This threat is has been observed being dropped by
Trojan.Maljava.
When the Trojan is executed, it creates the following file so that it executes whenever the computer starts:
/Users/[USER NAME]/Library/LaunchAgents/com.apple.PubSabAgent.plist
It also creates the following file:
/Users/[USER NAME]/Library/Preferences/com.apple.PubSabAgent.pfile
Next, the Trojan connects to the following location and opens a back door on the compromised computer:
[http://]rtx556.onedumb.com
The Trojan may then allow a remote attacker to perform the following actions on the compromised computer:
- Create new processes
- Download files on to the computer
- Take screenshots
- Upload files from the computer to a remote location
Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":