<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>premieropinion-spyware &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/premieropinion-spyware/</link>
	<description>Feed of posts on WordPress.com tagged "premieropinion-spyware"</description>
	<pubDate>Wed, 19 Jun 2013 22:52:05 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA["PremierOpinion" Spyware Now in Mac OS X]]></title>
<link>http://ithreats.net/2010/06/02/premieropinion-spyware-now-in-mac-os-x/</link>
<pubDate>Wed, 02 Jun 2010 04:05:59 +0000</pubDate>
<dc:creator>Methusela Cebrian Ferrer</dc:creator>
<guid>http://ithreats.net/2010/06/02/premieropinion-spyware-now-in-mac-os-x/</guid>
<description><![CDATA[From Intego security advisory today: &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;]]></description>
<content:encoded><![CDATA[<p><a href="http://ithreats.files.wordpress.com/2010/06/osx-spyware-premier-opinion-installation0.png"><img class="size-full wp-image-1085 alignnone" title="OSX Spyware &#34;Premier Opinion&#34; Installation0" src="http://ithreats.files.wordpress.com/2010/06/osx-spyware-premier-opinion-installation0.png?w=524&#038;h=327" alt="" width="524" height="327" /></a></p>
<p><em><strong>From Intego security advisory today: </strong></em></p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p><strong>Malware</strong>: OSX/OpinionSpy</p>
<p><strong>Risk</strong>: High</p>
<p><strong>Description</strong>: Intego has discovered a spyware application that is installed by a number of freely distributed Mac applications and<strong><em> screen savers found on a variety of websites</em></strong>.</p>
<div>OSX/OpinionSpy is installed by a number of applications and screen savers that are distributed on sites such as <strong>MacUpdate</strong>, <strong>VersionTracker</strong> and <strong>Softpedia</strong>.</div>
<div>Details: <a href="http://www.intego.com/news/osx-opinionspy-spyware-installed-by-freely-distributed-mac-applications.asp" target="_blank"><br />
http://www.intego.com/news/osx-opinionspy-spyware-installed-by-freely-distributed-mac-applications.asp<br />
</a></div>
<div>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</div>
<div>
<p>Who&#8217;s PremierOpinion?</p>
<p>PremierOpinion is part of an <strong><em>online market research community </em></strong>with over 2 million members worldwide. PremierOpinion <em>relies</em> on its members to <em>gain valuable</em> insight into <em>Internet trends</em> and <em>behavior</em>. In exchange for participating in periodic surveys on topics of interest to the Internet community, and for having<strong><em> their Internet browsing and purchasing activity monitored</em></strong>, PremierOpinion <em>sponsors</em> select <em>software</em> that its members can enjoy for <strong>free</strong>.</p>
<p>Website: <a href="http://www.premieropinion.com/Home.aspx" rel="nofollow">http://www.premieropinion.com/Home.aspx</a></p>
<p>So, who&#8217;s the partner?</p>
<p>&#8220;PremierOpinion&#8221; Mac OS X Spyware are distributed by 7art-screensavers and published in this link: <a href="http://7art-screensavers.com/Mac_OS_X.shtml" rel="nofollow">http://7art-screensavers.com/Mac_OS_X.shtml</a></p>
<p>Intego blog published detailed list of &#8220;PremierOpinion&#8221; Mac OS X Spyware.[<a href="http://blog.intego.com/2010/06/01/preliminary-list-of-applications-that-install-osxopinionspy-spyware/">here</a>]</p>
<p>There are 48 screensaver Mac OS X apps in this source, and there are two different packages.</p>
</div>
<div><a href="http://ithreats.files.wordpress.com/2010/06/two-packages.png"><img class="aligncenter size-full wp-image-1086" title="two packages" src="http://ithreats.files.wordpress.com/2010/06/two-packages.png?w=284&#038;h=126" alt="" width="284" height="126" /></a></div>
<div>
<p>How to spot &#8220;PremierOpinion&#8221; Mac OS X Spyware?</p>
<p>1. It uses <strong>IzPack </strong>&#8220;Package once. Deploy everywhere.&#8221; software installer generator. You&#8217;ll notice from a package inspection (press control+click on the application and from the pop-up menu choose<em> ‘Show Package Contents’), </em>the <strong><em>icons are different</em></strong> &#8211; <strong><em>7art</em></strong> while the other <strong><em>izpack.icns</em></strong>.</p>
</div>
<div><a style="text-decoration:none;" href="http://ithreats.files.wordpress.com/2010/06/izpack-vs-7art.png"><img class="aligncenter size-full wp-image-1087" title="izpack vs 7art" src="http://ithreats.files.wordpress.com/2010/06/izpack-vs-7art.png?w=600&#038;h=425" alt="" width="600" height="425" /></a></div>
<div>
<p>2. IzPack generated installers are in Java Archive (.<strong>JAR</strong>) file.</p>
<p>3. 7art screen savers installation do <strong>NOT</strong> require root password. While, PremierOpinion sponsored <strong>free </strong>software or application <strong>requires</strong> root password. Why? Because it installs spyware, which will track and monitor users&#8217; browsing behaviour, scans and gather information from the disk and sends back to its remote server. This is very <em>persistent</em> spyware, meaning it does <em>NOT want to be uninstalled</em>.</p>
</div>
<div><a href="http://ithreats.files.wordpress.com/2010/06/osx-spyware-premier-opinion-installation0.png"><img title="OSX Spyware &#34;Premier Opinion&#34; Installation0" src="http://ithreats.files.wordpress.com/2010/06/osx-spyware-premier-opinion-installation0.png?w=524&#038;h=327" alt="" width="524" height="327" /></a></div>
<div>
<p>4. Spyware installs software without user&#8217;s consent or notification.   It is often bundled with other clean application to misleads users of its true purpose and gain access to users&#8217; system. So, in this case, if you click &#8220;Cancel&#8221;, the IzPack installer will still continue by two pop-up screen: 1) PremierOpinion survey (<a href="http://ithreats.files.wordpress.com/2010/06/premieropinionsurvey.png">screenshot</a>) 2) 7art screen saver installation (<a href="http://ithreats.files.wordpress.com/2010/06/7artinstall.png">screenshot</a>).</p>
<p>&#8220;Package once. Deploy everywhere.&#8221;</p>
<p>This sneaky Mac OS X threat could be everywhere bundled and distributed in the internet.</p>
<p>Be cautious and stay safe!</p>
<p>&#8212;&#8212;&#8211;&#62; Threat Info FYI</p>
<p>File Name: poinstaller</p>
<p>File Type: Mach-O executable i386</p>
<p>File Size: 470,352 bytes</p>
<p>Threat Type: Backdoor, Downloader, Sniffer, Stealer,</p>
<p>Installation Requirement:  root</p>
<p>Remote Activity: Installation of other threats</p>
<p><a href="http://ithreats.files.wordpress.com/2010/06/ida-code-poinstaller.png"><img class="aligncenter size-full wp-image-1101" title="IDA code poinstaller" src="http://ithreats.files.wordpress.com/2010/06/ida-code-poinstaller.png?w=600&#038;h=124" alt="" width="600" height="124" /></a></p>
<p>Remote Download File: Rule14.xml</p>
<p><img class="aligncenter size-full wp-image-1102" title="rule14 xml" src="http://ithreats.files.wordpress.com/2010/06/rule14-xml.png?w=600&#038;h=213" alt="" width="600" height="213" />Remote Download: PermissionResearch.zip</p>
<p>Installation: RunPermissionResearch.sh</p>
<p><a href="http://ithreats.files.wordpress.com/2010/06/runpermissionresearch-sh.png"><img class="aligncenter size-full wp-image-1103" title="RunPermissionResearch sh" src="http://ithreats.files.wordpress.com/2010/06/runpermissionresearch-sh.png?w=600&#038;h=163" alt="" width="600" height="163" /></a>Package Name: PermissionResearch.app</p>
<p><a href="http://ithreats.files.wordpress.com/2010/06/permissionresearch-app.png"><img class="aligncenter size-full wp-image-1104" title="PermissionResearch app" src="http://ithreats.files.wordpress.com/2010/06/permissionresearch-app.png?w=600&#038;h=414" alt="" width="600" height="414" /></a>File Name: PermissionResearch</p>
<p>File Type: Mach-O executable i386</p>
<div>File Size: 4.1 MB</div>
<div></div>
<div>Resource Package Name: InjectCode.app</div>
<div></div>
</div>
<div><a href="http://ithreats.files.wordpress.com/2010/06/injectcode-app.png"><img class="aligncenter size-full wp-image-1105" title="InjectCode app" src="http://ithreats.files.wordpress.com/2010/06/injectcode-app.png?w=395&#038;h=758" alt="" width="395" height="758" /></a></div>
<div>File Name: InjectCode</div>
<div>File Type:</div>
<div>
<div id="_mcePaste">Mach-O executable i386</div>
</div>
<div>
<div>Mach-O 64-bit executable x86_64</div>
</div>
<div>File Size: 34,088 bytes</div>
<div>Resource Package Name: macmeterhk.bundle</div>
<div><a href="http://ithreats.files.wordpress.com/2010/06/macmeterhk-bundle.png"><img class="aligncenter size-full wp-image-1106" title="macmeterhk bundle" src="http://ithreats.files.wordpress.com/2010/06/macmeterhk-bundle.png?w=482&#038;h=155" alt="" width="482" height="155" /></a>File Name: macmeterhk</div>
<div>
<div>File Type:</div>
<div>
<div id="_mcePaste">Mach-O executable i386</div>
</div>
<div>
<div>Mach-O 64-bit executable x86_64</div>
</div>
<div>File Size:  894,836 bytes</div>
</div>
]]></content:encoded>
</item>

</channel>
</rss>
