Threat Database Trojans Trojan.Occamy.O

Trojan.Occamy.O

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,495
Threat Level: 80 % (High)
Infected Computers: 44
First Seen: February 4, 2024
Last Seen: June 7, 2026
OS(es) Affected: Windows

The detection of Trojan.Occamy.O on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it is essential to understand its characteristics and take steps to remove it.

What Is Trojan.Occamy.O?

Trojan.Occamy.O is a type of Trojan horse malware that can infect your computer through various means, such as opening malicious email attachments, visiting compromised websites, or downloading infected software. Once installed, it can give unauthorized access to your system, allowing attackers to steal sensitive information, install additional malware, or disrupt your computer's operation.

How Trojan.Occamy.O Operates

Trojan.Occamy.O operates by exploiting vulnerabilities in your system or applications, allowing it to gain unauthorized access and control. It can communicate with its command and control servers to receive instructions, download additional malware, or transmit stolen data. This type of malware can also use social engineering tactics to trick users into installing it or providing sensitive information.

Trojan.Occamy.O can be difficult to detect, as it may not exhibit obvious symptoms of infection. However, it can still cause significant harm to your system and compromise your personal data. It is essential to be cautious when opening email attachments, clicking on links, or downloading software from the internet, as these are common ways for Trojans to spread.

Symptoms of Infection

While Trojan.Occamy.O may not always exhibit obvious symptoms, some common signs of infection include slow system performance, unexpected pop-ups or ads, and unfamiliar programs or icons on your desktop. You may also notice that your browser homepage or search engine has been changed, or that your system is crashing or freezing frequently.

  • Unexplained changes to your system settings or configuration
  • Appearance of suspicious or unfamiliar programs or files
  • Increased network activity or unusual data transmissions
  • System crashes or freezes

How to Remove Trojan.Occamy.O

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware infections.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your knowledge.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Occamy.O from your system requires careful attention to detail and a thorough understanding of the malware's characteristics. By following the steps outlined above and taking preventative measures to avoid future infections, you can help protect your system and personal data from the risks associated with this type of malware. Remember to always be cautious when interacting with the internet, and to keep your anti-malware software up to date to ensure the best possible protection against emerging threats.

Analysis Report

General information

Family Name: Trojan.Occamy.O
Signature status: Self Signed

Known Samples

MD5: b09514ad9505c578257d8670c9b44a99
SHA1: 4e0fadd29613e17d0fc9e0be1afa892dc63fbb4a
SHA256: 7929D53F7F24DE9753E5829371A92D4A50F765C0FFD54B53F1F0584B65A35894
File Size: 5.46 MB, 5461504 bytes
MD5: af85f07f5c3e22d2260903d1fc26beff
SHA1: 1c1cff4a3f5f6f1592d81505ae35983e6b1e5d84
SHA256: 942DCA73809986B73A704498B31EE57F0EB27F73ACBF15621C529C9DBA59D59B
File Size: 6.96 MB, 6960128 bytes
MD5: 83508af45bbdbf54a34edaeceede1ef1
SHA1: 9cb9dda13759e8c5d6d0f34130cdddacd2476179
SHA256: 1295990734AAC3B19FE9D937F0940FE9F401E883C01E222EE7583B3EE7C974AD
File Size: 3.20 MB, 3201448 bytes
MD5: 808073cb5c80571f48d1fd827ffa0b97
SHA1: 9cfe9163c9a085059dbc35c1b475349e38cf33a4
SHA256: 188620AB3D327540502BD982C4E2939F2938312020EFC53384BB2E8AA12CB762
File Size: 2.65 MB, 2645928 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 2.1.0.0
  • 1.0.8.1
  • 1.0.0.81
  • 1.0.0.0
Comments
  • Aplicativo para recuperar os arquivos XMLs (NFe, NFCe e CTe)
  • www.emvstudio.com
  • Многофункциональный комбайн для управления аккаунтами Instagram
Company Name
  • EMVStudio2.1
  • Perfect-Studio.net
  • TillBill - Desenvolvimento de Sistemas
File Description
  • CapturaXML
  • EMVStudio2.1
  • EspiaoCloud_certificado
  • InstAccountsManager
File Version
  • 2.1
  • 1.0.8.1
  • 1.0.0.81
  • 1.0.0.0
Internal Name
  • CapturaXML.exe
  • EMVStudio2.0.exe
  • EspiaoCloud_certificado.exe
  • InstAccountsManager.exe
Legal Copyright
  • Copyright © 2015
  • Copyright © 2019 - 2024
  • Copyright © 2025
  • Copyright © Perfect-Studio.net 2020
Legal Trademarks TillBill
Original Filename
  • CapturaXML.exe
  • EMVStudio2.0.exe
  • EspiaoCloud_certificado.exe
  • InstAccountsManager.exe
Product Name
  • Captura XML
  • EMVStudio2.1
  • EspiaoCloud_certificado
  • InstAccountsManager
Product Version
  • 2.1
  • 1.0.8.1
  • 1.0.0.81
  • 1.0.0.0

Digital Signatures

Signer Root Status
EspiaoCloud EspiaoCloud Self Signed

File Traits

  • .NET
  • Agile.net
  • Fody
  • HighEntropy
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 618
Potentially Malicious Blocks: 15
Whitelisted Blocks: 600
Unknown Blocks: 3

Visual Map

0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Occamy.FA
  • Occamy.J
  • Occamy.K
  • Occamy.M
  • Occamy.N
Show More
  • Occamy.O

Files Modified

File Attributes
c:\users\user\appdata\local\temp\protect2a3d628b.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\protect4a647d98.dll Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation

Related Posts

Trending

Most Viewed

Loading...