Follow us on...
Follow us on Twitter Follow us on Facebook
Register
Page 1 of 2 12 LastLast
Results 1 to 8 of 16
  1. #1
    Damrod's Avatar
    Damrod is offline Registered User
    Join Date
    Aug 2002
    Location
    Aachen, Germany
    Posts
    408
    Thanks
    0
    Thanked 0 Times in 0 Posts

    First real trojan appeared on OS X

    http://www.sophos.com/virusinfo/anal...ccowhanda.html

    Accordin to Sophos, there is the first real MacTrojan under OS X. They do not say anything about where and how it spreads though...

    Thoughts or expiriences?
    PowerMac G4 MDD '03 1.25GHz, 1 GB RAM, 2x80 GB HDD, on OS X 10.4.x/10.5.x
    iPod nano 2nd Gen 2GB
    Part of the party since MacOS 7

    My Last.fm Profile

  2. #2
    MisterMe is offline Registered User
    Join Date
    Jun 2002
    Location
    USA
    Posts
    3,986
    Thanks
    7
    Thanked 140 Times in 136 Posts
    Quote Originally Posted by Damrod
    http://www.sophos.com/virusinfo/anal...ccowhanda.html

    Accordin to Sophos, there is the first real MacTrojan under OS X. They do not say anything about where and how it spreads though...

    Thoughts or expiriences?
    This is included in the the side effects of the Mac/Cowhand-A "Trojan":

    • Installs itself in the Registry

    Registry? That ain't no Registry in MacOS X!

  3. #3
    Viro's Avatar
    Viro is offline Registered User
    Join Date
    Nov 2003
    Location
    Oxford, UK
    Posts
    2,497
    Thanks
    0
    Thanked 2 Times in 2 Posts
    If it is a trojan, it will require the user to run it. It's annoying that they don't indicate what programs contain this trojan...

  4. #4
    mrfluffy's Avatar
    mrfluffy is offline OmniWeb Convert
    Join Date
    Dec 2001
    Location
    Hants UK
    Posts
    346
    Thanks
    0
    Thanked 0 Times in 0 Posts
    A firm that sells AV software 'discovering' a trojan, what are the odds?
    PowerBook G4 1.25Ghz, 15", 1GB, 80GB,SuperDrive, 10.4
    MacMini, 1.25Ghz G4, 256MB (will be upgraded), 80GB, Combo Drive, 10.4
    20GB iPod (4G)
    eMate 300, Newton OS 2.1, Bluetooth
    Newton MessagePad 2000, Newton OS 2.1, WiFi, Bluetooth
    NeXT Turbo Colour, NeXTStep 3.3
    TomPhippen.com
    dogtanian.net

  5. #5
    Darkshadow's Avatar
    Darkshadow is offline wandering shadow
    Join Date
    Jul 2001
    Location
    DE, USA
    Posts
    1,532
    Thanks
    0
    Thanked 1 Time in 1 Post
    Nope, definitely ain't one.

    If you go to the Advanced portion, it says this:

    Mac/Cowhand-A is a proxy Trojan for the Mac OSX platform.

    The Trojan may copy itself to the user's Preferences folder. In order to run itself on startup, the Trojan may add itself to the user's Startup Items.
    ...which is at least more in line with OS X.

    If you hit the link that is listed as "Trojan" you get sent to a page with the listed trojans, then (I presume) a link to the right of what type of trojan it is. If I'm right, then this is the type of trojan this is supposed to be:

    Troj/IRCFlood-E is used to flood an IP address with network packets. The Trojan can be controlled remotely over IRC
    Without more info, I can't say whether or not this is true. Guess we'll have to wait and see if anyone else carries the story.
    I am but a lonely shadow,
    Doomed forever to roam and wander.
    But if you allow me to pause before I must go,
    I'll spin you tales of mystery and wonder.


    Site: Night Productions

  6. #6
    fryke's Avatar
    fryke is offline Super Moderator
    Join Date
    Sep 2000
    Location
    macosx.com
    Posts
    14,287
    Thanks
    15
    Thanked 120 Times in 109 Posts
    The 'Registry' reference is probably a standard text, not customised by the person who enters the thing in the database. So that isn't anything we should blame on them right now. (They probably haven't got the right text blurbs for Mac OS X in their database.) What we should _worry_ about is, right now, the bad press this might give Apple.
    Mac user since 1987. Running Mac OS X 10.8 Mountain Lion on a MacBook Air 11" & an iMac 27" and whatever's newest for my iPhone 4s, iPad 3 and AppleTV 2.
    Apple Certified System Administrator 10.6, Apple Sales Professional 2008-2011, Apple Certified Mac Technician.

  7. #7
    ora's Avatar
    ora
    ora is offline Registered User
    Join Date
    Nov 2003
    Location
    London
    Posts
    2,306
    Thanks
    45
    Thanked 65 Times in 64 Posts
    Listed here at http://secunia.com/virus_information.../maccowhand-a/ , but its just a reprint of the sophos data (links point back to them). This is unhelpful, as it could make the info be spread without anyone else checking up on its validity.

    Oh and on security firms 'finding' virii etc, I'm still boycotting Intego after their last announcement of that dubious mac malware.
    How to ask questions sensibly
    --Macbook unibody 2.4ghz, 4gb ram, 500gb HD, glossy, OS 10.6.1
    --Homebrew PC, iPhone, many hard drives, Nikon D200

  8. #8
    Andrew Adamson's Avatar
    Andrew Adamson is offline Got root? Sudoes.
    Join Date
    Mar 2005
    Location
    Osaka, Japan
    Posts
    97
    Thanks
    0
    Thanked 1 Time in 1 Post
    As for "first", apparently not:
    http://securityresponse.symantec.com...04.trojan.html

    I agree that we will have to wait until someone releases some worthwhile information about this trojan -- in particular, how it is spread. At the moment, I am about as frightened of this threat as I am of accidentally installing Windows.
    Last edited by Andrew Adamson; April 25th, 2005 at 09:07 AM. Reason: (Secunia reference redundant)

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Os X Trojan
    By bobw in forum Mac OS X System & Mac Software
    Replies: 37
    Last Post: April 14th, 2004, 08:57 PM
  2. 10.22 and CD Mounting
    By emh_alpha1 in forum Mac OS X System & Mac Software
    Replies: 5
    Last Post: December 5th, 2002, 03:13 PM
  3. Switch campaign... real "actors"...
    By pezagent in forum Apple News, Rumors & Discussion
    Replies: 36
    Last Post: August 16th, 2002, 07:18 PM
  4. No need for Real...
    By lonny in forum Apple News, Rumors & Discussion
    Replies: 12
    Last Post: June 29th, 2002, 12:25 AM
  5. Real Software
    By tagliatelle in forum Bob's Place
    Replies: 0
    Last Post: February 9th, 2002, 11:00 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •