Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old April 8th, 2012, 01:05 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
Originally Posted by greatwhite
Wow quite a bit of Apple knocking on this bit of the forum. How sad. I have always had an AV program on my Macs because firstly I don't want to forward anything to my windoze using friends without my knowledge and secondly I knew the day would come when we would start getting them on macs. Maybe this threat may wake up some mac users to install an AV program, lets hope so.

A responsible Mac user.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #27  
Old April 8th, 2012, 11:26 PM
noway noway is offline
Frequent Poster
 
Join Date: Apr 2005
Posts: 345
Default Re: More than 600,000 Macs infected with Flashback botnet

Don't worry. If it gets too bad, Apple will just shut your computer down by remote control until they fix it! (Just kidding)

Last edited by noway : April 8th, 2012 at 11:58 PM.
  #28  
Old April 9th, 2012, 04:17 PM
crapbag's Avatar
crapbag crapbag is offline
Regular Poster
 
Join Date: Mar 2011
Posts: 117
Default Re: More than 600,000 Macs infected with Flashback botnet

My lady has used Macs for something like 5 years and never had any kind of AV protection. I don't even think she updates all that regularly. I kinda hope it's automatic

Being a PC man, I'm a paranoid nut-job compared to her.

It's one of those weird things. Some of the AV's available for Macs are pretty pricy *cough* Intego *cough*. Until Mac viruses become a bit more widespread it just isn't worth shelling out for.

After reading about this new bug I made her install Sophos free Mac AV.

A scan revealed she had 9 threats. Only one was a Mac bug, some fake AV for Macs app. The other 8 threats were Windows threats. We've left them on there for now.

It's a tough call, but if you can get decent free or cheapish protection for your Mac I don't get why you wouldn't use it.
__________________
"Truth is you fill your day most of the time by being in the washing machine of your own mind thinking 'What's this? When does it stop? Am I enjoying it? I don't know. Oh, it's time to go to sleep. I can't. I'm worried'."
Dylan Moran.
  #29  
Old April 9th, 2012, 08:01 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: More than 600,000 Macs infected with Flashback botnet

The thing is lets say you have an infected email thats target for windows on your mac,sure it wont hurt you but lets say you sent it off to family,friends running windows and they open the infected email that came from you. It is there resposibility to protect them self,but regardless you will become the evil villian that sent it to them.


Thats what greatwhite pointed out in post # 24 about infecting windoz users by running a AV program to prevent it all around.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.

Last edited by Dark Shadow : April 9th, 2012 at 08:09 PM.
  #30  
Old April 10th, 2012, 01:50 PM
SergM SergM is offline
Regular Poster
 
Join Date: Dec 2008
Location: Saint-Petersburg Russia
Posts: 178
Default BackDoor.Flashback.39 epidemic chronology

April 10, 2012
The news of the outbreak of BackDoor.Flashback.39 that has infected over 650 000 computers running Mac OS X quickly spread throughout the world, causing a strong public response. The Russian anti-virus company Doctor Web that was the first to issue a warning concerning this threat presents the brief BackDoor.Flashback.39 outbreak chronology.


February 2012 Oracle released an update for the Java Virtual Machine closing vulnerabilities exploited by BackDoor.Flashback.39.
March 25, 2012 First Flashback botnet domains registered
March 27, 2012 Doctor Web added the BackDoor.Flashback.39 signature into the virus database used by its Dr.Web for Mac OS X.
April 3, 2012 Doctor Web analysts reverse-engineered the routine employed by BackDoor.Flashback.39 to generate control server domain names, registered several domain names and began gathering statistics by analysing requests received from bots. More than 130000 bot replies were received in the very first hours.
April 4, 2012 According to data collected by Doctor Web virus laboratory, the number of infected hosts in the BackDoor.Flashback.39 botnet reached 550,000. Doctor Web issued a press-release concerning the BackDoor.Flashback.39 epidemic.
April 4, 2012 (April 3 for North America). Apple has released an update for Apple Java closing the vulnerabilities exploited by the Trojan BackDoor.Flashback.39. Due to the difference in time zones, many Mac OS X users got the update after a significant delay.
April 4, 2012 The number of hosts in the botnet exceeded 600 thousand infected Macs.
April 6, 2012 Apple released a second update that closed the vulnerabilities exploited by the Trojan BackDoor.Flashback.39.
April 9, 10 A corporation made unsuccessful attempts to block domains used by Doctor Web to study the BackDoor.Flashback.39 botnet.
April 10 The total number of computers infected by the Trojan has exceeded 650,000.

The current number of machines infected by BackDoor.Flashback.39 is 655 700. Mac users can use the free service from Doctor Web at www.drweb.com/flashback/ to check if their computers are infected.

View the article
  #31  
Old April 10th, 2012, 01:59 PM
SergM SergM is offline
Regular Poster
 
Join Date: Dec 2008
Location: Saint-Petersburg Russia
Posts: 178
Default Re: More than 600,000 Macs infected with Flashback botnet

http://www.forbes.com/sites/andygree...ng-infections/
  #32  
Old April 10th, 2012, 04:02 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,451
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
In order to make it easier for average users to check whether their computers are infected, Kaspersky Lab launched a website on Monday where people can input their systems' unique hardware identifiers (UUIDs) to see if they are among the almost 700,000 Macs known to be infected with Flashback so far.
Kaspersky Launches Free Flashback Removal Tool and Website to Check for Infections by Lucian Constantin.
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #33  
Old April 10th, 2012, 10:58 PM
twl845's Avatar
twl845 twl845 is offline
Massive Poster
 
Join Date: Apr 2005
Location: New York, USA
Posts: 3,331
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
Originally Posted by greatwhite
Wow quite a bit of Apple knocking on this bit of the forum. How sad. I have always had an AV program on my Macs because firstly I don't want to forward anything to my windoze using friends without my knowledge and secondly I knew the day would come when we would start getting them on macs. Maybe this threat may wake up some mac users to install an AV program, lets hope so.
But MAC's don't get infected. Ask at the Apple forum.
__________________
Now that I'm older, I seem to have more patience.
It turns out I just don't give a crap.

WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Active@ Disk Image, Macrium Reflect Standard, AX64 Time Machine
  #34  
Old April 10th, 2012, 11:23 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
Originally Posted by JRViejo
Wow the number is climbing.I wouldn't be a bit suprised if it climbs much higher then it is.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #35  
Old April 10th, 2012, 11:25 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
Originally Posted by twl845
But MAC's don't get infected. Ask at the Apple forum.
Hopefully they will change there tune or just stay in denial.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #36  
Old April 11th, 2012, 08:31 AM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,804
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
Apple is developing software that will detect and remove the Flashback malware.

http://support.apple.com/kb/HT5244
  #37  
Old April 11th, 2012, 08:05 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,804
Default Re: More than 600,000 Macs infected with Flashback botnet

Free stand-alone removal tool from F-Secure:
http://www.f-secure.com/weblog/archives/00002346.html

Free stand-alone removal tool from Kaspersky (already mentioned by JRViejo):
http://www.securelist.com/en/blog/20..._checking_site

===

BBC tech site:
http://www.bbc.co.uk/news/technology-17675314
Apple develops tool to 'detect and remove' Flashback Trojan

PCMag:
http://www.pcmag.com/article2/0,2817,2402914,00.asp
Number of Macs Infected With Flashback Trojan on the Decline

PCWorld:
http://www.pcworld.com/article/25352...nfections.html

Sophos:
http://nakedsecurity.sophos.com/2012...afer-than-pcs/
Are Macs safer than PCs?

Symantec:
http://www.symantec.com/connect/blog...ns-down-270000
OSX.Flashback.K – Suffering a Slashback – Infections Down to 270,000
  #38  
Old April 12th, 2012, 10:12 AM
TheKid7's Avatar
TheKid7 TheKid7 is offline
Very Frequent Poster
 
Join Date: Jul 2006
Posts: 2,504
Default Re: More than 600,000 Macs infected with Flashback botnet

Some more info here:
Quote:
Special project: remove BackDoor.Flashback.39 and learn about first Mac OS X virus outbreak
http://news.drweb.com/?i=2354&c=5&lng=en&p=0
__________________
NOD32, Sandboxie (Paid), AppGuard, Malwarebytes Anti-Malware, Emsisoft Emergency Kit, DrWeb Cureit, AVIRA Rescue CD, Image for Windows/Image for DOS/Image for Linux, Firefox (Adblock Plus, Subscriptions: EasyList+EasyPrivacy+Malware Domains), Norton DNS
  #39  
Old April 12th, 2012, 11:06 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,451
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
Kaspersky Lab on Thursday suspended distribution of its tool to remove the Flashback malware attacking Mac computers, saying the tool itself was making unacceptable alterations to user computers. A replacement is expected soon.
Kaspersky Lab suspends Flashback-removal tool by Joel Mathis.
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #40  
Old April 13th, 2012, 08:56 AM
3x0gR13N 3x0gR13N is offline
Frequent Poster
 
Join Date: May 2008
Posts: 580
Default Re: More than 600,000 Macs infected with Flashback botnet

http://www.kaspersky.com/about/news/...pdated_Version

Quote:
Kaspersky Lab has successfully fixed its free Kaspersky Flashfake Removal Tool. A bug was identified in the original version of the tool, which was first reported at approximately 17:40 MSK (GMT+4) on April 12. The tool was taken offline for maintenance.
  #41  
Old April 14th, 2012, 08:33 AM
vasa1's Avatar
vasa1 vasa1 is offline
Massive Poster
 
Join Date: May 2010
Posts: 3,988
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
The latest Java update from Apple removes the known variants of the Flashback malware from infected Mac OS X systems. It also automatically disables Java if it has not been used during the previous 35 days. Once disabled, users have to manually re-enable Java in order for Java applets to run again. That means that malware attacks like Flashback would be unable to automatically execute and compromise Macs that don't regularly use Java.
...
Kudos to Apple. It may be late to the game when it comes to helping users remove the Flashback malware from Mac OS X, but it has raised the bar for proactively protecting systems at the same time.
http://www.itworld.com/software/2677...cing-risk-macs
__________________
One can't be too rich, too thin, or too secure
  #42  
Old April 14th, 2012, 09:06 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,458
Default Re: More than 600,000 Macs infected with Flashback botnet

I'm not sure if it's just me, but I can't stop but have the feeling that also automatically disables Java if it has not been used during the previous 35 days and Once disabled, users have to manually re-enable Java in order for Java applets to run again. is not really the solution.

Sure, it's good to be disabled after a while, but what if from day 1 to 34, the user visits a legitimate website with some third-party ads, coming from an hijacked ad network, which will then point to an exploit ready to exploit a Java security vulnerability?

Right. I didn't bother reading those articles, but do they make any mentions to Apple actually releasing Oracle's patches as soon as they come out? I imagine they don't, otherwise you folks would have mentioned something about it.

It may be late to the game... The thing is, they're not playing the game, at all.
  #43  
Old April 14th, 2012, 01:58 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,451
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
What Apple didn't do was tell users that the tool existed. Not with a software update, not with a press release. It isn't listed on the Mac App Store and it doesn't show up in a search of the Apple website. And if you do somehow find and install it on your computer, it will disappear into the underlying code, making its presence known only if Flashback shows up.
Apple's Flashback fixes: Three belts and a pair of suspenders by Philip Elmer-DeWitt.

Flashback Malware Removal Tool
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #44  
Old April 15th, 2012, 03:54 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,451
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
Now, as the dust settles on what is considered to be the largest Mac malware threat to date, experts have started pointing fingers at Apple as being partially to blame for the scope of the Flashback malware infection. They argue that if Apple were more transparent about security issues--and if it had promptly released a Flashback fix--the extent of the damage could have been smaller. Also contributing to the magnitude of the infections is a boost in the number of Mac OS users, they say.
Flashback Malware Puts Apple in Security Spotlight: Experts Weigh In by Howard Baldwin.
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #45  
Old April 18th, 2012, 01:23 PM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,451
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
Though multiple removal tools are available from Apple and antivirus software vendors, the Flashback trojan is still infecting about 140,000 Macs. According to Symantec, the level of infection has dropped considerably since the latest Flashback variant was detected two weeks ago, but a surprisingly high number of Macs are still attempting to check in with command-and-control servers.
Flashback waning, but still infecting about 140,000 Macs by Chris Foresman.
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #46  
Old April 18th, 2012, 03:03 PM
gerardwil gerardwil is offline
Massive Poster
 
Join Date: Jan 2004
Posts: 4,510
Default Re: More than 600,000 Macs infected with Flashback botnet

Boris Sharov (DrWeb):
Quote:
The botnet seems to be slowly increasing inspite of Apple's updates.

http://twitter.com/#!/b_sharov/status/192586162517450752
  #47  
Old April 20th, 2012, 03:06 PM
SergM SergM is offline
Regular Poster
 
Join Date: Dec 2008
Location: Saint-Petersburg Russia
Posts: 178
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
Originally Posted by gerardwil
Boris Sharov (DrWeb):

http://twitter.com/#!/b_sharov/status/192586162517450752

Doctor Web doesn't register significant decrease in BackDoor.Flashback.39 bot number

http://news.drweb.com/show/?i=2386&lng=en&c=5
  #48  
Old April 21st, 2012, 04:02 AM
guest
 
Posts: n/a
Default Re: More than 600,000 Macs infected with Flashback botnet

Flashback infections not waning after all; 650,000 Macs still hijacked

Name:  en_grafik_map_flashback_20_ap-4f91f74-intro-thumb-640xauto-33203.png
Views: 156
Size:  50.4 KB
This image charts the number of Flashback bots from April 3 to April 19.

Quote:
Originally Posted by Ars
Analysis declaring the demise of the Flashback Mac backdoor has been greatly exaggerated, said researchers with a Russia-based antivirus firm, who on late Friday estimated there are 650,000 unique OS X machines currently infected by the malware.

Read more: http://arstechnica.com/apple/news/20...l-hijacked.ars
  #49  
Old April 24th, 2012, 12:30 AM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,451
Default Re: More than 600,000 Macs infected with Flashback botnet

Quote:
The new variant -- dubbed Flashback.S -- "is actively being distributed in the wild," taking advantage of a Java vulnerability that Apple has already patched, security company Intego said in a statement. The new variant installs itself on the user's home folder without a password and then deletes all folders and files from the Java cache folder to mask its presence.
New Flashback variant making the rounds by Steven Musil.
__________________
JR
"You don't have to win every argument. Agree to disagree." Regina Brett
  #50  
Old April 24th, 2012, 12:32 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: More than 600,000 Macs infected with Flashback botnet

ouch.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:13 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums