November 17, 2024
Dr. Web Says Flashback Trojan Infections Have Not Been Significantly Reduced

Dr. Web Says Flashback Trojan Infections Have Not Been Significantly Reduced

Posted April 21, 2012 at 1:55am by iClarified
Contrary to reports from Kaspersky and Symantec, Dr. Web says that the number of Macs infected with the Flashback trojan have not significantly declined.

Symantec recently reported that infections were down to 140,000 and Kaspersky reported they were down to 30,000. Dr. Web disagrees and says that infections are still at about 650,000.

The main domains for BackDoor.Flashback.39 command servers were registered by Doctor Web at the beginning of April, and bots first send requests to corresponding servers. On April 16th additional domains whose names are generated using the current date were registered. Since these domain names are used by all BackDoor.Flashback.39 variants, registration of additional control server names has allowed to more accurately calculate the number of bots on the malicious network, which is indicated on the graph. However, after communicating with servers controlled by Doctor Web, Trojans send requests to the server at 74.207.249.7, controlled by an unidentified third party. This server communicates with bots but doesn't close a TCP connection. As the result, bots switch to the standby mode and wait for the server's reply and no longer respond to further commands. As a consequence, they do not communicate with other command centers, many of which have been registered by information security specialists. This is the cause of controversial statistics - on one hand, Symantec and Kaspersky Lab reported a significant decline in the number of BackDoor.Flashback.39 bots, on the other hand, Doctor Web repeatedly indicated a far greater number of bots which didn't tend to decline considerably. The image below shows how a TCP-connection to the command center makes a BackDoor.Flashback.39 bot freeze.


Dr. Web was the first site to report the spread of BackDoor.Flashback.39 earlier this month.

Read More


Dr. Web Says Flashback Trojan Infections Have Not Been Significantly Reduced
Add Comment
Would you like to be notified when someone replies or adds a new comment?
Yes (All Threads)
Yes (This Thread Only)
No
iClarified Icon
Notifications
Would you like to be notified when we post a new Apple news article or tutorial?
Yes
No
Comments (1)
You must login or register to add a comment...
Jacob
Jacob - April 22, 2012 at 2:10am
I understand that Kornmeal is infected.
Recent. Read the latest Apple News.
RECENT
Tutorials. Help is here.
TUTORIALS
Where to Download macOS Sonoma
Where to Download macOS Ventura
AppleTV Firmware Download Locations
Where To Download iPad Firmware Files From
Where To Download iPhone Firmware Files From
Deals. Save on Apple devices and accessories.
DEALS