x
48h OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
SPECIAL OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
HALLOWEEN OFFER
take advantage of our
terrific discounts
BUY NOW AND GET A 50% OFF
x
CHRISTMAS OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 40% OFF
x
SPECIAL OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 50% OFF
x
BLACKFRIDAY OFFER
Buy the best antivirus
at the best price
TODAY ONLY UP TO 70% OFF
x
CYBERMONDAY OFFER
Buy the best antivirus
at the best price
(Only for homeusers)
TODAY ONLY UP TO 70% OFF
Active Scan. Scan your PC free
Panda Protection

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

RxPlug.A

Threat LevelLow threatDamageHighDistributionNot widespread
Common name:RxPlug.A
Technical name:OSX/RxPlug.A
Threat level:Medium
Type:Trojan
Effects:  

It only affects computers with Mac OS X operating system. It modifies the DNSs (Domain Name System) of the system so that they point to other malicious websites. It reaches the computer passing itself off as a codec in order to view videos in certain websites for adults.

Affected platforms:

Mac

First detected on:Nov. 2, 2007
Detection updated on:Nov. 9, 2007
StatisticsNo

Brief Description 

    

RxPlug.A is a Trojan that only affects computers with Mac OS X operating system.

It modifies the DNSs (Domain Name System) of the computer so that they point to other malicious websites.
DNS is a name system that allows to translate from domain to IP address and viceversa.

For example, this would allow RxPlug.A to obtain confidential information through the data entered in the malicious websites.

RxPlug.A reaches the computer when downloading videos from certain websites for adults. In order to view these videos, a codec must be downloaded. However, what is really downloaded is not a codec but RxPlug.A.

Bear in mind that although this Trojan is designed for Mac OS X, the websites from which it is downloaded are able to recognize the operating system and browser of the affected computer and depending on them, different malware will be downloaded.

Visible Symptoms 

    

RxPlug.A is easy to recognize, as it reaches the computer when downloading videos from certain websites for adults.

In order to view these videos, a codec must be downloaded, and an image with a link is displayed in order to download the codec:

If the link is followed, the user must follow an installation process in which several screens are displayed, among them the one below:

And finally, user's authentication is requested in order to complete the installation:

However, what is really downloaded is not a codec but RxPlug.A.

 

The malicious websites are the following:

ispfiltporn.com
lan
orn.com
lin
orn.net
loo
orn.com
playha
ovie.com
pla
orn.com
pla
video.com
pla
xvideo.net
por
bc.com
por
bout.com
por
ontact.com
por
rive.net
por
lobal.net
por
go.net
por
group.net
por
elp.net
por
ssex.com
por
ame.net
por
arty.net
por
lay.net
por
lus.net
por
ower.net
por
oom.net
por
xfilm.com
relat
orn.net
see
porn.net
steph
orn.com
supera
ltfriend.com
thead
teye.com
tim
orn.net
us
orn.com
withp
stars.com
world
tadult.com

>