Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« ACLU, EFF and Others Defend WikiLeaks | Main | Email, Web Surfing Hazardous to Your Career? »

Mac Bot Missed by Anit-Virus Detection

SANS is reporting on a newly analyzed IRC bot that has been compiled for Mac OS, FreeBSD and Linux. The fact that such bots run on these platform isn't news, but the rate at which is was detected is interesting:

About 75% of the AV programs detected the bot on FreeBSD and Linux versions but the Mac detection rate was a different story:

Finally, the Darwin version was a bit of a shock – 0 detections in total (!). Since it was a Mach-O executable for PPC, my guess is that AV programs didn't know how to parse the file format and just thought of it as data.

Not a problem for non-PPC platforms but the AV programs aren't preventing this thing from spreading and eventually landing on a vulnerable Mac. For more on Mac malware, check out this podcast.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/649

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net