Trojan

About “Trojan.Win32.Chapak.esqn” infection

Malware Removal

The Trojan.Win32.Chapak.esqn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Chapak.esqn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Manipuri
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

bankshopstars.space
bankshopstars.bar
api.ipify.org

How to determine Trojan.Win32.Chapak.esqn?


File Info:

crc32: 4EC72D46
md5: f0011549f242b69cc3b620f1540c0a0f
name: upload_file
sha1: d44971e1b717b46058a1fecc6b8a19f2b536de85
sha256: 1c8ed4600279d1f7c32c1e4b16f8bcdf6f4210fdd550ba96b5a8327dde66858c
sha512: f76a36f3b919ee111b938dfc246e5283b1c6e10bbb92bd77a7eb0f8aa98fd2b9c5faad73f563b86379c5e5e2997cb156ddea4905022922870acf7eefb0496d30
ssdeep: 1536:TBI1L9X29fiP3Ybkkb4CQ/F9+WVAmH5HDM463kQ7tK:TBIQmIz09+WVAU5jN63lt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: efhsjyrg.ufr
ProductionVersus: 1.0.6.23
Copyrights: Copyrighds (C) 2020, xjdk
FileV: 1.0.3
TranslationUsi: 0x0872 0x0cd7

Trojan.Win32.Chapak.esqn also known as:

BkavW32.AIDetectVM.malware1
CynetMalicious (score: 100)
FireEyeGeneric.mg.f0011549f242b69c
McAfeePacked-GAO!F0011549F242
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 0056bb551 )
BitDefenderTrojan.GenericKD.43574054
K7GWTrojan ( 0056bb551 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
F-ProtW32/S-1a6111b9!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Dropper.KPOT-9204617-0
GDataTrojan.GenericKD.43574054
KasperskyTrojan.Win32.Chapak.esqn
AlibabaTrojan:Win32/Chapak.4bf7d213
NANO-AntivirusTrojan.Win32.Chapak.hpwgoo
MicroWorld-eScanTrojan.GenericKD.43574054
RisingTrojan.Kryptik!1.C98B (CLOUD)
Ad-AwareTrojan.GenericKD.43574054
EmsisoftTrojan.GenericKD.43574054 (B)
F-SecureTrojan.TR/Kryptik.ghllg
DrWebTrojan.DownLoader34.16991
ZillyaTrojan.Chapak.Win32.86923
TrendMicroTROJ_GEN.R03BC0WH120
MaxSecureTrojan.Malware.300983.susgen
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Banker.IcedID
CyrenW32/Trojan.BCEI-9247
AviraTR/Kryptik.ghllg
Antiy-AVLTrojan/Win32.Chapak
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D298E326
ZoneAlarmTrojan.Win32.Chapak.esqn
MicrosoftTrojan:Win32/Glupteba.DEB!MTB
AhnLab-V3Trojan/Win32.Tofsee.R346630
Acronissuspicious
VBA32Malware-Cryptor.Limpopo
ALYacTrojan.GenericKD.43574054
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HFHP
TrendMicro-HouseCallTROJ_GEN.R03BC0WH120
SentinelOneDFI – Suspicious PE
FortinetW32/Kryptik.HEZN!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.1b717b
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM10.2.EF3C.Malware.Gen

How to remove Trojan.Win32.Chapak.esqn?

Trojan.Win32.Chapak.esqn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment