TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
UNIX_DNSCHAN.AA
Overview

Malware type: Trojan

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Mac OS X

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Low

Description: 

Trend Micro has flagged this malicious obfuscated script as noteworthy due to the increased potential for damage, propagation, or both, that it possesses.

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

UNIX_DNSCHAN.AA Behavior Diagram

Malware Overview

This malicious obfuscated script may be downloaded from remote sites by PERL_JAHLAV.F.

It changes the DNS servers to certain IP addresses. As a result, a remote user is able to monitor user activities. Users may be redirected to phishing sites or sites where other malware may be downloaded.

For additional information about this threat, see:
Solution
Technical Details

Description created: Aug. 11, 2009 7:52:12 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.