Trojan

About “AIT:Trojan.Nymeria.4764” infection

Malware Removal

The AIT:Trojan.Nymeria.4764 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.4764 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine AIT:Trojan.Nymeria.4764?


File Info:

name: BE2F34BF98CB99127A18.mlw
path: /opt/CAPEv2/storage/binaries/296bb926615a3a8be6dd04aa2b10ce663e61bf0173c0e4d53711e2aba4bd808c
crc32: 5F9BAEC9
md5: be2f34bf98cb99127a1887cd5c701676
sha1: 5456e651beaf4e1ff7b020652276b8426221f05c
sha256: 296bb926615a3a8be6dd04aa2b10ce663e61bf0173c0e4d53711e2aba4bd808c
sha512: be4462f4b435e83be0779f2b05ce7fb34f106716227a56a4a215ee2e1efcd0655db06445d434f662e6c22abb9ff23264b2d30d527fafc898df1a536e85d1689e
ssdeep: 49152:ah+ZkldoPKiz/LB9BWVzlWd+Z27pNbyhNKH487oz7IXhWV:z2cPKiiu82NofavaIXh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0D5DF03B3A18072FFABA1779B59F2029ABC7D640233856F13983D79B974571123E663
sha3_384: e57e45b08e12726131679739442b7cf1ae3e2206ebcebf76e8d5c3e277af4424c6290969cf8bd6f1954724ef93fbd010
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2021-08-31 17:51:53

Version Info:

Comments: Easy, light, and free audio player for you to play all your audio formats, compatible with all versions of Windows, and with all screen readers.
CompanyName: Nacer baaziz
FileDescription: easy audio player
FileVersion: 7.0.0.150
InternalName: easy Audio Player
LegalCopyright: copyright © 2021
OriginalFilename: easyAudioPlayer.exe
ProductName: easy audio player
ProductVersion: 7.0.0
Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.4764 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.4764
FireEyeGeneric.mg.be2f34bf98cb9912
ALYacAIT:Trojan.Nymeria.4764
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/Generic.a5889cf3
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
CyrenW32/Wacapew.AW.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H06KQ21
BitDefenderAIT:Trojan.Nymeria.4764
AvastWin32:Malware-gen
Ad-AwareAIT:Trojan.Nymeria.4764
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.vm
EmsisoftAIT:Trojan.Nymeria.4764 (B)
IkarusTrojan.Crypt
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataAIT:Trojan.Nymeria.4764 (2x)
CynetMalicious (score: 100)
AhnLab-V3Trojan/AU3.AutoInj.S1107
Acronissuspicious
McAfeeGenericRXIT-DP!BE2F34BF98CB
MAXmalware (ai score=88)
MalwarebytesMalware.AI.3899353985
FortinetW32/PossibleThreat
AVGWin32:Malware-gen

How to remove AIT:Trojan.Nymeria.4764?

AIT:Trojan.Nymeria.4764 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment