TextEdit is an application on every Mac that you can use to create and edit text files. It's included with all versions of macOS and OS X. Find TextEdit in the Applications folder on your Mac computer. By default, it creates formatted documents saved in rich text format, but you can use it to create a plain text file on a Mac. It copies a file called README!txt all around the user’s directories such as “Documents” and “Photos”. Its content is shown later in the article. Its content is shown later in the article.
Let's create, locally on the Mac, a folder containing a file b.txt and a symlink a.txt to that file. Mkdir TestFolder cd TestFolder touch b.txt ln -s b.txt a.txt ls -l lrwxrwxrwx 1 user staff 5 Oct 26 10:33 a.txt - b.txt -rw-r-r- 1 user staff 0 Oct 26 10:33 b.txt. Fixes reading ReadMe and License files. Mac: Fixes updater. 8.0 Development Release (January 10, 2011) Writes out system preference defaults during install/update Credits button fixes Page numbers now appear on reports, other report fixes. Number of sessions attached to TSR now displayed. 8.0 Development Release (December 22.
This last month we have seen a new ransomware for Mac. Written in Swift, it is distributed on BitTorrent distribution site as “Patcher” for pirating popular software.
Crypto-ransomware has been very popular lately amongst cybercriminals. While most of it targets the Windows desktop, we’ve also seen machines running Linux or macOS being compromised by ransomware in 2016 with, for example, KillDisk affecting Linux and KeRanger attacking OS X.
Early last week, we have seen a new ransomware campaign for Mac. This new ransomware, written in Swift, is distributed via BitTorrent distribution sites and calls itself “Patcher”, ostensibly an application for pirating popular software.
Figure 1 – BitTorrent site distributing Torrent files containing OSX/Filecoder.E
The Torrent contains a single ZIP file – an application bundle. We saw two different fake application “Patchers”: one for Adobe Premiere Pro and one for Microsoft Office for Mac. Mind you, our search was not exhaustive; there might be more out there.
Figure 2 – Icons of the “Patchers” as seen in Finder
The application is generally poorly coded. The window has a transparent background, which can be quite distracting or confusing (see Figure3), and it’s impossible to reopen the window if it is closed.
The application has the bundle identifier NULL.prova and is signed with a key that has not been signed by Apple.
2 4 6 8 10 | Executable=Office2016Patcher.app/Contents/MacOS/Office2016Patcher Format=app bundle with Mach-Othin(x86_64) CodeDirectoryv=20100size=507flags=0x2(adhoc)hashes=11+3location=embedded Info.plist entries=22 Sealed Resources version=2rules=12files=14 |
Figure 3 – The main window of the ransomware
Clicking the start button – shown in Figure 3 – launches the encryption process. It copies a file called README!.txt all around the user’s directories such as “Documents” and “Photos”. Its content is shown later in the article.
Readme Txt Xvid Codec For Mac
Then the ransomware generates a random 25-character string to use as the key to encrypt the files. The same key is used for all the files, which are enumerated with the find command line tool; the zip tool is then used to store the file in an encrypted archive.
Finally, the original file is deleted with rm and the encrypted file’s modified time is set to midnight, February 13th 2010 with the touch command. The reason for changing the file’s modified time is unclear. After the /Users directory is taken care of, it does the same thing to all mounted external and network storage found under /Volumes.
Once all the files are encrypted there is code to try to null all free space on the root partition with diskutil, but the path to the tool in the malware is wrong. It tries to execute /usr/bin/diskutil, however the path to diskutil in macOS is /usr/sbin/diskutil.
Figure 4 – Encrypted document and README!.txt as they appear in Finder
The instructions left for the victims in the README!.txt files are hardcoded inside the Filecoder, which means that the Bitcoin address and email address are always the same for every victim running the same sample. The message and contact details were the same in both samples we analyzed.
2 4 6 8 10 12 14 16 | All of your files were protectedbyastrong encryption method. What doIdo? So,there are two ways you can choose:wait foramiracle orstart obtaining BITCOIN NOW!,andrestore YOUR DATA the easy way IfYou have really valuable DATA,you better NOTWASTE YOUR TIME,because there isNO other way toget your files,except makeaPAYMENT FOLLOW THESE STEPS: 1)learn how tobuy bitcoin https://en.bitcoin.it/wiki/Buying_Bitcoins_(the_newbie_version) 2)send0.25BTC to1EZrvz1kL7SqfemkH3P1VMtomYZbfhznkb 3)send your btc address andyour ip(you can get your ip here https://www.whatismyip.com) via mail to rihofoj@mailinator.com 4)leave your computer on andconnected tothe internet forthe next24hours after payment,your files will be unlocked.(Ifyou can notwait24hours makeapayment of0.45BTC your files will be unlocked inmax10minutes) KEEP INMIND THAT YOUR DECRYPTION KEY WILL NOTBE STORED ON MY SERVER FORMORE THAN1WEEK SINCE YOUR FILE GET CRYPTED,THENTHERE WON'T BE ANY METHOD TO RECOVER YOUR FILES, DON'TWASTE YOUR TIME! |
So far, there is no transaction related to the Bitcoin wallet. Which mean the authors have not made a dime from this ransomware. Hopefully this post will raise awareness and keep the wallet’s balance at zero.
There is one big problem with this ransomware: it doesn’t have any code to communicate with any C&C server. This means that there is no way the key that was used to encrypt the files can be sent to the malware operators.
Readme Txt Download Mac
This also means that there is no way for them to provide a way to decrypt a victim’s files. Paying the ransom in this case will not bring you back your files. That’s one of the reasons we advise that victims never pay the ransom when hit by ransomware.
Alas, the random ZIP password is generated with arc4random_uniform which is considered a secure random number generator. The key is also too long to brute force in a reasonable amount of time.
Interestingly, the email address is an address provided by Mailinator. Mailinator provides a free inbox to anyone without requiring them to register or authenticate. This means it is possible to see the inbox used to communicate with the malware author. We’ve been monitoring this inbox for the last week and didn’t see any messages. However, it’s possible the messages get deleted really fast and we simply missed them.
This new crypto-ransomware, designed specifically for macOS, is surely not a masterpiece. Unfortunately, it’s still effective enough to prevent the victims accessing their own files and could cause serious damage.
There is an increased risk when downloading pirated software that someone is using a dubious channel for acquiring software in order to make you execute malware. ESET recommends that you have a security product installed but the most important precaution in case you encounter crypto-ransomware is to have a current, offline, backup of all your important data.
ESET products detect this threat as OSX/Filecoder.E. Crack 30 day trial periods programs 2020.
Readme.txt Mac
SHA-1 | Filename | Type | ESET detection name |
---|---|---|---|
1b7380d283ceebcabb683464ba0bb6dd73d6e886 | Office 2016 Patcher.zip | ZIP of App bundle | OSX/Filecoder.E |
a91a529f89b1ab8792c345f823e101b55d656a08 | Adobe Premiere Pro CC 2017 Patcher.zip | ZIP of App bundle | OSX/Filecoder.E |
e55fe159e6e3a8459e9363401fcc864335fee321 | Office 2016 Patcher | Mach-O | OSX/Filecoder.E |
3820b23c1057f8c3522c47737f25183a3c15e4db | Adobe Premiere Pro CC 2017 Patcher | Mach-O | OSX/Filecoder.E |