Home / malwarePDF  

Trojan:Win32/Nitol.C


First posted on 13 September 2012.
Source: SecurityHome

Aliases :

Trojan:Win32/Nitol.C is also known as TROJ_NITOL.SMB (Trend Micro), Trojan.Win32.Scar.gmkz (Kaspersky).

Explanation :

Trojan:Win32/Nitol.C is a malicious program that is unable to spread of its own accord. It may perform a number of actions of an attacker's choice on an affected computer.

Installation
When executed, Trojan:Win32/Nitol.C copies itself to sscqsw.exe.

Note: refers to a variable location that is determined by the malware by querying the Operating System. The default installation location for the System folder for Windows 2000 and NT is C:WinntSystem32; and for XP, Vista, and 7 is C:WindowsSystem32.

Payload
Contacts remote host
Trojan:Win32/Nitol.C may contact a remote host at 222.175.169.73 using port 8086. Commonly, malware may contact a remote host for the following purposes:

  • To report a new infection to its author

  • To receive configuration or other data

  • To download and execute arbitrary files (including updates or additional malware)

  • To receive instruction from a remote attacker

  • To upload data taken from the affected computer

Last update 13 September 2012

 

TOP