Trojan

Trojan.ChapakPMF.S26307769 information

Malware Removal

The Trojan.ChapakPMF.S26307769 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ChapakPMF.S26307769 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Serbian
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Trojan.ChapakPMF.S26307769?


File Info:

name: A7D061DAB892BE235513.mlw
path: /opt/CAPEv2/storage/binaries/219dee12ba42f5c39a9d72f5fa36bb672178b55d939d93efa164f89c5bc4138c
crc32: B9212A9B
md5: a7d061dab892be235513976179d68d80
sha1: ec9fa4c3394147943c5603a64d36cc06ce765669
sha256: 219dee12ba42f5c39a9d72f5fa36bb672178b55d939d93efa164f89c5bc4138c
sha512: 9e8654beb5e9b2642ef4ea1ac9c2a4c6632ebfd9e1928463feab620ff2d3a88160db2aa7c44d05152630bdbb5ee1cb48def1559a31ba392d1ce3ee2a83eb95e1
ssdeep: 6144:MqNAIL3hTYxQrwt50EkCRszonS50SB1qj6MpjwuMxJU:NFjhTYxQrgRe0y+6MpsuZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10F84E0343D90D432CC866530497ACFA19ABD7C71A8608A4737E8AB6E6F312C1567736F
sha3_384: f0363bae36ffeeb7f3d8326fbc3f5e63c2df4a686b84cfe2d1a3e098acb2b05f118e65be113c2127176ab96534e564ab
ep_bytes: e815500000e979feffff832544a14500
timestamp: 2020-12-26 04:52:06

Version Info:

FileVersion: 21.29.120.69
InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkorta
ProjectVersion: 1.10.70.57
Translations: 0x0121 0x03ca

Trojan.ChapakPMF.S26307769 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.SmartFortress.lEDV
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38637855
FireEyeGeneric.mg.a7d061dab892be23
CAT-QuickHealTrojan.ChapakPMF.S26307769
McAfeePacked-GEE!A7D061DAB892
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaPacked:Application/Obfuscated.4f557e65
K7GWTrojan ( 0058d5cd1 )
K7AntiVirusTrojan ( 003e58dd1 )
CyrenW32/Qbot.FK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HOBC
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9936948-0
KasperskyHEUR:Exploit.Win32.Shellcode.gen
BitDefenderTrojan.GenericKD.38637855
SUPERAntiSpywareTrojan.Agent/Generic
AvastWin32:AceCrypter-B [Cryp]
TencentWin32.Exploit.Shellcode.Lpbc
EmsisoftTrojan.Crypt (A)
DrWebTrojan.PWS.Stealer.26952
TrendMicroTROJ_GEN.R002C0PAK22
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fh
SophosMal/Generic-R + Mal/Agent-AWV
SentinelOneStatic AI – Malicious PE
JiangminExploit.ShellCode.ghk
WebrootW32.Trojan.Gen
AviraTR/AD.GenSHCode.csjuh
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/StopCrypt.PAQ!MTB
ViRobotTrojan.Win32.Z.Agent.399872.JV
ZoneAlarmHEUR:Exploit.Win32.Shellcode.gen
GDataWin32.Trojan.BSE.12FNXDY
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.GEE.R466730
BitDefenderThetaGen:NN.ZexaF.34182.yq0@aSjuTIfG
ALYacTrojan.GenericKD.38637855
MAXmalware (ai score=88)
VBA32BScope.Trojan.Convagent
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R002C0PAK22
RisingExploit.Shellcode!8.2A (CLOUD)
YandexTrojan.Kryptik!UInePUF7W9k
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_54%
FortinetW32/Kryptik.HOCG!tr
AVGWin32:AceCrypter-B [Cryp]
Cybereasonmalicious.339414
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.ChapakPMF.S26307769?

Trojan.ChapakPMF.S26307769 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment