A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #12618  by leeno
 Wed Apr 11, 2012 10:29 am
Hi Guys ,

Any body can help me with wireshark pcap generated from these sample . really i lack a mac system currently .
your help will be highly appreciated.

thanks

Leeno
 #12621  by rkhunter
 Wed Apr 11, 2012 11:00 am
Xylitol wrote:No idea if there is already sample available on the net, i'm just back on the net and not checked these files but they are all detected as Trojan-Downloader.OSX.Flashfake.ab by KAV.
cf here ~ http://www.securelist.com/en/blog/20819 ... _confirmed
Samples in attach (25)
Thank you for the samples, I asked hashes (hashes, not malware) at Kaspersky guys (look comment at it article) but without result...
 #12668  by rkhunter
 Fri Apr 13, 2012 9:27 am
Guys, did you notice that this Mac-botnet story was a usual PR-company from AV-companies side (especially from F-Secure and Dr.Web)? And another attempt to PR of AV-tools that makes nothing actually...
 #12671  by EP_X0FF
 Fri Apr 13, 2012 10:01 am
It revealed problems with security on MacOS isn't it? And Apple now aware who is Dr.Web :)
 #12674  by EP_X0FF
 Fri Apr 13, 2012 10:44 am
It wasn't so obvious and agressive Apple marketing always stated - "There is no malware on Mac, it is not Windows" :)