Home Malware Programs Potentially Unwanted Programs (PUPs) Cacaoweb

Cacaoweb

Posted: March 27, 2013

Threat Metric

Ranking: 3,821
Threat Level: 1/10
Infected PCs: 163,977
First Seen: March 27, 2013
Last Seen: March 10, 2025
OS(es) Affected: Windows

Cacaoweb markets itself as an alternative to popular torrent clients, but also exhibits some of the characteristics that malware experts often associate with botnet-based backdoor Trojans. Users of this supposedly legitimate product have reported worsened browser performance and other side effects, despite Cacaoweb's company's claim that Cacaoweb is a 'lightweight' program. For the time being, malware experts consider Cacaoweb to fall into the classification of a Potentially Unwanted Program, and you should consider the benefits of deleting Cacaoweb via reliable security software.

Why Finding Files may Find You Trouble, Too

The prominence of the torrent as the ascendant replacement of other file-sharing methods has not gone unnoticed by most software developers, but the company responsible for Cacaoweb seems to have added some 'extra' functions. Cacaoweb is not guilty of completely false advertising, and does provide functions for finding files online. However, its claims of bypassing cloud storage advertisements and other 'interruptions' in download content have yet to solidify, and malware experts also have noted some additional, troubling features.

The latter include:

  • Interrupted Internet connectivity.
  • Slow Web-browsing performance.
  • Automatic bandwidth usage for purposes not specified by Cacaoweb's user.

These issues sometimes are symptomatic of a Trojan that uses its network connection to force your PC to perform illegal actions 'behind the scenes,' such as crashing websites with fake traffic (also known as a DDoS attack). Bredolab, Conficker and Sality are examples of Trojans that include botnet features, and Cacaoweb may be a new member of this list. As a result, many PC security companies categorize Cacaoweb as a backdoor Trojan, although malware experts must rate Cacaoweb as a PUP until they can verify additional evidence.

Taking the Web Back from Cacaoweb

False detections of Trojans have been known to happen, but whenever a Trojan detection is accompanied by an unusual symptom, as with Cacaoweb, you should consider the situation with all due caution. Depending on your updated anti-malware programs to determine between safe and unsafe programs always is the best approach. As a side note, malware experts also might mention that using products designed to perform questionable acts, such as Cacaoweb's alleged propensity for circumventing the restrictions on file-sharing sites, may be an easy way to compromise your PC with threats.

Assuming you've removed Cacaoweb promptly and through proper tools, there shouldn't be any long-term damage to your PC from its temporary presence. Fortunately, botnet Trojans may focus their attacks on external targets. However, any Trojan with backdoor functions also has the potential for attacks directed against your computer, which is why exercising a heavy degree of paranoia is prudent. Cacaoweb may include compatibility with most operating systems, including Windows, Linux and OS X.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\Downloads\cacaoweb.exe File name: cacaoweb.exe
Size: 471.55 KB (471552 bytes)
MD5: 90d787a2df45b1e82c276dfd1a91ae61
Detection count: 8,895
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Downloads\cacaoweb.exe
Group: Malware file
Last Updated: November 15, 2024
C:\Qoobox\Quarantine\C\Users\<username>\AppData\Roaming\cacaoweb\cacaoweb.exe.vir File name: cacaoweb.exe.vir
Size: 457.72 KB (457728 bytes)
MD5: 98d472ec7b867c1cfeb1916ce3fa165b
Detection count: 4,712
Mime Type: unknown/vir
Path: C:\Qoobox\Quarantine\C\Users\<username>\AppData\Roaming\cacaoweb\cacaoweb.exe.vir
Group: Malware file
Last Updated: October 4, 2022
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonewd4be07.exe File name: cacaonewd4be07.exe
Size: 435.71 KB (435712 bytes)
MD5: be7f0b75275270688088e8956f02ee5d
Detection count: 3,843
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonewd4be07.exe
Group: Malware file
Last Updated: April 24, 2024
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew153105.exe File name: cacaonew153105.exe
Size: 436.22 KB (436224 bytes)
MD5: 7a93e7d6377640a2338438d1c51e2d3e
Detection count: 3,719
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew153105.exe
Group: Malware file
Last Updated: October 15, 2024
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew5cf2c7.exe File name: cacaonew5cf2c7.exe
Size: 436.22 KB (436224 bytes)
MD5: 9507d099d63307e9897d7e98373ee3a2
Detection count: 3,588
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew5cf2c7.exe
Group: Malware file
Last Updated: February 25, 2024
%SYSTEMDRIVE%\AdwCleaner\Quarantine\files\zjnctabcipcmhbxrdgaxmmrfuwwuhlvr.back File name: zjnctabcipcmhbxrdgaxmmrfuwwuhlvr.back
Size: 452.6 KB (452608 bytes)
MD5: e0d50b1d0fb4b71d7de0ece999c69028
Detection count: 3,152
Mime Type: unknown/back
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\files\zjnctabcipcmhbxrdgaxmmrfuwwuhlvr.back
Group: Malware file
Last Updated: December 11, 2024
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew6cc4a7.exe File name: cacaonew6cc4a7.exe
Size: 436.73 KB (436736 bytes)
MD5: ac782786780cbd9a72fe0cac0ee28107
Detection count: 2,536
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew6cc4a7.exe
Group: Malware file
Last Updated: September 24, 2023
G:\Laky Doc2015\Laky Doc. 2012\fillér\c\Documents and Settings\Fillér Zoja\Local Settings\Temp\cacaonew0de88a.exe File name: cacaonew0de88a.exe
Size: 396.28 KB (396288 bytes)
MD5: efaf5a80eff49efd9ba526781ad97e0d
Detection count: 1,860
File type: Executable File
Mime Type: unknown/exe
Path: G:\Laky Doc2015\Laky Doc. 2012\fillér\c\Documents and Settings\Fillér Zoja\Local Settings\Temp\cacaonew0de88a.exe
Group: Malware file
Last Updated: February 27, 2024
C:\RECYCLER\S-1-5-21-1343024091-1563985344-1177238915-500\Dc53.exe File name: Dc53.exe
Size: 452.6 KB (452608 bytes)
MD5: 20606d3a237e8907128a18e4ba080f19
Detection count: 1,806
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-1343024091-1563985344-1177238915-500\Dc53.exe
Group: Malware file
Last Updated: August 14, 2023
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew7b3d3e.exe File name: cacaonew7b3d3e.exe
Size: 435.71 KB (435712 bytes)
MD5: 2ccaf6b7b990892fb66702b9c34d058f
Detection count: 1,422
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew7b3d3e.exe
Group: Malware file
Last Updated: June 8, 2023
G:\Laky Doc2015\Laky Doc. 2012\fillér\c\Documents and Settings\Fillér Zoja\Local Settings\Temp\cacaonewf2e027.exe File name: cacaonewf2e027.exe
Size: 412.16 KB (412160 bytes)
MD5: 89733b554fe7b5089044ffdb8f132de9
Detection count: 1,375
File type: Executable File
Mime Type: unknown/exe
Path: G:\Laky Doc2015\Laky Doc. 2012\fillér\c\Documents and Settings\Fillér Zoja\Local Settings\Temp\cacaonewf2e027.exe
Group: Malware file
Last Updated: July 8, 2022
C:\Users\<username>\Documents\HD\Pastas\Documents\Dados HD\Usuarios\Hewerton\AppData\Local\Temp\cacaonewab8e8a.exe File name: cacaonewab8e8a.exe
Size: 433.15 KB (433152 bytes)
MD5: 2649eeb4f590742c0c6234dd90538dd9
Detection count: 1,157
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Documents\HD\Pastas\Documents\Dados HD\Usuarios\Hewerton\AppData\Local\Temp\cacaonewab8e8a.exe
Group: Malware file
Last Updated: June 8, 2023
C:\$RECYCLE.BIN\S-1-5-21-1922062534-1032020396-3115903374-1002\$R27TEPA.exe File name: $R27TEPA.exe
Size: 451.58 KB (451584 bytes)
MD5: 0374234b527f4a41593e073e7d8be800
Detection count: 597
File type: Executable File
Mime Type: unknown/exe
Path: C:\$RECYCLE.BIN\S-1-5-21-1922062534-1032020396-3115903374-1002\$R27TEPA.exe
Group: Malware file
Last Updated: March 26, 2022
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew21cad0.exe File name: cacaonew21cad0.exe
Size: 427 KB (427008 bytes)
MD5: 6d04c21c0356e798b5f2f76300c2e6af
Detection count: 445
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew21cad0.exe
Group: Malware file
Last Updated: February 1, 2025
C:\Users\<username>\Downloads\cacaoweb12.exe File name: cacaoweb12.exe
Size: 419.84 KB (419840 bytes)
MD5: 8a92e889fc42e9b30b0b3e91d0bce397
Detection count: 375
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Downloads\cacaoweb12.exe
Group: Malware file
Last Updated: June 29, 2024
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew749423.exe File name: cacaonew749423.exe
Size: 436.73 KB (436736 bytes)
MD5: 30db0ee7c0af7172359dc678545a90da
Detection count: 173
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonew749423.exe
Group: Malware file
Last Updated: April 2, 2022
C:\Users\<username>\AppData\Local\Temp\cacaonew5f7eac.exe File name: cacaonew5f7eac.exe
Size: 419.84 KB (419840 bytes)
MD5: 1ddc87a2c755e1e07967a0e89e339ed9
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\cacaonew5f7eac.exe
Group: Malware file
Last Updated: April 2, 2022
C:\Users\<username>\Desktop\DATOS RECUPERADOS\DATOS TOSHIBA\Users\<username>\AppData\Local\Temp\cacaonew0c2a2c.exe File name: cacaonew0c2a2c.exe
Size: 428.03 KB (428032 bytes)
MD5: ae67e21b7ca4449216482d391bf70468
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\DATOS RECUPERADOS\DATOS TOSHIBA\Users\<username>\AppData\Local\Temp\cacaonew0c2a2c.exe
Group: Malware file
Last Updated: February 27, 2022
%SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonewf6c72e.exe File name: cacaonewf6c72e.exe
Size: 428.54 KB (428544 bytes)
MD5: 5f6b679df08bd7ae58a05d8f3f6403fa
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\backup\Users\<username>\AppData\Local\Temp\cacaonewf6c72e.exe
Group: Malware file
Last Updated: April 2, 2022

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\cacaowebSoftware\Microsoft\Windows\CurrentVersion\Run\cacaoweb

Additional Information

The following directories were created:
%APPDATA%\cacaoweb%PROGRAMFILES%\cacaoweb%PROGRAMFILES(x86)%\cacaoweb
The following URL's were detected:
http://cacaoweb.org
Loading...