Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.mac.system > #23756

Flashback immunity via ... Xcode?! (and others)

From Rich Gray <devnull@nowhere.invalid>
Newsgroups comp.sys.mac.system
Subject Flashback immunity via ... Xcode?! (and others)
Date 2012-04-12 23:48 -0400
Organization dis
Message-ID <9uplvhFq83U1@mid.individual.net> (permalink)

Show all headers | View raw


According to :
<http://www.informationweek.com/news/security/vulnerabilities/232900223>

Flashback looks for certain software on the victim's machine:
- Little Snitch firewall
- Packet Peeper network protocol analysis software
- Apple's Xcode development tools
- various antivirus products
- Skype
- MS Office

If it finds any of these, it deletes itself, without executing its malicious 
payload.  I guess it was trying to keep a low profile, avoiding 
detection/analysis by geeks.  (Who knows what's up with Skype & MS Office...)

Funny, I never thought of a compiler as an anti-malware tool! ;p

- Rich

Back to comp.sys.mac.system | Previous | NextNext in thread | Find similar | Unroll thread


Thread

Flashback immunity via ...  Xcode?! (and others) Rich Gray <devnull@nowhere.invalid> - 2012-04-12 23:48 -0400
  Re: Flashback immunity via ...  Xcode?! (and others) dempson@actrix.gen.nz (David Empson) - 2012-04-13 20:02 +1200

csiph-web