Trojan infects only two versions of the system, Mac OS X are: Snow Leopard and Lion, Trojan remains in the system even after a restart of that will exist until it is removed, and if the Trojan resides on the user account has the powers of the ADMIN, the Trojan will install the different components, and modify files system in order to stay hidden from the user, and creates a number of files and folders in order to accomplish this task, as it creates 17 files when it is present in the calculation of ADMIN and 14 file when it is present in a regular account, as soon as the installation of Trojan will contact Bal following IP 176.58. 100.37 every 5 minutes to take instructions
It is worth mentioning that the Trojan creates a file in a way makes it difficult to analyze using the tools of reverse engineering, this technique is common in Troyjonat Windows but is not common in the Mac system Trojan.
0 commentaires:
Enregistrer un commentaire