"value":"A macOS malware agent, named MacDownloader, was observed in the wild as targeting the defense industrial base, and reported elsewhere to have been used against an human rights advocate. MacDownloader strangely attempts to pose as both an installer for Adobe Flash, as well as the Bitdefender Adware Removal Tool, in order to extract system information and copies of OS X keychain databases. Based on observations on infrastructure, and the state of the code, we believe these incidents represent the first attempts to deploy the agent, and features such as persistence do not appear to work. Instead, MacDownloader is a simple exfiltration agent, with broader ambitions.\r\n\r\nThe macOS malware also mirrors the approach of the ExtremeDownloader dropper previously documented in our research, and samples of the latter identified during this time used the same infrastructure. Lastly, the exposure of test victim data and code references provide a unique insight into the development of the malware, with potential connections to agents developed by long dormant threat groups.\r\n\r\nSince the Technical Preview of our forthcoming Carnegie Endowment publication about state-sponsored espionage campaigns was released at Black Hat USA, we have continued to disclose information about current Iranian activities in order to promote public education and to provide indicators of compromise. While this agent is neither sophisticated nor full-featured, its sudden appearance is concerning given the popularity of Apple computers with certain community, and inaccurate perceptions about the security of those devices."
"comment":"The malware reads from the embedded Resources folder the \"checkadr.txt,\" which contains the URL for the first beacon. 192.168.3.217 is internal development server address",
"deleted":false,
"disable_correlation":false,
"timestamp":"1486403324",
"to_ids":true,
"type":"url",
"uuid":"5898b6fc-a64c-4400-bcaf-76fb950d210f",
"value":"http://192.168.3.217/DroperTest"
},
{
"category":"Network activity",
"comment":"The malware reads from the embedded Resources folder the \"checkadr.txt,\" which contains the URL for the first beacon. 192.168.3.217 is internal development server address",
"deleted":false,
"disable_correlation":false,
"timestamp":"1486403326",
"to_ids":true,
"type":"url",
"uuid":"5898b6fe-3ac0-4dc2-b797-76fb950d210f",
"value":"http://46.17.97.37/Servermac.php"
},
{
"category":"Payload delivery",
"comment":"Bitdefender Adware Removal Tool - Xchecked via VT: 7a9cdb9d608b88bd7afce001cb285c2bb2ae76f5027977e8635aa04bd064ffb7",