Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
Status
Not open for further replies.

lasthope

macrumors newbie
Original poster
Feb 13, 2006
1
0
From the moderator: The link originally posted here has been removed.
 

swindmill

macrumors 6502a
Mar 17, 2005
946
4
KY
The download is a unix executable file which opens in Terminal but is disguised as a jpeg.
 

Benjamindaines

macrumors 68030
Mar 24, 2005
2,841
4
A religiously oppressed state
Oh wow, this member should be banned. I downloaded the file and it comes up as a picture file then when I click on it it pops open Terminal and runs something. Looks like someone attempted to make a Mac virus...

Reported.
 

Chaszmyr

macrumors 601
Aug 9, 2002
4,267
86
Benjamindaines said:
Oh wow, this member should be banned. I downloaded the file and it comes up as a picture file then when I click on it it pops open Terminal and runs something. Looks like someone attempted to make a Mac virus...

It does seem so. Also looks like they failed (though I'm not sure because i didn't download it myself)
 

yankeefan24

macrumors 65816
Dec 24, 2005
1,104
0
NYC
i noticed the same basic thing.

Chaszmyr said:
It does seem so. Also looks like they failed (though I'm not sure because i didn't download it myself)

they did.

he is creating another thread (if you believe the public profile), watch for more virus attempts. if he is not banned by the time he finsihes.
 

Laser47

macrumors 6502a
Jan 8, 2004
856
0
Maryland
lol, i downloaded it and ran it. Now if this was a pc, i would have already reformatted and reinstalled it. But since im on a mac right now im just like WTF. has anyone been able to find out what it does exactly. Probably not somthing harmful since you would have had to enter your password.
Edit: whats even funnier is that i was 'lucky' enough to download the file before it was changed by a mod. That person should be banned, even though he is less than likely to comeback.
 

Benjamindaines

macrumors 68030
Mar 24, 2005
2,841
4
A religiously oppressed state
Laser47 said:
lol, i downloaded it and ran it. Now if this was a pc, i would have already reformatted and reinstalled it. But since im on a mac right now im just like WTF. has anyone been able to find out what it does exactly. Probably not somthing harmful since you would have had to enter your password.
Edit: whats even funnier is that i was 'lucky' enough to download the file before it was changed by a mod. That person should be banned, even though he is less than likely to comeback.
He was trying to do something with Fire.app but I don't know what. Also i know for a fact that it didn't do anything because the permission was denied.
 

Laser47

macrumors 6502a
Jan 8, 2004
856
0
Maryland
Benjamindaines said:
He was trying to do something with Fire.app but I don't know what. Also i know for a fact that it didn't do anything because the permission was denied.
Phew. got kinda worried for a sec.
 

Timepass

macrumors 65816
Jan 4, 2005
1,051
1
Laser47 said:
lol, i downloaded it and ran it. Now if this was a pc, i would have already reformatted and reinstalled it. But since im on a mac right now im just like WTF. has anyone been able to find out what it does exactly. Probably not somthing harmful since you would have had to enter your password.
Edit: whats even funnier is that i was 'lucky' enough to download the file before it was changed by a mod. That person should be banned, even though he is less than likely to comeback.

It would not of effect a PC. Virus made for a mac have no effect on a Windows computer. Same goes the other way. It is one of the few times it would of been better to look at it though a PC since it can not be effected by it.

But this could just be a started. I wouldnt be surpised to see a real virus for the mac enter this way. It would not be wide spred becaue it how it needs to be activated.
 

Laser47

macrumors 6502a
Jan 8, 2004
856
0
Maryland
Timepass said:
It would not of effect a PC. Virus made for a mac have no effect on a Windows computer. Same goes the other way. It is one of the few times it would of been better to look at it though a PC since it can not be effected by it.

But this could just be a started. I wouldnt be surpised to see a real virus for the mac enter this way. It would not be wide spred becaue it how it needs to be activated.
I know that, I meant if I opened a file on windows that opened command prompt or installed something. However that would never happen because I never download files that i cannot identify. This one caught me off guard though, forgot how easy it was to change the icon.
 

CoMpX

macrumors 65816
Jun 29, 2005
1,242
0
New Jersey
Benjamindaines said:
Nope, that's the weird thing it's a 3rd party chat app that not a whole lot of people have.

Yea I wonder why he would target an app like that. Can anyone decode it and figure out exactly what he was trying to do?
 

ChrisA

macrumors G5
Jan 5, 2006
12,560
1,671
Redondo Beach, California
swindmill said:
The download is a unix executable file which opens in Terminal but is disguised as a jpeg.

Was it a binary or a shell script? I'm thinking "script"as it opened in a terminal. If you can yu read the file in an editor?

If it is a binary then sometimes you can gain som insight by running the "strings" command on it. See "man strings"

Technically you don't call these things "virus". This is a clasic "Trojan Horse" Only this attempt was poorly executed
 

ITASOR

macrumors 601
Mar 20, 2005
4,398
3
I'm surprised this hasn't happened more on here...it's so easy to write an applescript file and disguise it as anything...scary!
 

Peace

Cancelled
Apr 1, 2005
19,546
4,556
Space The Only Frontier
Man why do I always miss out on all the fun! :eek:

I didnt see the terminal app that was run or anything but by descriptions it sounds like the noob was trying to get into a users computer via a chat app.
 

Benjamindaines

macrumors 68030
Mar 24, 2005
2,841
4
A religiously oppressed state
Peace said:
Man why do I always miss out on all the fun! :eek:

I didnt see the terminal app that was run or anything but by descriptions it sounds like the noob was trying to get into a users computer via a chat app.
Or maybe he wanted to add himself to everyone's buddy list and then have the app send a message to his AIM addy just to see how many people fell for it. Unfortunately (or fortunately for us) he didn't test.
 
Status
Not open for further replies.
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.