Trojan

AIT:Trojan.Nymeria.559 information

Malware Removal

The AIT:Trojan.Nymeria.559 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.559 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine AIT:Trojan.Nymeria.559?


File Info:

name: BC891B966831D2D9BBA5.mlw
path: /opt/CAPEv2/storage/binaries/9a1241413daaa82f5ccd5d21e5fbd34ad68f059c753c70e123a7c8d59d636ee6
crc32: 83B6AB0F
md5: bc891b966831d2d9bba5f9914b87b19d
sha1: 56d16f24e5152292298faa556400a1afefba858c
sha256: 9a1241413daaa82f5ccd5d21e5fbd34ad68f059c753c70e123a7c8d59d636ee6
sha512: f61d46fae4b4fe387733a013a555dc986cfb8c8ec82da7e63c2bbf5962c350586e885bbc9c5efe3b80aee38af8e679afd01a2ee6996539ae995ebf88e880c742
ssdeep: 12288:Stb20Qc3lT7af41ePBRYuQLKpqeUhbTv5OFgNuPPpHSgaY7X76A:Stb20pkaCqT5TBWgNQ7aYX76A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3059E1373DD8361C3B25273BA25B701BEBF782506A5F96B2FD4093DE920122525EA73
sha3_384: 5cefbc86d249e47a9174482286a632ecd34f290139316cda40f6c59c0c7cf6604c6e6538789360546535f53ea63e9ba1
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2016-07-05 18:07:16

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.559 also known as:

LionicTrojan.Script.Generic.4!c
MicroWorld-eScanAIT:Trojan.Nymeria.559
FireEyeAIT:Trojan.Nymeria.559
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
BitDefenderAIT:Trojan.Nymeria.559
Cybereasonmalicious.66831d
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Autoit.OCJ
APEXMalicious
AlibabaTrojanDownloader:Script/Generic.7b3c4a03
AvastFileRepMalware
Ad-AwareAIT:Trojan.Nymeria.559
BitDefenderThetaAI:Packer.6A489FE616
TrendMicroTROJ_GEN.R049C0PL621
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
EmsisoftAIT:Trojan.Nymeria.559 (B)
AviraHEUR/AGEN.1207790
MAXmalware (ai score=86)
ViRobotTrojan.Win32.Z.Nymeria.860672.A
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
TrendMicro-HouseCallTROJ_GEN.R049C0PL621
YandexTrojan.Agent.Gen.QS
IkarusTrojan-Downloader.Win32.AutoIt
FortinetW32/Agent.OCJ!tr.dldr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_80% (W)

How to remove AIT:Trojan.Nymeria.559?

AIT:Trojan.Nymeria.559 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment