That would be a negative. I've tried this and others with the latest build on 10.13.4 and it's not resolving. The only other issue causing might be the enduser has filevault enabled on the Macbook in question. I tried this as "root" (I know, I know) and still didn't elevate or address this issue. Gatekeeper isn't showing the "allow MW to do xyz", either.
I contacted Simon at Obdev (Little Snitch) and asked about his opinion on this. He suggested adding these rules to block against the DNS servers being installed. " thank you for letting us know about this. I will dig somehow deeper into this issue, but after a brief look I can state the following: This malware called OSX/MaMi is an unsigned Mach-O 64-bit executable - that means, macOS will warn you when you run this executable and Little Snitch will warn you in case this unsigned process wants to make any network connections. Still - the tricky part come