TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
OSX_JAHLAV.D
Overview

Malware type: Others

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Mac OS X

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Low

Description: 

Trend Micro has flagged this malware as noteworthy due to the increased potential for damage, propagation, or both, that it possesses.

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

OSX_JAHLAV.D Behavior Diagram

This malware may be downloaded unknowingly by a user when visiting malicious Web sites. The said Web site encourages users to download a codec needed to play a video on the said site.

It arrives as a .DMG file that contains an installer package. The said installer package contains component files and malicious scripts. These malicious scripts are detected by Trend Micro as UNIX_JAHLAV.D.

It displays the following user interface upon execution:

{Fake GUI}

While this malware is supposedly installing an application, it executes UNIX_JAHLAV.D in the background. As a result, routines of the executed scripts are exhibited on the affected system.

For additional information about this threat, see:
Solution
Technical Details

Description created: Aug. 7, 2009 11:00:29 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.