![]() |
| Img.baronet4tibet. Tibetan furniture featuring a leopard and a lion |
Better late than never. Here are the samples of the recent twin newsmakers OSX/Dockster.A and Win32/Trojan.Agent.AXMO. The malware was already described and hashes published but I thought I would add traffic captures and samples themselves.
I ran these samples on Thursday, November 29 (OSX) and Friday, November 30 (Agent.AXMO) when the C&C servers were still online. Intego mentioned the address itsec.eicp.net was not registered and it was possibly a test but it is a dynamic DNS address and it was down by the weekend.Credit for the sample goes to an anonymous Santa.
I have to admit that my knowledge of OSX malware leaves much to be desired. When we deal with Windows malware, range of choices for capturing, logging, recording, and analyzing is similar to this. I cannot name more than a few for MAC OSX - Wireshark, native Apple syslogs, IDA, Macmemoryze from Mandiant, and a few more below. If you have some good recent papers and tools lists for OSX malware analysis please share.
Read more here
http://www.f-secure.com/weblog/archives/00002466.html
Read more here
http://www.f-secure.com/weblog/archives/00002466.html







