How can this Trojan horse propagate?
This Trojan horse can propagate in several ways: if a user downloads the file from the Internet, a server or a web site, it must be compressed in one way or another. This could be zip compression, if created from the Mac OS X 10.3 Finder, or Stuffit compression. This compression is necessary because the Trojan horse contains resources, which are stripped if it is downloaded without being compressed. This Trojan horse could also be encoded using binhex encoding, which maintains the resource fork as well. If the file is not compressed or encoded, it can be transferred across a local network between Macs, or even downloaded from a user's iDisk.
If a user sends this file to someone else by e-mail, unaware that it contains a Trojan horse, there are possibilities that it will be received intact. Apple's Mail, and Microsoft's Entourage, for example, encode this file using binhex by default, which transmits the resources that are required for this Trojan horse to function.
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?