TSPY_FAREIT.CP
April 12, 2016
ALIASES:
Trojan.PWS.Fareit!ihAbbOlWP2I(Agnitum), TrojanPSW.Fareit.r3(CAT-QuickHeal), Win32:VBCrypt-DAN [Trj](Avast)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:

Threat Type: Spyware
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It deletes itself after execution.
TECHNICAL DETAILS
File Size:
142,808 bytes
File Type:
EXE
Memory Resident:
No
Initial Samples Received Date:
03 Aug 2015
Arrival Details
This spyware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other Details
This spyware connects to the following possibly malicious URL:
- www. {BLOCKED}tech.com.br/cgii-bin/kene/gate.php
It deletes itself after execution.