Backdoor:OSX/Tsunami.A

Classification

Category :

Malware

Type :

Backdoor

Aliases :

Backdoor:OSX/Tsunami.A

Summary

Backdoor:OSX/Tsunami.A is a distributed denial-of-service (DDoS) flooder that is also capable of downloading files and executing shell commands in an infected system.

Removal

The F-Secure security product will automatically remove the file.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    NOTE If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note You need administrative rights to change the settings.

Technical Details

Backdoor:OSX/Tsunami.A is an OS X platform ported version of the IRC bot for Linux called "Kaiten wa goraku." Upon execution, it connects to an IRC server and then joins a password protected channel where it waits for further commands.

It is mainly a distributed denial-of-service (DDos) flooder, hence the name Tsunami. However, it is also capable of performing other actions such as downloading additional files and executing shell commands in an infected system. These actions could grant the bot master almost a full control of the infected system.

The IRC parameters, drop files and launch points differ between variants. As of this writing, two variants have been found. The table below describes the characteristics of the two variants.

IRC Server:Port Channel Drop Files and Launch Points
pingu.anonops.li:6667 #tarapia None. It must be installed manually by the user or an attacker who has access to the system
x.lisp.su:6667 #harbour -
/System/Library/LaunchDaemons/com.apple.logind.plist - launch point
/usr/sbin/logind - copy of the malware

As of this writing, both servers are not accessible

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award-winning antivirus and malware protection
  • Online browsing, banking, and shopping protection
  • 24/7 online identity and data breach monitoring
  • Unlimited VPN service to safe­guard your privacy
  • Password manager with private data protection
More Support

Community

Ask questions in our Community .

User Guides

Check the user guide for instructions.

Contact Support

Chat with or call an expert.

Submit a Sample

Submit a file or URL for analysis.