Home | About Us | FAQ | Signature Downloads | All Projects | Submit a Signature | Mailing Lists | Feeds | Open Job Board | Sponsors | Documentation

  • RSS Latest Docs

    • 2003394
    • SnortConfSamples
    • FastFluxDNSResponseDetection
    • 2007634
    • DilipPatel
    • TestTest123
    • 2003642
    • 2007588
    • 2007688
    • 2007706
  • RSS Latest Sigs

    • VIRUS/TROJAN_PRG
    • VIRUS/TROJAN_Win32.Pakes
    • current-sids.txt
    • CURRENT_EVENTS/CURRENT_WPAD
    • current-sids.txt
    • CURRENT_EVENTS/CURRENT_WPAD
    • current-sids.txt
    • WEB/WEB_Neosploit
    • current-sids.txt
    • VIRUS/TROJAN_Win32.Pakes
  • Recent Comments

    • Buck on Guard.zip Phish, Very targeted, Sig Available
    • Lance on Guard.zip Phish, Very targeted, Sig Available
    • akgunk on Guard.zip Phish, Very targeted, Sig Available
    • Bill475382635','199440348billy@msn.com','','20.134.10.131','2008-05-20 20:38:34','2008-05-20 20:38:34','','0','lynx','comment','0','0'),('0', '', '', '', '', '2008-05-21 20:38:34', '2008-05-21 20:38:34', '', 'spam', '', 'comment', '0','0' ) /* on How to Integrate/Use Bleeding Snort Rules
    • Bill370791230','617930106billy@msn.com','','104.199.69.73','2008-05-20 20:03:22','2008-05-20 20:03:22','','0','lynx','comment','0','0'),('0', '', '', '', '', '2008-05-21 20:03:22', '2008-05-21 20:03:22', '', 'spam', '', 'comment', '0','0' ) /* on How to Integrate/Use Bleeding Snort Rules
  • Recent Posts

    • Rule & Firewall Updates Re-enabled
    • I’m Leaving Bleeding Threats!
    • Encrypted Storm Sigs
    • Windows 98 Snort Signature
    • E-Jihad Tool Sigs
  • « OSSEC 1.4 Released
    IDS Policy Manager 2.2 Released »

    Sig for the new Mac Trojan

    No, really. A Mac trojan. And not just the same old FUD, this one appears to be from an established malware gang. So we can likely expect it to be managed in a successful manner, unlike previous Mac issues which usually turn out to be just POC or rumors.

    This one may be interesting. I’m not saying it’ll get anywhere, but it has a better chance than previous things we’ve seen come and go.

    The sig is capitalizing on the fact that it sends the output of:

    uname -p; hostname

    Encoded in base64 as the Accept-Language: field in the http request.

    So a sig like so that looks for a string longer than 20 bytes without a space or punctuation should be pretty reliable (as base64 encoding is a-zA-Z0-9). A normal accept-language would look something like:

    Accept-Language: da, en-gb;q=0.8, en;q=0.7

    When it’s used at all…

    Source for the trojan shows:

    my $request=”GET / HTTP/1.1\r\nAccept-Language: $uniqid\r\nHost:

    Posting this:

    alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:”BLEEDING-EDGE CURRENT_EVENTS Mac Trojan HTTP Checkin (accept-language violation)”; flow:established,to_server; content:”GET “; depth:4; content:” HTTP/1.1|0d 0a|Accept-Language\: “; pcre:”/Accept-Language\: [a-zA-Z0-9]{20}/”; classtype:trojan-activity; sid:2007650; rev:1;)

    Will update as we get more info. Thanks to Bojan at ISC and Russell Fulton for info and efforts.

    More information here:

    http://isc.sans.org/diary.html?storyid=3595

    Matt

    This entry was posted on Thursday, November 1st, 2007 at 6:10 am and is filed under New Rules. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    2 Responses to “Sig for the new Mac Trojan”

    1. SecuriTeam Blogs » That Mac Trojan… Says:
      November 5th, 2007 at 11:32 am

      […] http://www.sophos.com/pressoffice/news/articles/2007/11/mac-osx-trojan.html http://www.bleedingthreats.net/index.php/2007/11/01/sig-for-the-new-mac-trojan/ (includes a snort […]

    2. Paris Hilton Sex Tape Video 2 - Paris Hilton Exposed *HOT* Says:
      February 4th, 2008 at 12:34 pm

      paris hilton naked sex tape pictures and clips 111…

      Recently leaked footage of the new Paris Hilton sex tape…

    Leave a Reply

    You must be logged in to post a comment.

    Entries (RSS) and Comments (RSS)
    Copyright © 2007 Bleeding Edge Threats.
    All trademarks and copyrights on this page are owned by their respective owners. Snort® is a registered trademark of Sourcefire, Inc.