A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #30285  by ynvb
 Fri Apr 28, 2017 5:56 am
New Mac OSX campaign detected.
Uses naive techniques to install proxy on infected computer. Proxy redirects to attacker controlled server on .onion

Malware spreads via a SPAM campaign of unknwon source.
.onion server seems to currently be offline.

Full report:
http://blog.checkpoint.com/2017/04/27/o ... s-traffic/
 #30305  by ynvb
 Fri May 05, 2017 5:51 am
A new variant, with new Apple Developer ID. Packed with UPX.

http://blog.checkpoint.com/2017/05/04/u ... -campaign/

3f0130cfd7bf61b8e8226dd4775319c7376a08ec019f9df12875e9ea55992e94
cd93142f1e0bac1d73235515bc127f5f9634eafde0bea2d6c294bf3549d612b7
4252e482c9801463e6f684c71f70cb64a17ae74957ed8986f2401c653acae1d7