Home / malwarePDF  

Backdoor:Win32/Caphaw.K


First posted on 02 October 2012.
Source: Microsoft

Aliases :

There are no other names known for Backdoor:Win32/Caphaw.K.

Explanation :



Backdoor:Win32/Caphaw.K is a trojan that allows unauthorized access and control of your computer.



Installation

Backdoor:Win32/Caphaw.K creates a new instance of "%WINDOWS%\svchost.exe" and injects itself into it. The trojan uses this code injection to run its code and to hinder detection and removal.

When run, the trojan creates a mutex that matches a random globally unique identifier (for example, "7CA7BF113BA3B73C45D937C0ECA3C59C3555316931"). It may do this to ensure that only one copy of the malware is running on your computer at any one time.



Payload

Allows backdoor access and control

Backdoor:Win32/Caphaw.K allows unauthorized access and control of an affected computer. An attacker can perform any number of different actions on an affected computer using the backdoor. This could include, but is not limited to, the following actions:

  • Download and execute arbitrary files
  • Upload files
  • Spread to other computers using various methods of propagation
  • Log keystrokes or steal sensitive data
  • Modify system settings
  • Run or terminate applications
  • Delete files


In order to receive commands, we have observed this trojan attempt to connect to various remote sites, including the following:

  • hxxps://online-upd.at/
  • hxxps://stat-servise.cc
  • hxxps://str-main.su




Analysis by Daniel Radu

Last update 02 October 2012

 

TOP