Trojan

Trojan:Win32/Occamy.CA4 (file analysis)

Malware Removal

The Trojan:Win32/Occamy.CA4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Occamy.CA4 virus can do?

  • Creates RWX memory
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

How to determine Trojan:Win32/Occamy.CA4?


File Info:

crc32: 0EC0FD21
md5: d1d3da469fded971587a3b1eff99a335
name: binded.exe
sha1: 1c18516a7a05123b065a38d45b4b4093df99376d
sha256: a4c1251eebcec362abd2ebb7d795660655fb708b66b71ab9e80aa3f2ed2d25e5
sha512: c7eb9428897d91d1b8fb977c5c9e05c01c5b526e64120dd16145828366ba96dcd9ada7015811cba730bec0035b17c5d906800e8b47b75d6b00e5710b859ef6f9
ssdeep: 24576:E7LIQ1oJv5NBpNeKNMV7Bm0nHZ/jIr4cgnbRV9xEE/:k4NzNLOHNsrREf
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: binded.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: binded.exe

Trojan:Win32/Occamy.CA4 also known as:

MicroWorld-eScanGen:Variant.Kazy.42068
FireEyeGeneric.mg.d1d3da469fded971
CAT-QuickHealTrojan.Wacatac
McAfeeTrojan-FOYS!D1D3DA469FDE
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Kazy.42068
K7GWTrojan ( 00567a071 )
K7AntiVirusTrojan ( 00567a071 )
Invinceaheuristic
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojan.MSIL.WACATAC.THFAIBO
Paloaltogeneric.ml
ClamAVWin.Dropper.njRAT-7473933-0
GDataGen:Variant.Kazy.42068
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/Generic.207938f9
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Generic.Wrpz
Ad-AwareGen:Variant.Kazy.42068
SophosMal/Generic-S
ComodoTrojWare.MSIL.Noancooe.CDT@7jluau
F-SecureTrojan.TR/Dropper.MSIL.Gen
DrWebTrojan.MulDrop7.47478
TrendMicroTrojan.MSIL.WACATAC.THFAIBO
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
EmsisoftGen:Variant.Kazy.42068 (B)
IkarusTrojan-Dropper.MSIL.Agent
JiangminTrojan.Generic.flekz
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Kazy.DA454
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Occamy.CA4
CynetMalicious (score: 100)
ALYacGen:Variant.Kazy.42068
MAXmalware (ai score=88)
MalwarebytesBackdoor.Agent.PGen
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DTP
RisingSpyware.AgentTesla!1.B864 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Agent.CDT!tr
BitDefenderThetaGen:NN.ZemsilF.34128.on0@a01d10d
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.69fded
AvastWin32:RATX-gen [Trj]
Qihoo-360Win32/Trojan.ae8

How to remove Trojan:Win32/Occamy.CA4?

Trojan:Win32/Occamy.CA4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment