Threat Database Trojans Trojan.Naid

Trojan.Naid

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 5
First Seen: June 18, 2012
Last Seen: April 19, 2023
OS(es) Affected: Windows

Trojan.Naid is a Trojan that opens a back door on the compromised PC. Trojan.Naid enables cybercriminals to gain remote access and control over the targeted machine. When activated, Trojan.Naid creates malevolent files. Trojan.Naid also modifies the Windows Registry by creating a few registry keys. Trojan.Naid may create one of the services called AppMgmt and BITS so that it can load whenever you boot up Windows. Trojan.Naid collects the specific system information from the targeted computer, which involve unique identifier (UID) and domain name.
Trojan.Naid uses its own custom communications protocol for connecting to the IP address 219.90.117.132 over port 443.

File System Details

Trojan.Naid may create the following file(s):
# File Name Detections
1. %UserProfile%\AppMgmt.dll
2. %Windir%\Temp\uid.ax

Registry Details

Trojan.Naid may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\AppMgmt\"FailureActions" = "[BINARY DATA]"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\AppMgmt\"Start" = "2"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\AppMgmt\Parameters\"ServiceDll" = "%UserProfile%\AppMgmt.dll"
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\AppMgmt\"Type" = "272"

Trending

Most Viewed

Loading...