Trojan

What is “Trojan.Win32.Nimnul”?

Malware Removal

The Trojan.Win32.Nimnul is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Nimnul virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Trojan.Win32.Nimnul?


File Info:

name: D95802EB2523210E0714.mlw
path: /opt/CAPEv2/storage/binaries/d35b806cc5281e1eaaddb64b1820bb880400a71cd41986e499c885f05901ad70
crc32: 5AFCFC49
md5: d95802eb2523210e071414ece89a67dd
sha1: f56c021574fff9f9163f71d99b0c7dcbf39fef9d
sha256: d35b806cc5281e1eaaddb64b1820bb880400a71cd41986e499c885f05901ad70
sha512: d2da0215723b66b1f1796f89ad36fb105e2b1fafddc9911bdf84483031efbb155b614102649c41a1f0fba5fb0e93ef62ac7281dec493b76bb91ff6787dcf2769
ssdeep: 49152:5lDTYNYnb2AANTaApCCBBiM2+s8KuqGaX0ToIBAUZLYm:r+Ynb2vRJpCCBLJBAUZLB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160E5481DAAC38CA1D779173CCC662FFE9A259D313A218AC7E374FD684A32150D5AF109
sha3_384: debc590415032bc2d6db7114cc40962c92d7efffaa6644dd31aa6da3892e982337677e1301e4405f60c1dfc066c5675e
ep_bytes: 558bec6aff68d8a86b006864cf4b0064
timestamp: 2017-04-15 16:28:07

Version Info:

FileVersion: 3.0.17.415
FileDescription: 丨EY丨边境助手
ProductName: 易雲1990056222
ProductVersion: 3.0.17.415
CompanyName: 易雲1990056222
LegalCopyright: EY福慧双修師院版权所有,盗版必究!
Comments: EY福慧双修師院
Translation: 0x0804 0x04b0

Trojan.Win32.Nimnul also known as:

LionicTrojan.Win32.Nimnul.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.d95802eb2523210e
McAfeeArtemis!D95802EB2523
CylanceUnsafe
SangforTrojan.Win32.Nimnul.gen
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojan:Win32/Tonmye.3e8074a1
K7GWTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaF.34182.jt0@a4TxuSjH
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9820446-0
KasperskyHEUR:Trojan.Win32.Nimnul.gen
AvastWin32:Malware-gen
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
TrendMicroTROJ_GEN.R002C0DB422
McAfee-GW-EditionBehavesLike.Win32.Generic.wh
MaxSecureTrojan.Malware.300983.susgen
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Tonmye.gen!A
ZoneAlarmHEUR:Trojan.Win32.Nimnul.gen
GDataWin32.Trojan.Agent.BEDFTG
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2438900
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002C0DB422
RisingHackTool.GameHack!1.B2A6 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetRiskware/Application
AVGWin32:Malware-gen
Cybereasonmalicious.574fff
PandaTrj/GdSda.A

How to remove Trojan.Win32.Nimnul?

Trojan.Win32.Nimnul removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment