TSPY_FAREIT.VG
PWS:Win32/Fareit(Microsoft), Trojan-PWS.Win32.Tepfer(Ikarus), Win32/PSW.Fareit.A trojan(Eset)
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

Threat Type: Spyware
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
115,752 bytes
EXE
No
04 Jun 2013
Arrival Details
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other System Modifications
This spyware adds the following registry entries:
HKEY_CURRENT_USER\Software\WinRAR
HWID = "{random value}"
HKEY_CURRENT_USER\Software\WinRAR
Client Hash = "{random value}"
Other Details
This spyware connects to the following possibly malicious URL:
- http://{BLOCKED}zheim.de/default.php?j8g8Mwi1RO6zdG3T41krmOc7m18BheXBmx79I
- http://{BLOCKED}r-en-car.com/default.php?N7bHHjKGcU7uF5818FlhxkDci7ZT9MFJN
- http://{BLOCKED}rinnung-nuernberg.de/default.php?YqFsvKW7V3lxMTLyWRgIZueZ1
- http://{BLOCKED}eads.org/b.htm?16tZt6GLRtSCcMViuLfoW9HXeC5jJNP6pep51SmwNg2
- http://{BLOCKED}eads.org/r.htm?zB8QEyqur7YhwPenqstzfWV4R641lSapJ8NUtRZPgsU
- http://{BLOCKED}eads.org/z.htm?7OA7FY3Haz9AFMwvDpbhDhEMqwbjKn2R9alwr1XZrbO
- http://{BLOCKED}sora.net/y.htm?gBDtvvfgwt8B5wnGCbtjyclshFNwKcmNDs2U8ZN7Ztu
- http://{BLOCKED}sora.net/w.htm?36HazPIdHRzG6x7Wwt84dQlafBXCxLyP4ncvrUO3V5m
- http://{BLOCKED}sora.net/c.htm?LXtaKWEaYoe7UN3gpOyV4x55wTq59GUNcrf8MoU1lZl
- http://{BLOCKED}i.org/l.htm?KniaRFsOTUigTyVv7ph7UQQh2b87sTyJfQHshkB2kSkhSPx
- http://{BLOCKED}i.org/n.htm?PpqeQfT6YITxckVEX6RZJenyZUu2hCWfPSoW4z3SsEGMoZ