Caphaw.A responsible for some recent Facebook attacks

  • 1 Replies

Offline ky331

  • Dell Community Colleague
  • Dell Support Group
  • Bronze Member
  • 376
  • Rascal & Biscuit
Caphaw.A responsible for some recent Facebook attacks
« on: November 17, 2011, 05:37:28 PM »
Backdoor:Win32/Caphaw.A is "a sophisticated firewall-bypassing backdoor armed with almost everything. It installs an FTP server, a proxy server, and a keylogger on the computer. It also has built-in remote desktop functionality based on the open source VNC project. We received a report that a user found this in his computer and also discovered that money had been transferred from his bank account by an unknown party. The keylogging component, coupled with the remote desktop functionality, makes it entirely possible for this to have happened.

The backdoor "calls home" to domains such as commonworld<removed>.cc or web<removed> to get the data that it posts on the friends' Facebook walls. Its main module, in the meantime, is hosted on <removed>

Full article:


Offline faith_michele

  • Anti - Phishing Staff
  • Gold Member
  • 1947
    • A Beacon of Light
Re: Caphaw.A responsible for some recent Facebook attacks
« Reply #1 on: November 18, 2011, 02:55:11 PM »
Thanks!  :)1
Microsoft Consumer Security MVP, July 2007-June 2010

"Fight your fights, find the grace in all the things that you can't change and help somebody, if you can." Van Zant

A Beacon of Light