Trojan

What is “Trojan.Win32.Chapak.abcn”?

Malware Removal

The Trojan.Win32.Chapak.abcn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.abcn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Detects the presence of Wine emulator via function name
  • Detects Sandboxie through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

booomaahuuoooapl.ru
eoufaoeuhoauengi.ru
maeobnaoefhgoajo.ru
ashihsijaediaehf.ru
plpanaifheaighai.ru
iuefgauiaiduihgs.ru
aeiziaezieidiebg.ru
aneoeauhiazegfiz.ru
uoaeogauhduadhug.ru
plpoiupakludkosa.ru
booomaahuuoooapl.su
eoufaoeuhoauengi.su
maeobnaoefhgoajo.su
ashihsijaediaehf.su
plpanaifheaighai.su
iuefgauiaiduihgs.su
aeiziaezieidiebg.su
aneoeauhiazegfiz.su
uoaeogauhduadhug.su
plpoiupakludkosa.su
booomaahuuoooapl.in
eoufaoeuhoauengi.in
maeobnaoefhgoajo.in
ashihsijaediaehf.in
plpanaifheaighai.in
iuefgauiaiduihgs.in
aeiziaezieidiebg.in
aneoeauhiazegfiz.in
uoaeogauhduadhug.in
plpoiupakludkosa.in
booomaahuuoooapl.net
eoufaoeuhoauengi.net
maeobnaoefhgoajo.net
ashihsijaediaehf.net
plpanaifheaighai.net
iuefgauiaiduihgs.net
aeiziaezieidiebg.net
aneoeauhiazegfiz.net
uoaeogauhduadhug.net
plpoiupakludkosa.net
booomaahuuoooapl.com

How to determine Trojan.Win32.Chapak.abcn?


File Info:

crc32: F137DDD2
md5: 5850c6df197c6d61dd815ce46364edcc
name: 5850C6DF197C6D61DD815CE46364EDCC.mlw
sha1: 079f3b344bc0e91b0bb7ba833510b123dacb9220
sha256: d8282105f71b7e8c37ab199ec5dbcc10c331782e03ff1ac70ab50d212ebbf552
sha512: e22f22c9a86580c7ece24105f57549c5483609074e538a5bbb8d24f5f59cf43f87ae12ec635843b85d8b6238c6122cd4e9f1b69f272acbec97b38ef1e46152a0
ssdeep: 3072:Vza7ooY9lk+Mgeremj0l+yBNP1uKXkWL5SHdM1XrrsrrrP0ZZZZZZZZZzZZZZZZ:Vetq4dremj0rl1uCEOwdJO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0808 0x04b0

Trojan.Win32.Chapak.abcn also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner2.40254
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacTrojan.BRMon.Gen.4
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Phorpiex.eea8b09b
K7GWAdware ( 004ef1551 )
Cybereasonmalicious.f197c6
CyrenW32/GandCrab.H.gen!Eldorado
ESET-NOD32Win32/Phorpiex.J
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.Phorpiex-9818009-1
KasperskyTrojan.Win32.Chapak.abcn
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.GenKryptik.fdxtjk
ViRobotTrojan.Win32.Agent.232960.Q
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentMalware.Win32.Gencirc.114dd6b4
Ad-AwareTrojan.BRMon.Gen.4
SophosML/PE-A + Mal/GandCrab-B
ComodoTrojWare.Win32.TrojanDownloader.Upatre.GP@7ou4hv
BitDefenderThetaGen:NN.ZexaF.34170.ouW@aiVZgmaO
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.URSNIF.SMD2.hp
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
FireEyeGeneric.mg.5850c6df197c6d61
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.GandCrypt.ej
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1121589
Antiy-AVLTrojan/Generic.ASMalwS.2691AE6
MicrosoftTrojan:Win32/Phorpiex.AR!MTB
SUPERAntiSpywareBackdoor.Andromeda/Variant
GDataTrojan.BRMon.Gen.4
TACHYONTrojan/W32.Chapak.232960
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
McAfeeTrojan-FPST!5850C6DF197C
MAXmalware (ai score=99)
VBA32BScope.Trojan.Encoder
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMD2.hp
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.GenAsa!fSr3du7EiLY
IkarusTrojan-Dropper.Win32.Danabot
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GOGY!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml

How to remove Trojan.Win32.Chapak.abcn?

Trojan.Win32.Chapak.abcn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment