Trojan

Trojan.Caypnamer (file analysis)

Malware Removal

The Trojan.Caypnamer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Caypnamer virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • NtSetInformationThread: attempt to hide thread from debugger
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Accessed credential storage registry keys
  • Anomalous binary characteristics

How to determine Trojan.Caypnamer?


File Info:

name: 958523CB0E6D2B1B306F.mlw
path: /opt/CAPEv2/storage/binaries/510eb062400788d26850ed509e1e99381b1c2f485400a5775ccf273b8c38c929
crc32: C318B080
md5: 958523cb0e6d2b1b306fe02a62d05a03
sha1: ad744596d7a86a323aa78fbce090757335a44b3e
sha256: 510eb062400788d26850ed509e1e99381b1c2f485400a5775ccf273b8c38c929
sha512: c208813019ed26d4c8fd454cc7459f5097ede140d5aad7ace2c29c0475b7fa8d5c8f5b7d1ad253cc1bd9a525ca933d9088fc8217dd39d72521e5665a832adb94
ssdeep: 98304:vgwRt91wA/Sde3nUTe1zMNVxM5KFdqivyQfpDqoWytMFUMqUB:vg2Dck3UTe1zMNV6+qivzfR97UB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1892633E0EBB478B4E0662172B846717C36DBAF0DCB6445A7DA4BE60F34A11C1B9B5D03
sha3_384: b6628aa648bcbb9977b1d72e5053fa57b256b41a0f31b752647b21b586af095e5bb0b0c96347767487386c75b4b1e150
ep_bytes: 558bec6aff6870c4410068c095410064
timestamp: 2012-12-31 00:38:51

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.6.0.2712
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.6.0.2712
Translation: 0x0000 0x04b0

Trojan.Caypnamer also known as:

BkavW32.AIDetect.malware2
LionicRiskware.Win64.Miner.1!c
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.Caypnamer
ALYacGen:Variant.Application.Miner.43
CylanceUnsafe
SangforCoinMiner.Win64.Miner.gen
K7AntiVirusAdware ( 0057f0ea1 )
AlibabaRiskWare:Win64/Miners.111128eb
K7GWAdware ( 0057f0ea1 )
Cybereasonmalicious.b0e6d2
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/CoinMiner.SQ potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Ulise-9938012-0
Kasperskynot-a-virus:UDS:RiskTool.Win64.Miner.gen
BitDefenderGen:Variant.Application.Miner.43
AvastWin64:Malware-gen
EmsisoftGen:Variant.Application.Miner.43 (B)
ComodoApplicUnwnt@#1ze8q4igonhv9
DrWebTool.BtcMine.2609
TrendMicroPUA.BAT.PhoenixMiner.A.component
McAfee-GW-EditionRDN/Generic PUP.x
FireEyeGeneric.mg.958523cb0e6d2b1b
SophosGeneric PUA KN (PUA)
IkarusPUA.CoinMiner
GDataGen:Variant.Application.Miner.43
JiangminRiskTool.Miner.alq
AviraPUA/CoinMiner.Gen
MAXmalware (ai score=79)
Antiy-AVLTrojan/Generic.ASCommon.22B
ArcabitTrojan.Application.Miner.43
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4198781
McAfeeArtemis!958523CB0E6D
MalwarebytesRiskWare.BitCoinMiner
TrendMicro-HouseCallPUA.BAT.PhoenixMiner.A.component
RisingHackTool.CoinMiner!8.F154 (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/BtcMineNET.2!tr
BitDefenderThetaGen:NN.ZexaF.34606.fyW@aqIZMzdi
AVGWin64:Malware-gen
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Trojan.Caypnamer?

Trojan.Caypnamer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment