Home Malware Programs Trojans TSPY_FAREIT.ACU

TSPY_FAREIT.ACU

Posted: June 28, 2013

Threat Metric

Threat Level: 10/10
Infected PCs: 7
First Seen: June 28, 2013
Last Seen: November 18, 2019
OS(es) Affected: Windows

TSPY_FAREIT.ACU is a data-stealing Trojan, which is signed with Certificate stolen from Opera. TSPY_FAREIT.ACU pretends to be an Opera update. Once installed on a targeted computer system, TSPY_FAREIT.ACU is able to steal information from specific FTP clients and file managers, involving usernames, passwords, and server names. TTSPY_FAREIT.ACU is also created to steal data stored in affected web browsers. This data is usually login credentials for social networking, banking, and e-commerce websites. Using this information, attackers can hijack numerous online accounts or even launch unauthorized transactions. Attackers can also benefit from this stolen data by selling it to the underground market. TSPY_FAREIT.ACU targets Opera, Thunderbird, Mozilla Firefox, Google Chrome, Total Commander, CuteFTP, The Bat!, Far, Filezilla, and other similar programs. TSPY_FAREIT.ACU is also able to download additional malware threats from a web address, which still seems to be working. The suspicious web address has been detected to store police ransomware, an information-stealing Trojan, and a backdoor Trojan.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 1.06 MB (1063572 bytes)
MD5: 74bfab32741f15b9fcfb32aacffab584
Detection count: 74
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: November 18, 2019

More files
Loading...