Threat Database Trojans TSPY_SPCESEND

TSPY_SPCESEND

By GoldSparrow in Trojans

Threat Scorecard

Ranking: 10,701
Threat Level: 90 % (High)
Infected Computers: 244
First Seen: March 28, 2013
Last Seen: September 14, 2023
OS(es) Affected: Windows

TSPY_SPCESEND is a Trojan with spyware funcionalities that uses the file-hosting website 'Sendspace' as a storage of stolen information. TSPY_SPCESEND grabs MS Word and Excel files. TSPY_SPCESEND searches the local drive of a targeted PC for MS Word and MS Excel documents. The grabbed documents are then archived and saved by TSPY_SPCESEND. TSPY_SPCESEND then uploads the created archive to the website 'sendspace.com'. Once the archive is uploaded successfully, TSPY_SPCESEND transmits the created download link and archive password to a C&C server. This routine exposes data, which may be used for damaging intentions to unidentified computer users. TSPY_SPCESEND may be distributed from remote websites by other malware infections.

File System Details

TSPY_SPCESEND may create the following file(s):
# File Name Detections
1. %User Temp%\[RANDOM CHARACTERS].zip

Related Posts

Trending

Most Viewed

Loading...