Home Malware Programs Backdoors Backdoor:Win32/Noancooe

Backdoor:Win32/Noancooe

Posted: October 16, 2015

Threat Metric

Threat Level: 6/10
Infected PCs: 199
First Seen: October 16, 2015
Last Seen: November 6, 2020
OS(es) Affected: Windows

Backdoor:Win32/Noancooe is one of those cyber threats that should never reach your PC. It is extremely threatening malware because it may provide its operators with a full control over the infected systems. It is impossible to prevent the installation of this vicious Trojan unless you know its distributions methods. Up to now, there are no reports whatsoever that Backdoor:Win32/Noancooe relies on some unique infection vector. It may get access to your PC in case you are not vigilant during your surfing sessions, and open a corrupt email attachment or download any software from suspicious platforms. For a solid protection, always double check if the sender is who he claims to be, avoid torrent trackers and install updates solely from official platforms. If you make the mistake and load Backdoor:Win32/Noancooe, it will establish a connection with remote Command and Control (C&C) servers. It may connect your machine to a.config.skype.com or dns.msftncsi.com through port 53. The culprits behind these attacks use this centralized computer to communicate with their malware. They may send various instructions to undertake different actions. As a result, the infection with Backdoor:Win32/Noancooe may lead to a loss of crucial data on the hard drives. The con artists also may obtain valuable account credentials, which may result in financial losses potentially. The hackers also may upload additional harmful programs to your PC for more specific operations. Unfortunately, both the connection to the C&C servers and the presence of the Trojan are silent. You may not detect any symptoms but some minor drop in the performance. Some of the files that Backdoor:Win32/Noancooe creates are %APPDATA%\c97e261a-abeb-4aa5-9797-7611f82457ca\run.dat and %TEMP%\windowsus\windows.exe. However, deleting them will certainly be insufficient to resolve the issue because Backdoor:Win32/Noancooe is too stubborn. To clean your PC, you should use special security software.

Technical Details

Additional Information

The following directories were created:
%APPDATA%\servicexxxx
Loading...