Threat Database Trojans Trojan.Agent.NAL

Trojan.Agent.NAL

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: December 14, 2023
Last Seen: December 24, 2023
OS(es) Affected: Windows

The detection of Trojan.Agent.NAL on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, putting your personal data and sensitive information at risk. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Agent.NAL?

Trojan.Agent.NAL is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate or harmless. The name "Trojan" refers to the malware's ability to infiltrate a system by hiding within or masquerading as a legitimate program or file. The ".NAL" suffix may indicate a specific variant or identifier, but it does not provide information about the malware's behavior or purpose.

How Trojan.Agent.NAL Operates

Trojan horse malware, including Trojan.Agent.NAL, typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once inside a system, it can perform a variety of malicious actions, such as stealing sensitive information, installing additional malware, or providing unauthorized access to the infected computer. The exact behavior of Trojan.Agent.NAL may vary, but its primary goal is to compromise the security and integrity of the infected system.

Symptoms of Infection

Infected systems may exhibit various symptoms, including slow performance, frequent crashes, or unfamiliar programs and icons. Users may also notice unusual network activity, such as unexpected connections or data transfers. However, some malware can operate stealthily, making it difficult to detect without the aid of security software. If you suspect that your system is infected with Trojan.Agent.NAL, it is crucial to take immediate action to remove the threat and prevent further damage.

How to Remove Trojan.Agent.NAL

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs associated with Trojan.Agent.NAL.
  3. Uninstall any suspicious programs or applications that may be related to the malware, as they may be used to reinstall or reactivate the threat.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons that may be associated with the malware.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Trojan.Agent.NAL from your system requires a combination of technical knowledge and caution. By following the steps outlined above and using reputable security software, you can effectively remove the threat and prevent future infections. It is essential to remain vigilant and proactive in maintaining the security and integrity of your computer, as new threats and vulnerabilities emerge continuously. Regularly updating your operating system, software, and security tools can help prevent similar infections in the future.

Analysis Report

General information

Family Name: Trojan.Agent.NAL
Signature status: No Signature

Known Samples

MD5: a253d0fb7fb37e7b75388e7d0c5ea69f
SHA1: 7a73e31d432b22ce316503aa2f764dbb3b73499f
SHA256: FEB23FE8E94A34D458E507A964AD181D3A59D589717BC280E2EDE4017A90359F
File Size: 348.16 KB, 348160 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Mcnfyhfnk Xmtadntivfg
File Description MS DTCconsole program
File Version 2001.12.4720.3959 (srv03_sp2_rtm.070216-1710)
Internal Name MSDTC.EXE
Legal Copyright © Szwnueccu Cbccvqmlqkk. All rights reserved.
Original Filename MSDTC.EXE
Product Name Qvtjrcwor® Wgronow® Qxmkmonmu Qskyon
Product Version 5.2.3790.3959

File Traits

  • x86

Block Information

Total Blocks: 271
Potentially Malicious Blocks: 13
Whitelisted Blocks: 209
Unknown Blocks: 49

Visual Map

? ? ? ? ? ? ? ? ? x ? x 0 ? ? ? x ? 0 ? 0 ? ? ? 0 ? x 0 1 0 1 ? 0 0 0 ? 0 0 0 x 0 x 2 3 0 0 ? 0 0 0 0 0 0 0 x x 0 1 1 x 0 0 ? 0 0 0 x 2 3 0 0 0 x ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 1 0 0 0 0 1 1 0 0 x 0 0 2 1 1 3 1 0 1 0 0 2 2 3 0 0 0 0 0 ? 0 0 0 0 ? 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x ? ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\~unins6640.bat Generic Write,Read Attributes
c:\users\user\downloads\7a73e31d432b22ce316503aa2f764dbb3b73499f_0000348160 Synchronize,Write Attributes
c:\windows\syswow64\windowse.exe Generic Write,Read Attributes
c:\windows\syswow64\windowse.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\bfhhlgu::gmhywxqtzh 5����T���� 0����fң_�a�.�[����]���)t,^����y�j��t�0����9��罁��j�چI��^�h�uF�k\ �to�_����ޜw��)�w�/�qDw�`&�w��i��Ƴ�\�Ic�N�� 6��#�L2C�>$��l���"D����m�q���j�\��k��i�j�*�1�\�W ��>;F<�^o�kY�W� ��v,�N� q�����z��d��� RegNtPreCreateKey
HKLM\software\wow6432node\bfhhlgu::gmhywxqtzh 5����T���� 0����fң_�a�.�[����]���)t,^����y�j��t�0����9��罁��j�چI��^�h�uF�k\ �to�_����ޜw��)�w�/�qDw�`&�w��i��Ƴ�\�Ic�N�� 6��#�L2C�>$��l���"D����m�q���j�\��k��i�j�*�1�\�W ��>;F<�^o�kY�W� ��v,�N� q�����z��d��� RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows\currentversion\policies\explorer\run::gpvnzg C:\WINDOWS\SysWOW64\Windowse.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings::6 ⾫先 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\internet settings::6 ⾫先 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\systemrestore::rpsessioninterval RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings::9 ;�����y{_�8� RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\internet settings::9 ;�����y{_�8� RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe খ똃诉ǜ RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Shell Execute
  • WriteConsole
Process Terminate
  • TerminateProcess

Shell Command Execution

WriteConsole: The batch file c

Trending

Most Viewed

Loading...