Jun 02, 2017 Attempting to open profile files using the snakeviz entry-point no longer opens an instance of the default browser: $ snakeviz basicprofile.prof & 1 11150 username:/work $ snakeviz web server started on 127.0.0.1:8080; enter Ctrl-C. Slither through a new competitive version of Snake and survive as long as you can! Challenge your friends and try to be the biggest worm in Snake.io! Snake Deluxe for Mac 2.1 can be downloaded from our website for free. This application's bundle is identified as com.Crazysoft.Snake2. Our built-in antivirus checked this Mac download and rated it as 100% safe. The application is also known as 'SnakeDeluxeDemo'. The application belongs to Games. The most popular version of Snake Deluxe for Mac.
Google uses cookies and data to:Click “Customize” to review options, including controls to reject the use of cookies for personalization and information about browser-level controls to reject some or all cookies for other uses. You can also visit g.co/privacytools anytime.
Snake is a known malware on Windows OS since 2008. In 2017 fox-it found a variant of this malware that was ported to macOS.The malware arrived as the file “Install Adobe Flash Player.zip” which is a modify version of Adobe Flash installation. Within the zip file there is a macOs application bundle signed with a legitimate Apple Developer ID (revoked already):
Source: CheckPoint
Once executed the malware will execute its script first prior the real Adobe installation. It will use AppleScript in order to execute its infection script with administrator permissions:
Source: CheckPoint
The infection vector contains two scripts. The first will copy the malware files to target locations “/Library/Scripts/” and create a LaunchDaemon in order to persist on the system.
Source: CheckPoint
The second script “installd.sh” will check if “installdp” process is running, and if not, will execute it.It is unknown what the infection vector is, if any infection was there at all. From the malicious binary file “installdp” it might be implied that this version of the malware is not finished as there are a lot of debug strings:
Source: CheckPoint
Links: