XProtect Update History
Because, why not? 🙂
Latest changes at the top, incomplete before 2016.
Data taken from the current OS version.
Work in progress, still collecting data.
2017 February 22
Version 2089
Malware signature added for:
• OSX.Findzip.A (better known as Patcher or Filecoder ransomware)
2017 February 17
Version 2088
Malware signatures added for:
• OSX.XAgent.A
• OSX.iKitten.A
• OSX.Proton.A
• OSX.Hmining.C
Extension blocked:
• com.searchnt.safari – Dev ID: 6ERPEMNB65
2016 November 16
Version 2086
Malware signatures added for:
• OSX.Hmining.B
2016 November 2
Version 2085
Minimum version of Flash Player changed from 23.0.0.185 to 23.0.0.205
2016 October 13
Version 2084
Malware signatures added for:
• OSX.Netwire.A
• OSX.Bundlore.B
Minimum version of Flash Player changed from 23.0.0.162 to 23.0.0.185
Minimum version of Flash Player ESR changed from 18.0.0.375 to 18.0.0.382
Extensions blocked:
• com.shelfsick.safari – Dev ID: 33HGJH7H8P
2016 September 17
Version 2082
Malware signatures added for:
• OSX.Netwire.A
• OSX.Bundlore.B
Minimum version of Flash Player changed from 22.0.0.192 to 23.0.0.162
Minimum version of Flash Player ESR changed from 18.0.0.360 to 18.0.0.375
Extensions blocked:
• com.shelfsick.safari – Dev ID: 6JM6T7HSQN
• com.searchnt.safari – Dev ID: LUZSN84HYP
2016 July 7
Version 2081
Malware signatures added for:
• OSX.Eleanor.A
• OSX.Hmining.A.2
2016 June 20
Version 2080
Minimum version of Flash Player changed from 21.0.0.242 to 22.0.0.192
Minimum version of Flash Player ESR changed from 18.0.0.352 to 18.0.0.360
Introduction of yara rules.
2016 May 16
Version 2079
Minimum version of Flash Player changed from 21.0.0.226 to 21.0.0.242
Minimum version of Flash Player ESR changed from 18.0.0.343 to 18.0.0.352
2016 April 28
Version 2078
Minimum version of Flash Player changed from 21.0.0.182 to 21.0.0.226
Minimum version of Flash Player ESR changed from 18.0.0.333 to 18.0.0.343
2016 March 24
Version 2077
Malware signatures added for:
• OSX.Trovi.A
• OSX.Hmining.A
• OSX.Bundlore.A
• OSX.Genieo.E
• OSX.InstallCore.A
Minimum version of Flash Player changed from 20.0.0.267 to 21.0.0.182
Minimum version of Flash Player ESR changed from 18.0.0.324 to 18.0.0.333
Extensions blocked:
• com.searchtrust.safariext – Dev ID: 9V6HEQPZK3
• com.leperdvil.safari – Dev ID: Y7QR7RXE99
• info.trovi – Dev ID: 2GLUU75QJH
• info.searchquick – Dev ID: 2GLUU75QJH
2016 March 5
Version 2076
Malware signatures added for:
• OSX.KeRanger.A
2016 February 9
Version 2075
Malware signatures added for:
• OSX.CrossRider.A
• OSX.GenieoDropper.A
Extensions blocked:
• com.searchnt.safari – Dev ID: 4VNW4T5764
• com.spigot.safari.searchme – Dev ID: B652554955
• com.spigot.safari.ebayshopassist – Dev ID: B652554955
• com.smokycap.safari – Dev ID: JSKF7A7MSD
• com.searchconnect.safariext – Dev ID: 97VW76A9RY
2016 January 15
Version 2073
Minimum version of Silverlight set to 5.1.41212.0
2016 January 5
Version 2072
Minimum version of Flash Player changed from 20.0.0.235 to 20.0.0.267
Minimum version of Flash Player ESR changed from 18.0.0.268 to 18.0.0.324
2015 December 16
Version 2071
Minimum version of Flash Player changed from 19.0.0.226 to 20.0.0.235
Minimum version of Flash Player ESR changed from 18.0.0.255 to 18.0.0.268
Malware signature added for:
• OSX.InstallImitator.D
2015 October 19
Version 2070
Minimum version of Flash Player changed from 18.0.0.232 to 19.0.0.226
Minimum version of Flash Player ESR changed from 18.0.0.232 to 18.0.0.255
Extensions blocked:
• com.codec.extension – Dev ID: 9FHEC8C8B8
• com.zako.chatzum – Dev ID: 87X4MN23Z9
• com.adobe.flash – Dev ID: E728F995AB
• com.optimalcycling.safari.popupblocker – Dev ID: 6AR4TE4Z39
• com.genieo.safari – Dev ID: K444F5Z2ZH
• com.app65867 – Dev ID: T5PTSKMRT6
• com.defaultsearch.safariext – Dev ID: 544JR7KQT8
• com.jbsearch.safariext – Dev ID: NRQCQ6DVMZ
• com.mtsearch.safariext – Dev ID: HL68H687N8
• com.rohit.MacMInSale – Dev ID: 42F2G9DQ47
• com.tabgreg.safariext – Dev ID: LNWBP677VB
• com.gold.safari – Dev ID: NHEDAZU9T4
• com.eliaho.safari – Dev ID: 6JM6T7HSQN
• com.nariabox.safari – Dev ID: DXBF7F94N3
• com.diigo.safari.awesomeScreenshot – Dev ID: 5DXNM3K2CT
• com.portsayd.safari – Dev ID: YZG972RG8Z
2015 September 25
Version 2068
Minimum version of Flash Player changed from 18.0.0.209 to 18.0.0.232
Minimum version of Flash Player ESR changed from 13.0.0.305 to 18.0.0.232
Malware signatures added for:
• OSX.XcodeGhost.A
• OSX.Genieo.D
• OSX.Genieo.C
2015 August 5
Version 2066
Malware signatures added for:
• OSX.Genieo.B
• OSX.InstallImitator.C
2015 July 17
Version 2065
Minimum version of Flash Player changed from 17.0.0.188 to 18.0.0.209
Minimum version of Flash Player ESR changed from 13.0.0.289 to 13.0.0.305
Minimum version of Java changed from 1.7.25.15 to 1.8.51.16
2015 May 28
Version 2061
Minimum version of Flash Player changed from 17.0.0.169 to 17.0.0.188
Minimum version of Flash Player ESR changed from 13.0.0.281 to 13.0.0.289
2015 April 22
Version 2060
Minimum version of Flash Player changed from 17.0.0.134 to 17.0.0.169
Minimum version of Flash Player ESR changed from 13.0.0.277 to 13.0.0.281