CAFEiNi 0.9
(Backdoor.Win32.Cafeini.09)

by Brain Storm [Electronic Souls]

Written in Visual C++, compressed with UPX

Released in July 2000

Made in Poland

more versions


VERSION 0.9 (01.08.2000)
CAFEiNi server:
-server is automatic updated by http
-added registry editor
-new options: CHANGEOWNER, CHANGEGROUP, CHANGESERIAL
-new options: SETTIME, SETDATE
-more information about victim (Windows owner,owners group,serial number,display adapter)
-kills new antivirus: AntiVirus eXpert
-kills some backdoor removers (The Cleaner, HookProtect, LockDown, TrojanDefenseSuite)
 from memory
-faster screen dump (snapshot), about 4 times :)
-fixed telnet command (works only with telnet client)
-some bugs removed

CAFEiNi client:
-added tooltips for all buttons and fileds
-all text fileds in client are remembered
-added registry manager
-faster screen dump (snapshot), about 4 times :)
-new option: continuous screen dump
-new options: change Windows owner, owners group, serial number
-new options: set time, set date
-more information about victim (Windows owner,owners group,serial number,display adapter)
-some bugs removed
 
Brain Storm


Server:
dropped file:
c:\Documents and Settings\%User%\gososu.exe
size: 122.880 bytes
 
port: 51966, 1213 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Hybezufe"
data: C:\Documents and Settings\%User%\Hybezufe.exe 

tested on Windows XP

MegaSecurity