Trojan

Should I remove “Trojan:Win32/SiennaPurple.A!dha”?

Malware Removal

The Trojan:Win32/SiennaPurple.A!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SiennaPurple.A!dha virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Trojan:Win32/SiennaPurple.A!dha?


File Info:

name: 54CA404D16DB18D233C6.mlw
path: /opt/CAPEv2/storage/binaries/99fc54786a72f32fd44c7391c2171ca31e72ca52725c68e2dde94d04c286fccd
crc32: 257ECBB2
md5: 54ca404d16db18d233c606b48c73d66f
sha1: d7d472bfc62bd6f52e3b4b3c7e88b92b664dd142
sha256: 99fc54786a72f32fd44c7391c2171ca31e72ca52725c68e2dde94d04c286fccd
sha512: 7e050f69257338bbb129b64671055d68e4232404f440c19157553eb9ddf103ec17f1053438d6692f29e921ca9e384ced684b4f89c0756ef9b414978aefdb5941
ssdeep: 24576:RtpRWh9e6yT5p0qMBNEYhw+fEh9vnwR76aNGu:Rch9JqMBNZNMh962c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D465BE22FB40D132F6A10072DA2D9F6B995CAE31673444D3B3D44E1E6AB48E35E36B47
sha3_384: ae402b758920cb39e5c024c0752ae284e3b39b2c17ac54c47620454f1e6c6f4da540ef882d574ae529d72d7803806540
ep_bytes: e8e3a50000e97ffeffff558bec568bf1
timestamp: 2021-10-08 04:32:44

Version Info:

0: [No Data]

Trojan:Win32/SiennaPurple.A!dha also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Bodegun.4!c
FireEyeGen:Heur.Bodegun.8
CAT-QuickHealTrojan.Siennapurple
McAfeeRansomware-HKH!54CA404D16DB
VIPREGen:Heur.Bodegun.8
SangforTrojan.Win32.Siennapurple.Vh0z
K7AntiVirusTrojan ( 00595a181 )
AlibabaTrojan:Win32/SiennaPurple.3bcf57f2
K7GWTrojan ( 00595a181 )
Cybereasonmalicious.d16db1
SymantecRansom.Gen
Elasticmalicious (high confidence)
ESET-NOD32Win32/Filecoder.OLY
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Agentb.gen
BitDefenderGen:Heur.Bodegun.8
ViRobotTrojan.Win32.S.Agent.1435136.B
MicroWorld-eScanGen:Heur.Bodegun.8
AvastWin32:Malware-gen
TencentWin32.Trojan.Filecoder.Swva
Ad-AwareGen:Heur.Bodegun.8
EmsisoftGen:Heur.Bodegun.8 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosMal/Generic-S + Troj/Ransom-GRL
GDataGen:Heur.Bodegun.8
WebrootW32.Ransom.H0lygh0st
ArcabitTrojan.Bodegun.8
ZoneAlarmHEUR:Trojan.Win32.Agentb.gen
MicrosoftTrojan:Win32/SiennaPurple.A!dha
AhnLab-V3Trojan/Win.SiennaPurple.C5207112
ALYacTrojan.Ransom.HolyGhost
MAXmalware (ai score=85)
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002H01GE22
RisingRansom.Agent!8.6B7 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34786.xrW@aO2Cb4
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Trojan:Win32/SiennaPurple.A!dha?

Trojan:Win32/SiennaPurple.A!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment