OSX/AceInstaller appears to be a Trojaned or bundled installer distributed with torrent downloads [1]. However, there is little publicly available information about this threat at this time. Researching the Yara rule, a matching file appears to have been uploaded and analyzed by malwr.com. The sample contains additional strings that indicate its ability to masquerade as an Adobe Flash Installer, likely as a form of Adware [2]. While the hash associated with the malwr.com analysis [2] is not currently found in VirusTotal, the hash associated a second sample at malwr.com [3] is detected by many AV products as a variant of OSX/Genieo.
9e3bb13fc0148ae2ac965b0b41588455 |
e2c5c5813f003e914456820a8771021a |