Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Backdoor:OSX/Tsunami.A


Aliases:


Backdoor:OSX/Tsunami.A

Malware
Backdoor
OSX

Summary

Backdoor:OSX/Tsunami.A is a distributed denial-of-service (DDoS) flooder that is also capable of downloading files and executing shell commands in an infected system.



Disinfection & Removal


Automatic Disinfection

Allow F-Secure Anti-Virus for Mac to remove the relevant files.



Technical Details

Backdoor:OSX/Tsunami.A is an OS X platform ported version of the IRC bot for Linux called "Kaiten wa goraku." Upon execution, it connects to an IRC server and then joins a password protected channel where it waits for further commands.

It is mainly a distributed denial-of-service (DDos) flooder, hence the name Tsunami. However, it is also capable of performing other actions such as downloading additional files and executing shell commands in an infected system. These actions could grant the bot master almost a full control of the infected system.

The IRC parameters, drop files and launch points differ between variants. As of this writing, two variants have been found. The table below describes the characteristics of the two variants.

IRC Server:Port Channel Drop Files and Launch Points
pingu.anonops.li:6667 #tarapia None. It must be installed manually by the user or an attacker who has access to the system
x.lisp.su:6667 #harbour -
/System/Library/LaunchDaemons/com.apple.logind.plist - launch point
/usr/sbin/logind - copy of the malware

As of this writing, both servers are not accessible







Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.

Disinfect your Mac




F-Secure Anti-Virus for Mac will disinfect your Mac and remove all harmful files