Home / malwarePDF  

Trojan.Alnaddy


First posted on 28 October 2014.
Source: Symantec

Aliases :

There are no other names known for Trojan.Alnaddy.

Explanation :

Trojan.Alnaddy is a Trojan horse that may download threats onto the compromised computer.

The Trojan may be downloaded and executed manually.

Once executed, the Trojan creates the following files:
%ProgramFiles%\Universal Updater\settings.json%ProgramFiles%\Universal Updater\UpdaterService.exe
It then creates the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Universal\"aid" = "1001"HKEY_LOCAL_MACHINE\SOFTWARE\Universal\"dt" = "23102014"HKEY_LOCAL_MACHINE\SOFTWARE\Universal\"geo" = "[GEO]"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UniversalUpdater\"Type" = "10"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UniversalUpdater\"Start" = "2"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UniversalUpdater\"ErrorControl" = "1"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UniversalUpdater\"ImagePath" = "%ProgramFiles%\Universal Updater\UpdaterService.exe"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UniversalUpdater\"DisplayName" = "Universal Updater Service"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UniversalUpdater\"ObjectName" = "LocalSystem"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UniversalUpdater\"Description" = "Keeps your computer synchronized with the latest software updates."HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UniversalUpdater\Security\"Security" = "[BINARY DATA]"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\UniversalUpdater\"Type" = "10"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\UniversalUpdater\"Start" = "2"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\UniversalUpdater\"ErrorControl" = "1"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\UniversalUpdater\"ImagePath" = "%ProgramFiles%\Universal Updater\UpdaterService.exe"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\UniversalUpdater\"DisplayName" = "Universal Updater Service"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\UniversalUpdater\"ObjectName" = "LocalSystem"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\UniversalUpdater\"Description" = "Keeps your computer synchronized with the latest software updates."HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\UniversalUpdater\Security\"Security" = "[BINARY DATA]"
Next, the Trojan creates a service with the following properties:
Display name: Universal Updater ServiceImage path: %ProgramFiles%\Universal Updater\UpdaterService.exeDescription: Keeps your computer synchronized with the latest software updates.
It then creates the following registry subkeys to register itself as a service:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\UniversalUpdaterHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\UniversalUpdater
Once executed, the Trojan starts an installation wizard which may ask user to install a toolbar. The Trojan may also install additional software on the compromised computer.

The Trojan may also connect to the following remote location:
[http://]update.data-url.com[REMOVED]
The Trojan then downloads a configuration file to tell it where to download further potentially malicious files.

Last update 28 October 2014

 

TOP