Trojan

About “Trojan.Win32.Chapak.azrm” infection

Malware Removal

The Trojan.Win32.Chapak.azrm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.azrm virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Thai
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Collects and encrypts information about the computer likely to send to C2 server
  • Creates a hidden or system file
  • Detects Bochs through the presence of a registry key

How to determine Trojan.Win32.Chapak.azrm?


File Info:

name: 8EA3C50480430FCB4F62.mlw
path: /opt/CAPEv2/storage/binaries/7835a807f15db91f72046b741ce71c9a2ad01cb1cfb776a9ac05f2b816830fa3
crc32: 6EAD011E
md5: 8ea3c50480430fcb4f62170d24d5c620
sha1: 098d33db76bbdde891906097ae643fc4d0ec07e8
sha256: 7835a807f15db91f72046b741ce71c9a2ad01cb1cfb776a9ac05f2b816830fa3
sha512: 44245dbff8221a137cbb7e6f3c65517d3896f22cad68877956b74e48e4a2e751e66add3ad43d5ffa3b3ff52e20678b4517df2fdf0676268b41291f836115e73d
ssdeep: 49152:uVyYWmDMBL8A0/LPzDjGdYS89y/8FOyFeBGoDjzX9N/h91ipeMQNi30t9e+Ngv6f:WhWmHPDAn89ykK4orX9ZwpXKi30X3j
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122E533D0F190BB11E12BC9F99C5858C5AADADC1C1734B84B47961316BFBAF825273BC8
sha3_384: d57d46f698c0077993f361877799b1d2be5713789f9824406ed8b9461e2b6cbbbae721f49edd505a30da872592cecd3a
ep_bytes: e85c280000e978feffff8bff558bec83
timestamp: 2017-05-26 09:51:00

Version Info:

FileVersion: 1.0.0.1
ProductVersion: 1.0.0.1
Translation: 0x0809 0x04b0

Trojan.Win32.Chapak.azrm also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.59112
MicroWorld-eScanTrojan.AntiSandbox.GenericKD.42025499
FireEyeGeneric.mg.8ea3c50480430fcb
ALYacTrojan.Chapak.A
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.19701
K7AntiVirusTrojan ( 0053f3e31 )
AlibabaTrojan:Win32/Chapak.bb11f1b6
K7GWTrojan ( 0053f3e31 )
Cybereasonmalicious.480430
CyrenW32/Kryptik.MO.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GLXJ
Paloaltogeneric.ml
KasperskyTrojan.Win32.Chapak.azrm
BitDefenderTrojan.AntiSandbox.GenericKD.42025499
NANO-AntivirusTrojan.Win32.GandCrypt.fjioiz
AvastWin32:MalwareX-gen [Trj]
RisingTrojan.Generic@ML.100 (RDMK:pGhhQPjpAUFvRM80XMMtIw)
Ad-AwareTrojan.AntiSandbox.GenericKD.42025499
SophosMal/Generic-S + Mal/GandCrab-G
ComodoMalware@#2cosrbea3xyn5
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftTrojan.Agent (A)
IkarusTrojan.Win32.Krypt
JiangminTrojan.Generic.csrkf
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.28B4249
KingsoftWin32.Troj.Generic.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.C78
GDataTrojan.AntiSandbox.GenericKD.42025499
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.C4192941
Acronissuspicious
McAfeeGenericRXGN-GF!8EA3C5048043
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.MalPack.GS
APEXMalicious
TencentWin32.Trojan.Chapak.Eerj
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.COIX!tr
WebrootW32.Trojan.Gen
AVGWin32:MalwareX-gen [Trj]
PandaTrj/Kryptik.D
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Chapak.azrm?

Trojan.Win32.Chapak.azrm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment