema is the same steaming pile [different day] - MAC.BLORGE
Pingback: Mac Trojan is just typo away! « Threat Researcher
Pingback: Nuevo Mac OS X DNS changer se propaga mediante ingenieria social | Shadow Security
Pingback: Plaats hier software gerelateerd nieuws! - Page 10
Pingback: New Mac OS X DNS changer spreads through social engineering | Cyber World Network
Pingback: UnderForge of Lack » Blog Archive » 2009.08.12 水曜日
Pingback: New trojan that hijacks your Mac’s DNS spotted in the wild | Supossably
Pingback: Novo cavalo de Troia se mascara como update do QuickTime e pode alterar o DNS de Macs infectados | MacMagazine
Pingback: New trojan that hijacks your Mac’s DNS spotted in the wild - - Tech News
Pingback: Open Systems Journal » Blog Archive » New trojan that hijacks your Mac’s DNS spotted in the wild
Pingback: New Mac OS X DNS changer spreads through social engineering | Zero Day | ZDNet.com