This is included in the the side effects of the Mac/Cowhand-A "Trojan":Originally Posted by Damrod
• Installs itself in the Registry
Registry? That ain't no Registry in MacOS X!
http://www.sophos.com/virusinfo/anal...ccowhanda.html
Accordin to Sophos, there is the first real MacTrojan under OS X. They do not say anything about where and how it spreads though...
Thoughts or expiriences?
PowerMac G4 MDD '03 1.25GHz, 1 GB RAM, 2x80 GB HDD, on OS X 10.4.x/10.5.x
iPod nano 2nd Gen 2GB![]()
Part of the party since MacOS 7
My Last.fm Profile
This is included in the the side effects of the Mac/Cowhand-A "Trojan":Originally Posted by Damrod
• Installs itself in the Registry
Registry? That ain't no Registry in MacOS X!
If it is a trojan, it will require the user to run it. It's annoying that they don't indicate what programs contain this trojan...
A firm that sells AV software 'discovering' a trojan, what are the odds?
PowerBook G4 1.25Ghz, 15", 1GB, 80GB,SuperDrive, 10.4
MacMini, 1.25Ghz G4, 256MB (will be upgraded), 80GB, Combo Drive, 10.4
20GB iPod (4G)
eMate 300, Newton OS 2.1, Bluetooth
Newton MessagePad 2000, Newton OS 2.1, WiFi, Bluetooth
NeXT Turbo Colour, NeXTStep 3.3
TomPhippen.com
dogtanian.net
Nope, definitely ain't one.
If you go to the Advanced portion, it says this:
...which is at least more in line with OS X.Mac/Cowhand-A is a proxy Trojan for the Mac OSX platform.
The Trojan may copy itself to the user's Preferences folder. In order to run itself on startup, the Trojan may add itself to the user's Startup Items.
If you hit the link that is listed as "Trojan" you get sent to a page with the listed trojans, then (I presume) a link to the right of what type of trojan it is. If I'm right, then this is the type of trojan this is supposed to be:
Without more info, I can't say whether or not this is true. Guess we'll have to wait and see if anyone else carries the story.Troj/IRCFlood-E is used to flood an IP address with network packets. The Trojan can be controlled remotely over IRC
I am but a lonely shadow,
Doomed forever to roam and wander.
But if you allow me to pause before I must go,
I'll spin you tales of mystery and wonder.
Site: Night Productions
The 'Registry' reference is probably a standard text, not customised by the person who enters the thing in the database. So that isn't anything we should blame on them right now. (They probably haven't got the right text blurbs for Mac OS X in their database.) What we should _worry_ about is, right now, the bad press this might give Apple.
Mac user since 1987. Running Mac OS X 10.8 Mountain Lion on a MacBook Air 11" & an iMac 27" and whatever's newest for my iPhone 4s, iPad 3 and AppleTV 2.
Apple Certified System Administrator 10.6, Apple Sales Professional 2008-2011, Apple Certified Mac Technician.
Listed here at http://secunia.com/virus_information.../maccowhand-a/ , but its just a reprint of the sophos data (links point back to them). This is unhelpful, as it could make the info be spread without anyone else checking up on its validity.
Oh and on security firms 'finding' virii etc, I'm still boycotting Intego after their last announcement of that dubious mac malware.
How to ask questions sensibly
--Macbook unibody 2.4ghz, 4gb ram, 500gb HD, glossy, OS 10.6.1
--Homebrew PC, iPhone, many hard drives, Nikon D200
As for "first", apparently not:
http://securityresponse.symantec.com...04.trojan.html
I agree that we will have to wait until someone releases some worthwhile information about this trojan -- in particular, how it is spread. At the moment, I am about as frightened of this threat as I am of accidentally installing Windows.
Last edited by Andrew Adamson; April 25th, 2005 at 09:07 AM. Reason: (Secunia reference redundant)
Bookmarks