MyAntiSpyware


Leap.A – Worm for Mac OS X

Myantispyware team February 18, 2006    

Leap.A is a binary file compiled for Mac OS X. It arrives in an archive file, called ‘latestpics.tgz’. When the executable in the archive is opened the virus activates. First it drops an icon resource and an external hook bundle which is used for spreading through iChat.

Spreading through iChat

Leap.A installs a bundle to ‘~/InputManagers/apphook’ that hooks certain iChat functions. When any of the user’s buddies change their status, the worm initiates a file transfer and sends a copy of ‘ ‘latestpics.tgz’. The file transfer is not visible to the user as the worm hides the transfer status information.

File infection

The worm enumerates all applications on the computer that were used during the last month. Leap.A replaces the main executable of those applications with itself and saves the original file to a resource fork with the same filename. When the application is opened the worm activates first, then it runs the original application from the resource fork.

Thanks to F-Secure.

Worms

 Previous Post

Found DVD disks contains a copy protection mechanism which uses rootkit-like cloaking technology.

Next Post 

Multiple vulnerabilities in WinAmp – Affected all versions (including 5.13)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

Leave a Reply Cancel reply

New Guides

Jetterix Reviews, $59 Hose Attachment Pressure Hack Scam Exposed
Doecex.com Promo Code Scam: What You Should Know
scam alert
Gerspin.com Promo Codes: A Crypto Scam
scam alert
Jetovex.com Promo Codes: A Crypto Scam
Kegodex.com Scam Alert: Fake Promo Codes

Follow Us

Search

Useful Guides

Files encrypted by ransomware become useless
How To Recover Encrypted Files (Ransomware file recovery)
Iphone Calendar virus spam
Iphone Calendar Virus/Spam 2022 (Removal guide)
How to reset Google Chrome settings to default
browser redirect virus
How to remove Browser redirect virus [Chrome, Firefox, IE, Edge]
How to reset Internet Explorer settings to default

Recent Guides

Found DVD disks contains a copy protection mechanism which uses rootkit-like cloaking technology.
Exploit for Vulnerability in Windows Media Player has been released
Adware SE 14.02.2006 update now available
Vulnerability in Windows Media Player Could Allow Remote Code Execution
How to remove AlfaCleaner

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2026 MASW - Myantispyware.com.