TROJ_CAPHAW.BO
Windows 2000, Windows XP, Windows Server 2003


Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It modifies Internet Explorer security settings. This puts the affected computer at greater risk, as it allows malicious URLs to be accessed by the computer.
It connects to certain URLs. It may do this to remotely inform a malicious user of its installation. It may also do this to download possibly malicious files onto the computer, which puts the computer at a greater risk of infection by other threats.
It deletes itself after execution.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Web Browser Home Page and Search Page Modification
This Trojan modifies Internet Explorer zone settings.
Download Routine
This Trojan connects to the following malicious URLs:
- {BLOCKED}.{BLOCKED}.83.48:80
- {BLOCKED}.{BLOCKED}.119.138:443
Other Details
This Trojan deletes itself after execution.
