Begin 777 withLove by OSX DNSChanger
November 19, 2008
14 comments
What’s new? Here’s a static analysis of this new variant. Notice the header, it seems the compression used was changed.
The preinstall/preupgrade script now looks like this:
Which previous variants contains code or sequence of strings as follows:
Before,the installer name was “MacVideo” and “Porn4Mac”, today it’s “MacAccess”.
Most known IPs and nodes of this threats is currently active serving this variant.
Stay safe and report Dodgy websites!







Recent Comments