{"id":17895,"date":"2013-09-17T11:04:10","date_gmt":"2013-09-17T18:04:10","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=17895"},"modified":"2016-10-07T12:19:56","modified_gmt":"2016-10-07T19:19:56","slug":"new-mac-trojan-discovered-related-to-syria","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/","title":{"rendered":"New Mac Trojan Discovered Related to Syria"},"content":{"rendered":"<p>A new Mac Trojan has been discovered that creates a backdoor on an affected user\u2019s machine. It was found on VirusTotal, sent by a user in Belarus. At the time of writing, the Command and Control (C&amp;C) server is down and no longer sending commands to affected users. This appears to be a targeted attack, though the method of delivery is not yet known. So, while this has been affecting users in the wild, the overall threat level appears to be low.<\/p>\n<p>The Trojan is an application that is disguised as a picture \u2013 the .app file-extension is not visible by default.<\/p>\n<p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/Leverage.png\"><img loading=\"lazy\" class=\"aligncenter size-full wp-image-17899\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/Leverage.png\" alt=\"Leverage\" width=\"142\" height=\"149\" \/><\/a><\/p>\n<p>At this time, we are unaware how it is sent to affected users. The malware could likely be sent by email or placed on a website as part of a watering hole attack, for instance. Depending on how the file is received, the behavior of the file in OS X may be slightly different.<\/p>\n<p>In some cases, there will only be an alert from Gatekeeper if the user clicks on the application if it came from a download with a quarantine bit set. There are several ways of downloading a file that would set the quarantine bit; for example, apps downloaded from the browser or an email client. Apps from other sources, such as file servers, external drives, or optical discs will not set the quarantine bit, unless the apps were originally downloaded from the Internet and had the quarantine bit set at that time.<\/p>\n<p>When run, the Trojan copies itself to <b>\/Users\/Shared\/UserEvent.app<\/b><\/p>\n<p><b>MD5<\/b>\u00a0\u00a0\u00a0 6a36379b1da8919c1462f62deee666be<\/p>\n<p><b>SHA-1<\/b> 40b34e91cde683a567974750d1c5c9bcb09a87bb<\/p>\n<p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/UserEvent.png\"><img loading=\"lazy\" class=\"aligncenter size-full wp-image-17901\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/UserEvent.png\" alt=\"UserEvent\" width=\"315\" height=\"167\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/UserEvent.png 315w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/UserEvent-150x79.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/UserEvent-300x159.png 300w\" sizes=\"(max-width: 315px) 100vw, 315px\" \/><\/a><\/p>\n<p>It also creates a LaunchAgent in <b>~\/Library\/LaunchAgents\/UserEvent.System.plist<\/b> to launch the application <b>\/Users\/Shared\/UserEvent.app<\/b><\/p>\n<p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/LaunchAgents.png\"><img loading=\"lazy\" class=\"aligncenter size-full wp-image-17903\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/LaunchAgents.png\" alt=\"LaunchAgents\" width=\"313\" height=\"152\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/LaunchAgents.png 313w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/LaunchAgents-150x72.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/LaunchAgents-300x145.png 300w\" sizes=\"(max-width: 313px) 100vw, 313px\" \/><\/a><\/p>\n<p>The Mac Trojan hides itself from the Dock and Cmd-Tab Application switching.\u00a0It then opens the JPEG image inside the Application bundle with the standard OS X application Preview, which fools the user into thinking that it was just an image file.<\/p>\n<p>Once it\u2019s installed, the Trojan connects to the C&amp;C server on port 7777.<\/p>\n<p>The Trojan application installs a permanent backdoor that allows the attacker to send a variety of commands. In testing, we observed the C&amp;C receiving a variety of system information about the affected machine, sending Pings to monitor the connection, and trying to download the following image file to the machine, among other commands.<\/p>\n<p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/syrian-electronic-army.jpeg\"><img loading=\"lazy\" class=\"aligncenter size-full wp-image-17919\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/syrian-electronic-army.jpeg\" alt=\"syrian electronic army logo\" width=\"460\" height=\"276\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/syrian-electronic-army.jpeg 460w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/syrian-electronic-army-150x90.jpeg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/09\/syrian-electronic-army-300x180.jpeg 300w\" sizes=\"(max-width: 460px) 100vw, 460px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.intego.com\/virusbarrier\" target=\"_blank\">Intego VirusBarrier<\/a> with current virus definitions protects Mac users against this malware, detected as <strong>OSX\/Leverage.A<\/strong>. While this is known to be affecting users, this is considered to be a low-risk threat at this time, as it appears to be a targeted attack. This rating may be changed as more information comes to light. If possible, it\u2019s advised that users keep all their software, particularly operating system, browsers and browser plugins (such as Flash and Java if applicable) up to date as exploits are common ways for such attacks to spread.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new Mac Trojan has been discovered that creates a backdoor on an affected user\u2019s machine. It was found on VirusTotal, sent by a user in Belarus. At the time of writing, the Command and Control (C&amp;C) server is down and no longer sending commands to affected users. This appears to be a targeted attack, [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":8755,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[190,5],"tags":[30,174,86,635,637,132],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"A new Mac Trojan has been discovered that creates a backdoor on an affected user\u2019s machine. It was found on VirusTotal, sent by a user in Belarus. At the\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Mac Trojan Discovered Related to Syria - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"A new Mac Trojan has been discovered that creates a backdoor on an affected user\u2019s machine. It was found on VirusTotal, sent by a user in Belarus. At the\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2013-09-17T18:04:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-10-07T19:19:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lysa Myers\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png\",\"width\":\"400\",\"height\":\"260\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/\",\"name\":\"New Mac Trojan Discovered Related to Syria - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#primaryimage\"},\"datePublished\":\"2013-09-17T18:04:10+00:00\",\"dateModified\":\"2016-10-07T19:19:56+00:00\",\"description\":\"A new Mac Trojan has been discovered that creates a backdoor on an affected user\\u2019s machine. It was found on VirusTotal, sent by a user in Belarus. At the\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New Mac Trojan Discovered Related to Syria\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a\"},\"headline\":\"New Mac Trojan Discovered Related to Syria\",\"datePublished\":\"2013-09-17T18:04:10+00:00\",\"dateModified\":\"2016-10-07T19:19:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#webpage\"},\"wordCount\":510,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png\",\"keywords\":[\"Backdoor\",\"Mac\",\"Malware\",\"OSX\/Leverage.A\",\"Syria\",\"Trojan Horse\"],\"articleSection\":[\"Malware\",\"Security News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a\",\"name\":\"Lysa Myers\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g\",\"caption\":\"Lysa Myers\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"A new Mac Trojan has been discovered that creates a backdoor on an affected user\u2019s machine. It was found on VirusTotal, sent by a user in Belarus. At the","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/","og_locale":"en_US","og_type":"article","og_title":"New Mac Trojan Discovered Related to Syria - The Mac Security Blog","og_description":"A new Mac Trojan has been discovered that creates a backdoor on an affected user\u2019s machine. It was found on VirusTotal, sent by a user in Belarus. At the","og_url":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/","og_site_name":"The Mac Security Blog","article_published_time":"2013-09-17T18:04:10+00:00","article_modified_time":"2016-10-07T19:19:56+00:00","og_image":[{"width":"400","height":"260","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Lysa Myers","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","width":"400","height":"260"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/","name":"New Mac Trojan Discovered Related to Syria - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#primaryimage"},"datePublished":"2013-09-17T18:04:10+00:00","dateModified":"2016-10-07T19:19:56+00:00","description":"A new Mac Trojan has been discovered that creates a backdoor on an affected user\u2019s machine. It was found on VirusTotal, sent by a user in Belarus. At the","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"New Mac Trojan Discovered Related to Syria"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a"},"headline":"New Mac Trojan Discovered Related to Syria","datePublished":"2013-09-17T18:04:10+00:00","dateModified":"2016-10-07T19:19:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#webpage"},"wordCount":510,"commentCount":2,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","keywords":["Backdoor","Mac","Malware","OSX\/Leverage.A","Syria","Trojan Horse"],"articleSection":["Malware","Security News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/new-mac-trojan-discovered-related-to-syria\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a","name":"Lysa Myers","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g","caption":"Lysa Myers"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2012\/12\/MalwareAlert.png","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-4ED","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/17895"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=17895"}],"version-history":[{"count":15,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/17895\/revisions"}],"predecessor-version":[{"id":58192,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/17895\/revisions\/58192"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/8755"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=17895"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=17895"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=17895"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}