Home Malware Programs Potentially Unwanted Programs (PUPs) Cacaoweb

Cacaoweb

Posted: March 27, 2013

Threat Metric

Ranking: 2,527
Threat Level: 1/10
Infected PCs: 162,216
First Seen: March 27, 2013
Last Seen: October 16, 2023
OS(es) Affected: Windows

Cacaoweb markets itself as an alternative to popular torrent clients, but also exhibits some of the characteristics that malware experts often associate with botnet-based backdoor Trojans. Users of this supposedly legitimate product have reported worsened browser performance and other side effects, despite Cacaoweb's company's claim that Cacaoweb is a 'lightweight' program. For the time being, malware experts consider Cacaoweb to fall into the classification of a Potentially Unwanted Program, and you should consider the benefits of deleting Cacaoweb via reliable security software.

Why Finding Files may Find You Trouble, Too

The prominence of the torrent as the ascendant replacement of other file-sharing methods has not gone unnoticed by most software developers, but the company responsible for Cacaoweb seems to have added some 'extra' functions. Cacaoweb is not guilty of completely false advertising, and does provide functions for finding files online. However, its claims of bypassing cloud storage advertisements and other 'interruptions' in download content have yet to solidify, and malware experts also have noted some additional, troubling features.

The latter include:

  • Interrupted Internet connectivity.
  • Slow Web-browsing performance.
  • Automatic bandwidth usage for purposes not specified by Cacaoweb's user.

These issues sometimes are symptomatic of a Trojan that uses its network connection to force your PC to perform illegal actions 'behind the scenes,' such as crashing websites with fake traffic (also known as a DDoS attack). Bredolab, Conficker and Sality are examples of Trojans that include botnet features, and Cacaoweb may be a new member of this list. As a result, many PC security companies categorize Cacaoweb as a backdoor Trojan, although malware experts must rate Cacaoweb as a PUP until they can verify additional evidence.

Taking the Web Back from Cacaoweb

False detections of Trojans have been known to happen, but whenever a Trojan detection is accompanied by an unusual symptom, as with Cacaoweb, you should consider the situation with all due caution. Depending on your updated anti-malware programs to determine between safe and unsafe programs always is the best approach. As a side note, malware experts also might mention that using products designed to perform questionable acts, such as Cacaoweb's alleged propensity for circumventing the restrictions on file-sharing sites, may be an easy way to compromise your PC with threats.

Assuming you've removed Cacaoweb promptly and through proper tools, there shouldn't be any long-term damage to your PC from its temporary presence. Fortunately, botnet Trojans may focus their attacks on external targets. However, any Trojan with backdoor functions also has the potential for attacks directed against your computer, which is why exercising a heavy degree of paranoia is prudent. Cacaoweb may include compatibility with most operating systems, including Windows, Linux and OS X.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\Downloads\cacaoweb.exe File name: cacaoweb.exe
Size: 471.55 KB (471552 bytes)
MD5: 90d787a2df45b1e82c276dfd1a91ae61
Detection count: 8,879
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Downloads\cacaoweb.exe
Group: Malware file
Last Updated: October 2, 2023
C:\Users\<username>\Downloads\cacaoweb.exe File name: cacaoweb.exe
Size: 469.5 KB (469504 bytes)
MD5: 6aabcab9ff3ffb26ef173153b765483d
Detection count: 5,295
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Downloads\cacaoweb.exe
Group: Malware file
Last Updated: December 13, 2022
%SYSTEMDRIVE%\Users\<username>\Documents\progs\cacaoweb.exe File name: cacaoweb.exe
Size: 452.6 KB (452608 bytes)
MD5: 5a0ea36a22384ca00ab57603349386d3
Detection count: 5,211
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\Documents\progs\cacaoweb.exe
Group: Malware file
Last Updated: December 13, 2022
C:\Qoobox\Quarantine\C\Users\<username>\AppData\Roaming\cacaoweb\cacaoweb.exe.vir File name: cacaoweb.exe.vir
Size: 457.72 KB (457728 bytes)
MD5: 98d472ec7b867c1cfeb1916ce3fa165b
Detection count: 4,712
Mime Type: unknown/vir
Path: C:\Qoobox\Quarantine\C\Users\<username>\AppData\Roaming\cacaoweb\cacaoweb.exe.vir
Group: Malware file
Last Updated: October 4, 2022
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\cacaoweb\cacaoweb.exe File name: cacaoweb.exe
Size: 451.07 KB (451072 bytes)
MD5: dcbae6e09552effca9b78b5184d49d12
Detection count: 3,998
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming\cacaoweb\cacaoweb.exe
Group: Malware file
Last Updated: October 5, 2023
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonewd4be07.exe File name: cacaonewd4be07.exe
Size: 435.71 KB (435712 bytes)
MD5: be7f0b75275270688088e8956f02ee5d
Detection count: 3,841
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonewd4be07.exe
Group: Malware file
Last Updated: June 8, 2023
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew153105.exe File name: cacaonew153105.exe
Size: 436.22 KB (436224 bytes)
MD5: 7a93e7d6377640a2338438d1c51e2d3e
Detection count: 3,712
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew153105.exe
Group: Malware file
Last Updated: April 3, 2022
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew5cf2c7.exe File name: cacaonew5cf2c7.exe
Size: 436.22 KB (436224 bytes)
MD5: 9507d099d63307e9897d7e98373ee3a2
Detection count: 3,586
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew5cf2c7.exe
Group: Malware file
Last Updated: June 8, 2023
%SYSTEMDRIVE%\AdwCleaner\Quarantine\files\zjnctabcipcmhbxrdgaxmmrfuwwuhlvr.back File name: zjnctabcipcmhbxrdgaxmmrfuwwuhlvr.back
Size: 452.6 KB (452608 bytes)
MD5: e0d50b1d0fb4b71d7de0ece999c69028
Detection count: 3,141
Mime Type: unknown/back
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\files\zjnctabcipcmhbxrdgaxmmrfuwwuhlvr.back
Group: Malware file
Last Updated: June 4, 2023
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew6cc4a7.exe File name: cacaonew6cc4a7.exe
Size: 436.73 KB (436736 bytes)
MD5: ac782786780cbd9a72fe0cac0ee28107
Detection count: 2,536
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew6cc4a7.exe
Group: Malware file
Last Updated: September 24, 2023
C:\RECYCLER\S-1-5-21-1343024091-1563985344-1177238915-500\Dc53.exe File name: Dc53.exe
Size: 452.6 KB (452608 bytes)
MD5: 20606d3a237e8907128a18e4ba080f19
Detection count: 1,806
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-1343024091-1563985344-1177238915-500\Dc53.exe
Group: Malware file
Last Updated: August 14, 2023
C:\cacaoweb\cacaoweb.exe File name: cacaoweb.exe
Size: 452.6 KB (452608 bytes)
MD5: 7a28500b46d35119fd01376800cade64
Detection count: 1,557
File type: Executable File
Mime Type: unknown/exe
Path: C:\cacaoweb\cacaoweb.exe
Group: Malware file
Last Updated: September 1, 2022
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew7b3d3e.exe File name: cacaonew7b3d3e.exe
Size: 435.71 KB (435712 bytes)
MD5: 2ccaf6b7b990892fb66702b9c34d058f
Detection count: 1,422
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew7b3d3e.exe
Group: Malware file
Last Updated: June 8, 2023
C:\Users\<username>\Documents\HD\Pastas\Documents\Dados HD\Usuarios\Hewerton\AppData\Local\Temp\cacaonewab8e8a.exe File name: cacaonewab8e8a.exe
Size: 433.15 KB (433152 bytes)
MD5: 2649eeb4f590742c0c6234dd90538dd9
Detection count: 1,157
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Documents\HD\Pastas\Documents\Dados HD\Usuarios\Hewerton\AppData\Local\Temp\cacaonewab8e8a.exe
Group: Malware file
Last Updated: June 8, 2023
%APPDATA%\cacaoweb\cacaoweb.exe File name: cacaoweb.exe
Size: 438.27 KB (438272 bytes)
MD5: 370ef064e925fdf111badb6445648944
Detection count: 953
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\cacaoweb
Group: Malware file
Last Updated: January 24, 2023
C:\$RECYCLE.BIN\S-1-5-21-1922062534-1032020396-3115903374-1002\$R27TEPA.exe File name: $R27TEPA.exe
Size: 451.58 KB (451584 bytes)
MD5: 0374234b527f4a41593e073e7d8be800
Detection count: 597
File type: Executable File
Mime Type: unknown/exe
Path: C:\$RECYCLE.BIN\S-1-5-21-1922062534-1032020396-3115903374-1002\$R27TEPA.exe
Group: Malware file
Last Updated: March 26, 2022
C:\Users\<username>\AppData\Roaming\cacaoweb\cacaoweb.exe File name: cacaoweb.exe
Size: 469.5 KB (469504 bytes)
MD5: c5213a4409d96dca7db4ad093f216bcf
Detection count: 541
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\cacaoweb\cacaoweb.exe
Group: Malware file
Last Updated: March 11, 2022
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew21cad0.exe File name: cacaonew21cad0.exe
Size: 427 KB (427008 bytes)
MD5: 6d04c21c0356e798b5f2f76300c2e6af
Detection count: 443
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew21cad0.exe
Group: Malware file
Last Updated: October 24, 2022
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew749423.exe File name: cacaonew749423.exe
Size: 436.73 KB (436736 bytes)
MD5: 30db0ee7c0af7172359dc678545a90da
Detection count: 173
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew749423.exe
Group: Malware file
Last Updated: April 2, 2022
%PROGRAMFILES%\cacaoweb\cacaoweb.exe File name: cacaoweb.exe
Size: 454.65 KB (454656 bytes)
MD5: d983e39a4a32033b418ab5cac342a0ce
Detection count: 136
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\cacaoweb
Group: Malware file
Last Updated: April 25, 2020
%SystemDrive%\Users\<username>\AppData\Roaming\cacaoweb\cacaoweb.exe File name: cacaoweb.exe
Size: 451.58 KB (451584 bytes)
MD5: b58159a51b1f9e80790f798773461b8a
Detection count: 119
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming\cacaoweb
Group: Malware file
Last Updated: September 15, 2022
%APPDATA%\cacaoweb\cacaoweb.exe File name: cacaoweb.exe
Size: 450.56 KB (450560 bytes)
MD5: 594abb76543198abda41ce3dd592ba19
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\cacaoweb
Group: Malware file
Last Updated: March 7, 2014
%APPDATA%\cacaoweb\cacaoweb.exe File name: cacaoweb.exe
Size: 433.15 KB (433152 bytes)
MD5: 08b12911beb6164a3985f90bc8869c78
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\cacaoweb
Group: Malware file
Last Updated: March 7, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\cacaowebSoftware\Microsoft\Windows\CurrentVersion\Run\cacaoweb

Additional Information

The following directories were created:
%APPDATA%\cacaoweb%PROGRAMFILES%\cacaoweb%PROGRAMFILES(x86)%\cacaoweb
The following URL's were detected:
http://cacaoweb.org
Loading...