Malware

Nemesis.8609 (file analysis)

Malware Removal

The Nemesis.8609 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Nemesis.8609 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Nemesis.8609?


File Info:

name: F54DE89BB09EE1D55DBC.mlw
path: /opt/CAPEv2/storage/binaries/007a8cd2423b3397492f99561c113f68e6f3683c9400ea239a8ac5d826c6a2ae
crc32: AE6ECB24
md5: f54de89bb09ee1d55dbcc2b03e55d352
sha1: 5fb0c7d099d268a0ecbc7feadcbb50f5b5162d5b
sha256: 007a8cd2423b3397492f99561c113f68e6f3683c9400ea239a8ac5d826c6a2ae
sha512: 657f13d4ec1954c88b81b9ae1a3f7b3864dfb1295aa91eaf39d49520f09db4f3edd0e8c600e0c09b697bc69f8751c6c6bc66f37b88b042bd928da71888d71307
ssdeep: 3072:erV1c41Utsu5QWoGKy+mXAMEcGl1uYHECcpvrn6J/:eo4UrQWoXy+Z9ck1TdcA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12DD3011297B0C027ECB30F301E7E46525BB9E16921A4971B2768DF9C3E37742CC5E6A2
sha3_384: 98762da0b1160a22e61af4c0571e4bb5253154329e3ee42eb5f5ff537d287dc9e2422c54054fe239a791685ce4627a7b
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2017-08-01 00:35:01

Version Info:

Comments: sdbrtfnfhsehhsehhseh brtfn xxx iInstall software 32
Translation: 0x0409 0x04b0

Nemesis.8609 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Nemesis.8609
FireEyeGeneric.mg.f54de89bb09ee1d5
ALYacGen:Trojan.Heur.RP.dmGfbawc4Hc
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.99079
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan-Downloader ( 00520c311 )
AlibabaMalware:Win32/km_2c3f9.None
K7GWTrojan-Downloader ( 00520c311 )
Cybereasonmalicious.bb09ee
CyrenW32/Tovkater.O.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Tovkater.IC
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Tovkater-6956309-0
KasperskyTrojan-Downloader.Win32.Tovkater.botb
BitDefenderGen:Variant.Nemesis.8609
NANO-AntivirusRiskware.Win32.InstMonster.ewfgnd
SUPERAntiSpywareTrojan.Agent/Gen-Tovkater
AvastWin32:Malware-gen
TencentWin32.Trojan-Downloader.Tovkater.Kzfl
SophosGeneric ML PUA (PUA)
ComodoApplicUnwnt@#3v7murujfje29
DrWebTrojan.DownLoader26.3208
VIPREGen:Variant.Nemesis.8609
TrendMicroTROJ_GEN.R002C0PD822
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Nemesis.8609 (B)
SentinelOneStatic AI – Suspicious PE
GDataNSIS.Trojan-Downloader.Tovkater.C
GoogleDetected
AviraHEUR/AGEN.1210120
Antiy-AVLTrojan/Generic.ASMalwS.3E79
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Tovkater.C2311989
McAfeeArtemis!F54DE89BB09E
MAXmalware (ai score=96)
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Trojan.Malicious.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0PD822
RisingDownloader.Tovkater/NSIS!1.AF36 (CLASSIC:bWQ1Om/xwo3OuoXG)
YandexTrojan.GenAsa!qhYl4EpQjKc
IkarusTrojan-Downloader.Win32.Tovkater
FortinetW32/Tovkater.IA!tr.dldr
BitDefenderThetaAI:Packer.279156441E
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Nemesis.8609?

Nemesis.8609 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment