Trojan

Trojan.ChapakRI.S26141452 (file analysis)

Malware Removal

The Trojan.ChapakRI.S26141452 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ChapakRI.S26141452 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Divehi
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan.ChapakRI.S26141452?


File Info:

name: 587BCAE57D95EA12FF89.mlw
path: /opt/CAPEv2/storage/binaries/19ec7f8c5b27f230cc02dd7b0139ab671893f7da2043a4e3a5c6b35e90ab82a0
crc32: FD8539FC
md5: 587bcae57d95ea12ff89ef419d611266
sha1: 329d2a5f85b6b3b1141b536f1ca0b1685337adad
sha256: 19ec7f8c5b27f230cc02dd7b0139ab671893f7da2043a4e3a5c6b35e90ab82a0
sha512: b163bd7e0e8624ce537c7c309bc32b4ecbaebae51fa52a7846785e77d03d8757ba7fdbde5c4102cd6dd2d9b663a7a61c74a49eeb81e7e551ecc99c587d432d98
ssdeep: 6144:f/C5JvQIIkO7/ZiywopeTOwVkkq86QwFGvppFOJVSg:f/EJvQIIkO7ZFwopeThVkkr6QwFGvkJp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136747C10B7A0C034F5B356F449BAA275B52EBEA16B2891CB53D53BED96346D0EC3070B
sha3_384: 34ec73ebe427262bb6acff93dbcc4723b6922cd138a2dd09c447f8f07d315cf2a98eebb4efca7423dcf748a03828444f
ep_bytes: 8bff558bece876b10000e8110000005d
timestamp: 2021-01-04 12:06:31

Version Info:

0: [No Data]

Trojan.ChapakRI.S26141452 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.22298
MicroWorld-eScanTrojan.GenericKD.38401972
FireEyeGeneric.mg.587bcae57d95ea12
CAT-QuickHealTrojan.ChapakRI.S26141452
ALYacTrojan.GenericKD.38401972
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058c7251 )
AlibabaTrojan:Win32/Raccrypt.e9854790
K7GWTrojan ( 0058c7251 )
Cybereasonmalicious.f85b6b
CyrenW32/Kryptik.FSC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Smokeloader.F
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXBL5Z
Paloaltogeneric.ml
ClamAVWin.Packed.Generic-9918587-0
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.GenericKD.38401972
AvastWin32:DropperX-gen [Drp]
TencentBackdoor.Win32.Tofsee.16000134
Ad-AwareTrojan.GenericKD.38401972
SophosMal/Generic-S + Troj/Krypt-FV
ComodoMalware@#375j98a7id09z
BaiduWin32.Trojan.Kryptik.jm
TrendMicroTrojan.Win32.SMOKELOADER.YXBL5Z
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.fm
EmsisoftTrojan.GenericKD.38401972 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BSE.554AXK
JiangminTrojan.Chapak.ppg
AviraHEUR/AGEN.1210730
MAXmalware (ai score=89)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Raccrypt.GW!MTB
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.Stop.R461538
Acronissuspicious
McAfeePacked-GEE!587BCAE57D95
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingMalware.Obscure!1.A3BB (CLOUD)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HNWJ!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan.ChapakRI.S26141452?

Trojan.ChapakRI.S26141452 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment