Results 1 to 2 of 2

Thread: Flashfake botnet confirmed on Mac OS X, distributed as Java applet

  1. #1
    Join Date
    Dec 2004
    Posts
    420

    Flashfake botnet confirmed on Mac OS X, distributed as Java applet

    Kaspersky Lab analysis showed more than 600 000 unique robots that were connected to your server within 24 hours, using a total of more than 620 thousand IP addresses. Approximately 300 000 917 of active bots were connected from the United States, followed by 94 000 625 in Canada, 27 000 109 in the UK and 41 000 600 in Australia. The analysis confirmed that this Trojan virus is also present in Latin America with over 13 thousand Macs are infected. Mexico has about 6 000 infections, as many Mac-based computers in Latin America compromised by this threat. The map below shows the penetration of Flashfake in South America.

    The bot is distributed as a Java applet on web pages infected by passing himself off as an update for Adobe Flash Player. The Java program then executes the first downloader, which in consequence, the main component of the Trojan downloads and installs. In the main component is a Trojan downloader, which continuously connects with one of its command-and-control servers (C & C) and is waiting to download and execute other new components.

    Once installed, the Trojan alternates browser's search results, skewing the results to phishing sites through ad clicks. It also functions as a downloader, which allow creators to update it with new threats or harmful characteristics.

    As the botnet actually has been spreading due to a vulnerability in Java, at first glance could not blame Apple for this shortcoming. However, it happens that Oracle released a security patch for more than three months, but the Cupertino company recently put available since last April 2, allowing the indiscriminate spread of the botnet.

    If your Mac is under attack, it takes regular contact with the cyber criminal’s domains that point to a supervisory authority to, in order to receive commands, such as redirecting search requests to advertising sites or spam. Of the domains, there are 5 new every day, then 365 x 5 domains. If one domain, there are 20 case-back domains that can be resorted to. If the connection has been established between the bot and the domain receives the IP address of the supervisory and the Hardware UUID and commands issued in exchange for example, to unwanted advertisements. Of the approach and intent of these botnet cyber criminals is similar to the DNS Changer botnet.

  2. #2
    Join Date
    Feb 2010
    Posts
    538

    Re: Flashfake botnet confirmed on Mac OS X, distributed as Java applet

    Flashback is definitely one of the greatest threats ever detected for the Apple operating systems. The malware is disguised by false update for Flash Player and exploits a flaw in Java to access data on our computer sends to a remote server. Flashfake Removal Tool is therefore one of the safest way to detect the presence of malware on our computer and Macs without having to remove it to make by hand, via the terminal, this work. This security tool from Kaspersky Lab is fully automatic. Once downloaded and launched, will only ask you to enter the root password of our Mac and start scanning and then in the case of positive detection, remove the malware.

Similar Threads

  1. How to run java applet program using cmd
    By Rao's in forum Software Development
    Replies: 3
    Last Post: 07-01-2012, 03:35 PM
  2. Zoom in on a Java Applet?
    By Bharata in forum Software Development
    Replies: 6
    Last Post: 21-10-2010, 07:01 AM
  3. Java signed applet permission
    By Parvati in forum Software Development
    Replies: 4
    Last Post: 09-08-2010, 10:28 AM
  4. Java applet errors
    By Harpreet Gaur in forum Software Development
    Replies: 5
    Last Post: 12-01-2010, 12:08 PM
  5. Refresh Java Applet
    By Brake Fail in forum Software Development
    Replies: 6
    Last Post: 16-03-2009, 10:02 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,418,377.28668 seconds with 17 queries