TSPY_FAREIT.EV

 Analysis by: Nikko Tamana

 ALIASES:

Trojan-PWS.Win32.Fareit (Ikarus), PWS:Win32/Fareit (Microsoft)

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Spyware

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It executes then deletes itself afterward.

However, as of this writing, the said sites are inaccessible.

  TECHNICAL DETAILS

File Size:

120,912 bytes

File Type:

EXE

Initial Samples Received Date:

16 Nov 2012

Arrival Details

This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This spyware drops the following file(s)/component(s):

  • %User Temp%\abcd.bat

(Note: %User Temp% is the current user's Temp folder, which is usually C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, XP, and Server 2003.)

It executes then deletes itself afterward.

Other System Modifications

This spyware adds the following registry entries as part of its installation routine:

HKEY_CURRENT_USER\Software\WinRAR
HWID = "{FCC499B8-BBF2-49EA-8BDC-A17125BE18FA}"

Other Details

This spyware connects to the following possibly malicious URL:

  • http://{BLOCKED}.{BLOCKED}.106.99/vbulletin/profile.php

However, as of this writing, the said sites are inaccessible.