TROJ_CAPHAW.BO

 Analysis by: Michael Cabel

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW


This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It modifies Internet Explorer security settings. This puts the affected computer at greater risk, as it allows malicious URLs to be accessed by the computer.

It connects to certain URLs. It may do this to remotely inform a malicious user of its installation. It may also do this to download possibly malicious files onto the computer, which puts the computer at a greater risk of infection by other threats.

It deletes itself after execution.

  TECHNICAL DETAILS

File Size:

294,912 bytes

File Type:

EXE

Memory Resident:

No

Initial Samples Received Date:

03 Nov 2012

Arrival Details

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Web Browser Home Page and Search Page Modification

This Trojan modifies Internet Explorer zone settings.

Download Routine

This Trojan connects to the following malicious URLs:

  • {BLOCKED}.{BLOCKED}.83.48:80
  • {BLOCKED}.{BLOCKED}.119.138:443

Other Details

This Trojan deletes itself after execution.