The threat may arrive on the compromised computer by being downloaded via browser exploits or social engineering.
Once executed, copies itself as the following files:
/Library/Internet Plug-Ins/plugins.settings
/Library/Internet Plug-Ins/sendreq
It also creates the following clean file:
/Library/Internet Plug-Ins/Mozillaplug.plugins
It modifies the the hosts' DNS servers to one of the following sets of IP addresses:
- 85.255.115.58
- 85.255.112.159
OR
- 85.255.115.21
- 85.255.112.151
OR
- 85.255.115.116
- 85.255.112.222
OR
- 85.255.113.106
- 85.255.112.85
OR
- 85.255.115.117
- 85.255.112.204
OR
- 85.255.116.150
- 85.255.112.148
It then updates crontab to run the following script:
/Library/Internet Plug-Ins/plugin.settings
Note: This script ensures the DNS server entries are reverted back to the above IP addresses if they are updated.
It then sends the CPU type, the User Identifier (UID), and the hostname to the following URL:
http://85.255.121.37
The Trojan then deletes the file /Library/Internet Plug-Ins/sendreq.
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":