Cabrotor

Classification

Malware

-

-

Cabrotor, Backdoor.Cabrotor.10.a, Cabronator

Summary

Cabrotor is backdoor, allowing an attacker to control the machine where it runs. The trojan itself is a Windows PE EXE file written in Delphi.

Removal

Automatic action

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

Find out more

Knowledge Base

Find the latest advice in our Community Knowledge Base.

User Guide

See the user guide for your product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

The original trojan package contains three main executable files:

CaBrONaToR.exe - client to send commands to remote server
CaBrONeDiT.exe - server editor to modify default server settings
8======D.exe - server (trojan itself)
 

When run, the backdoor code copies itself to the Windows directory and registers itself in the system registry in the auto-run section. In different backdoor versions the backdoor EXE name and registry keys are different. The known variant has:

Executable name:

ASDAPI.EXE
 

The registry key entries it creates are located in:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
[HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices]
 

And their names are:

LoadPowerProfile
 

The trojan then opens a connection to its master's IRC channel and waits for its master's commands.

The backdoor allows the attacker to invoke any of the following commands:

Reports computer information (Windows version, CPU type, UserName, CompanyName)
Open/closes CD drive
Reports directories and file names
Runs a local file or command
Send information: RAS, MS Messenger and .NET services
Exits Windows
Downloads a requested file
Performs DoS attack to a requested victim address
Terminates itself
 

Date Created: -

Date Last Modified: -