cacaoweb.exe

This is a setup program which is used to install the application. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘cacaoweb’. The file has been seen being downloaded from nl.inncdn.com and multiple other hosts.
MD5:
6aabcab9ff3ffb26ef173153b765483d

SHA-1:
66124cdfd9b396e712d13ee8248b87c02a98f328

SHA-256:
1028880c72e13ac70b17ce94209c763478f09c34c5ac6a3299e5aa5cda24929f

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/19/2024 11:19:07 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Boost by Reason
Optional.Startup.I
188163

Trend Micro House Call
TROJ_GEN.R0C1H0ALL13
7.2.357

File size:
458.5 KB (469,504 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\cacaoweb\cacaoweb.exe

File PE Metadata
Compilation timestamp:
12/21/2013 10:38:37 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:ClePbYv4OwSB3ZUeYimHoWB4Wc50bhMojyc9Td/6L0+J7+CiOsyNj6ioSrI:ClW+ZjZ64nYpyclhitwyNjBoSE

Entry address:
0x15AC20

Entry point:
60, BE, 00, D0, 4E, 00, 8D, BE, 00, 40, F1, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 68, 8C, 15, 00, 57, 83, C3, 04, 53, 68, 0F, DC, 06, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 02, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
444 KB (454,656 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
cacaoweb

Command:
"C:\users\{user}\appdata\roaming\cacaoweb\cacaoweb.exe" -noplayer


The file cacaoweb.exe has been seen being distributed by the following 6 URLs.

http://nl.inncdn.com/?domain=cacaoweb&name=Cacaoweb&icon=aHR0cDovL3NjcmVlbnNob3QuaXQuc2Z0Y2RuLm5ldC9pdC9zY3JuLzMxNDAwMC8zMTQ2OTMvY2FjYW93ZWItMDktMzJ4MzIucG5n&url=aHR0cDovL3d3dy5jYWNhb3dlYi5vcmcvZG93bmxvYWQvY2FjYW93ZWIuZXhl&os=&lang=it_IT

The executing file has been seen to make the following network communications in live environments.

TCP:
Connects to public157970.cdma.centertel.pl  (5.185.233.18:51212)

TCP:
Connects to lns-bzn-22-82-249-120-122.adsl.proxad.net  (82.249.120.122:53746)

TCP:
Connects to ip-61.net-89-3-19.rev.numericable.fr  (89.3.19.61:62028)

TCP:
Connects to ip-58.net-82-216-171.joinville2.rev.numericable.fr  (82.216.171.58:52853)

TCP:
Connects to 19.host-182-48-152.compassnet.co.nz  (182.48.152.19:49706)

Scan cacaoweb.exe - Powered by Reason Core Security