© 2008 Websense, Inc. All Rights Reserved.
Blog
Hi I am an infected...Hi I am an infected MAC
10.31.2007 - 3:59 PMPrevious Posts
October 2007| 10/31/2007 | Halloween storm » |
| 10/31/2007 | Hi I am an infected...Hi I am an infected MAC » |
| 10/29/2007 | Beware of Phresh Credit Union Vish » |
| 10/25/2007 | Southern California Wildfire Scams » |
| 10/16/2007 | Sending Out An SOS (Spam Over Skype) » |
| 10/15/2007 | MOTW: PE Lurker Analysis: File Infection through a Kernel Driver » |
| 10/02/2007 | Website Redirection Analysis » |
+ September 2007
+ August 2007
+ July 2007
+ June 2007
+ May 2007
The sites are hosting code which checks to see what browser you are using. If you are using a Windows PC it will attempt to serve you a Windows binary, if you are a MAC a disk image file (.dmg).
The file attempts to change the DNS server settings for the machine and redirect all DNS queries to the attackers server in order to generate advertizing revenue.
Some screenshots are available within Sunblets Blog also here:
http://sunbeltblog.blogspot.com/2007/10/screenshot-of-new-mac-trojan.html
http://sunbeltblog.blogspot.com/2007/10/mackanapes-can-now-can-feel-pain-of.html
Threatseeker is scanning the Web looking for additional sites that we don’t already have classified and that are infected with these links.
Post a Comment:







