OSX.RSPlug.D Trojan Horse – New Variant of RSPlug Trojan

You can find all the latest computer hardware press releases in here.
Post Reply
User avatar
Apoptosis
Site Admin
Site Admin
Posts: 33941
Joined: Sun Oct 05, 2003 8:45 pm
Location: St. Louis, Missouri
Contact:

OSX.RSPlug.D Trojan Horse – New Variant of RSPlug Trojan

Post by Apoptosis »

Just got this e-mail from INTEGO and thought it might be worth passing it along.
Exploit: OSX.RSPlug.D Trojan Horse

Discovered: November 18, 2008

Risk: Medium

Description: A new variant of the RSPlug Trojan horse has been found on several
pornographic web sites. (See Intego’s Internet Security Memo of October 31, 20071 for
more on this Trojan horse.) While this new variant currently performs the same actions
as the RSPlug.A Trojan horse, its installer is different: it is a downloader, and it contacts
a remote server to download the files it installs. This means that, in the future, the
downloader may be able to install other payloads than the one it currently installs.
This new variant, like the initial RSPlug.A Trojan horse, has been found on
pornographic web sites. When visiting such a site, a user is alerted that there is a “Video
ActiveX Object Error” and is told that their “Browser cannot play this video file.” The
alert instructs the user to download the “missing Video ActiveX Object”. If the user
clicks OK, a disk image called cleanlive.dmg downloads (this name may be different in
the future; with the first version of the RSPlug Trojan horse, a number of different
names were found). Depending on the user’s browser settings, this disk image may
mount and launch automatically commencing installation. If the user clicks Cancel
when the Video ActiveX Object alert displays, however, they receive another alert
saying, “Please install new version of Video ActiveX Object.” This alert only allows the
user to click OK, returning them to the first alert. The only way to get rid of these alerts
is either to download the infected disk image, or quit the browser.
here is a screen shot of the virus being detected by CirusBarrier X5:
image001.gif
image001.gif (91.75 KiB) Viewed 727 times
Post Reply