Analysis by: Nice Yutuc

ALIASES:

PWS:Win32/Fareit.gen!C (Microsoft), Backdoor-EXI.gen.w (Mcafee) , Backdoor W32/Cycbot.EH (Norman), Trojan-PWS.Win32.Fareit (Ikarus)

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Spyware

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

It executes then deletes itself afterward.

  TECHNICAL DETAILS

File Size: 100,352 bytes
Memory Resident: Yes
Initial Samples Received Date: 25 Nov 2011

Arrival Details

This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This spyware executes then deletes itself afterward.

Other System Modifications

This spyware adds the following registry keys as part of its installation routine:

HKEY_CURRENT_USER\SOFTWARE\WinRAR\
HWID

Other Details

This spyware connects to the following possibly malicious URL:

  • http://{BLOCKED}atransfers.com/gate.php