Trojan

AIT:Trojan.Nymeria.645 (file analysis)

Malware Removal

The AIT:Trojan.Nymeria.645 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.645 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup

Related domains:

iplogger.com
apps.identrust.com

How to determine AIT:Trojan.Nymeria.645?


File Info:

crc32: FFA4ED27
md5: 11c4577d15409607201bdf3d986919d2
name: 11C4577D15409607201BDF3D986919D2.mlw
sha1: edd951c2ca522e8da5e155089cd05676f85add1b
sha256: 69d9388226b41f504bed6b8c2edf6f8b94b41ca77bddc2c3887db7d628fa2fd1
sha512: 592c8618d60b8fbb9b939b527709a47d033976d4e92d4157f036e5c34fd0e7801e0b523bd059a72788b78b799b65fe07aa67b42aae5fb963c0b648d3be18152d
ssdeep: 24576:3AHnh+eWsN3skA4RV1Hom2KXMmHac7jr1VBA1j+LNvc5:qh+ZkldoPK8YacL1jAILw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.645 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005642691 )
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AutoIt.Nymeria.ZZ
ALYacGen:Heur.Mint.Titirez.zu0@iWlEGBoi
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005642691 )
Cybereasonmalicious.d15409
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.Emotet-6544428-0
KasperskyTrojan-Banker.Win32.Gozi.mw
BitDefenderAIT:Trojan.Nymeria.645
NANO-AntivirusTrojan.Win32.Fareit.faurot
MicroWorld-eScanAIT:Trojan.Nymeria.645
Ad-AwareAIT:Trojan.Nymeria.645
SophosMal/Generic-R + Mal/GandCrab-D
ComodoMalware@#3ca0apxd1ru8i
BitDefenderThetaAI:Packer.78A35CD516
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_GANDCRAB.SMALY-5
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.11c4577d15409607
EmsisoftAIT:Trojan.Nymeria.645 (B)
AviraHEUR/AGEN.1100251
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Predator!ml
AegisLabHacktool.Win32.Gamehack.3!e
GDataGen:Heur.Mint.Titirez.zu0@iWlEGBoi (2x)
AhnLab-V3Malware/Win32.Generic.C2480975
McAfeeArtemis!11C4577D1540
MAXmalware (ai score=98)
VBA32TrojanBanker.Gozi
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-5
TencentWin32.Trojan-banker.Gozi.Dxwu
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoit/TrojanDropper.RK!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove AIT:Trojan.Nymeria.645?

AIT:Trojan.Nymeria.645 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment