Skip to main content

Cabrotor

Classification

Category:

Malware

Aliases:

  • Cabrotor
  • Backdoor.Cabrotor.10.a
  • Cabronator

Summary

Cabrotor is backdoor, allowing an attacker to control the machine where it runs. The trojan itself is a Windows PE EXE file written in Delphi.

Removal

Technical Details

The original trojan package contains three main executable files:

CaBrONaToR.exe - client to send commands to remote server CaBrONeDiT.exe - server editor to modify default server settings 8======D.exe - server (trojan itself)

When run, the backdoor code copies itself to the Windows directory and registers itself in the system registry in the auto-run section. In different backdoor versions the backdoor EXE name and registry keys are different. The known variant has:

Executable name:

ASDAPI.EXE

The registry key entries it creates are located in:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] [HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices]

And their names are:

LoadPowerProfile

The trojan then opens a connection to its master's IRC channel and waits for its master's commands.

The backdoor allows the attacker to invoke any of the following commands:

Reports computer information (Windows version, CPU type, UserName, CompanyName) Open/closes CD drive Reports directories and file names Runs a local file or command Send information: RAS, MS Messenger and .NET services Exits Windows Downloads a requested file Performs DoS attack to a requested victim address Terminates itself

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.