Trojan

Should I remove “Trojan.Win32.Chapak.dnan”?

Malware Removal

The Trojan.Win32.Chapak.dnan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.dnan virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

How to determine Trojan.Win32.Chapak.dnan?


File Info:

name: F2B238120AFB8665B95A.mlw
path: /opt/CAPEv2/storage/binaries/39a6f1c967f7c5d3906cc0fc2dbecd41f5ce9b13420ca205858b42003ae031ef
crc32: AC03BFCE
md5: f2b238120afb8665b95afd44b727701f
sha1: 0ff3830d8786cc2fa653423accb04401e074d00b
sha256: 39a6f1c967f7c5d3906cc0fc2dbecd41f5ce9b13420ca205858b42003ae031ef
sha512: 32a4c2604924a8cbab466485c941bc5a539a8b5ae5b072173039d28a985f1bab45f385518b42072e682c6de0950eb0918b654956d0f9fd34e86e00c0e25a9494
ssdeep: 12288:wO97vQrGUARTWnyf2uv4lPDLrzzSmCgRQbPQJscnJeyW5esk:99TQrGb5fPuNQbPU5WQP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EAF4F112B4D48033D5B342724568E72246BFBE725A764ABB2BCC4E4D1A744C1AF3A773
sha3_384: cf01467260f588c5e5bee5da6680809d349329b0da18b196f732969cdbdbd3df8e0a84e34d0e5fcc6238492eb33c3d79
ep_bytes: e8bd860000e939feffffcccccccccccc
timestamp: 2018-09-16 09:21:11

Version Info:

0: [No Data]

Trojan.Win32.Chapak.dnan also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Brsecmon.1
FireEyeGeneric.mg.f2b238120afb8665
CAT-QuickHealRansom.Stop.MP4
ALYacTrojan.Brsecmon.1
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0055204a1 )
K7AntiVirusTrojan ( 0055204a1 )
BitDefenderThetaGen:NN.ZexaF.34062.TuW@aa!nyoeG
CyrenW32/S-d75e9604!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GTYY
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Score-6995873-0
KasperskyTrojan.Win32.Chapak.dnan
BitDefenderTrojan.Brsecmon.1
AvastWin32:Trojan-gen
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazpJLYoOBne4+ByPdLSgZYD+)
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-R + Mal/GandCrab-G
ComodoTrojWare.Win32.Fakecsrss.AV@88nqyj
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.Brsecmon.1
eGambitUnsafe.AI_Score_99%
AviraTR/AD.VidarStealer.anqd
MAXmalware (ai score=83)
ArcabitTrojan.Brsecmon.1
MicrosoftTrojan:Win32/Kryptik.DR!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/MalPe18.Suspicious.X1989
Acronissuspicious
McAfeeSodinokibi!F2B238120AFB
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.MalPack.GS.Generic
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
TencentWin32.Trojan.Chapak.Eddi
YandexTrojan.Chapak!RA+RffEsMwo
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.DQHN!tr
WebrootW32.Malware.Gen
AVGWin32:Trojan-gen
Cybereasonmalicious.20afb8

How to remove Trojan.Win32.Chapak.dnan?

Trojan.Win32.Chapak.dnan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment