Cacheton Webdl 1.0
(Trojan-Downloader.Win32.Small.efz)

by Toxikko

Written in Assembler, source included

Released in July 2006


Cacheton Webdl is coded in ASM (masm).
It stealthttp downloads all file types.
It uses a brand nHTTPirewall bypass method I named "fwbc".
This technique bypasses recent firewalls thanks to Internet Explorer's cache.
The server is open source.

--------
Features
--------

[*] Builder (masm)
[*] FWBc (bypasses Tiny Pro)
[*] Bypass more firewalls (eg : Outpost)
[*] Unkillable process
[*] Melt server
[*] Download after restart
[*] Execute the downloaded file
[*] Persistent download
[*] Choice of the target directory
[*] Choice of the target filename
[*] serv size: 4.0 ko or 1.8 ko packed

Toxikko


Server:
c:\Documents and Settings\All Users\services.exe
size: 4,096 bytes 

tested on Windows XP
August 02, 2006

MegaSecurity