Trojan

About “Trojan:Win32/Offloader.CCHL!MTB” infection

Malware Removal

The Trojan:Win32/Offloader.CCHL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Offloader.CCHL!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering

How to determine Trojan:Win32/Offloader.CCHL!MTB?


File Info:

name: F81D0C572987216A47F7.mlw
path: /opt/CAPEv2/storage/binaries/763a6dc2dd98067c77e55fa51b00b633ce2721cc6cdaabe83bf1fb2f0a2b5349
crc32: B1F18C72
md5: f81d0c572987216a47f76054816a4ac4
sha1: e32c86d538b1501279d65a22c660b26b4b8af2fd
sha256: 763a6dc2dd98067c77e55fa51b00b633ce2721cc6cdaabe83bf1fb2f0a2b5349
sha512: 84f42a1817e20d78e48fe041a922171649072095b26f12dd4d508b4a58cc0dedec5851d56ca38059e16b3000bbad3fa8483b02559d6aeed2aea0ff01dc4fdf0f
ssdeep: 24576:1lE2MzI1NOIzp04qSVmGN6csDitNyNdEOM3:7hMz/YJhNPSEOM3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1301533F5A0D498D5E93F1036CDF5426AFBAEE22627A150E3435B5F1B1C33742A828DC6
sha3_384: 44c048afdb4141b025a1ab3b81070a2b94b5655d6399d548fbaf920079739d0c4b415bf67d6e75e339a5368237ad0010
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:41

Version Info:

0: [No Data]

Trojan:Win32/Offloader.CCHL!MTB also known as:

BkavW32.AIDetectMalware
AVGWin32:Malware-gen
MicroWorld-eScanGen:Variant.Nemesis.31305
FireEyeGen:Variant.Nemesis.31305
SkyhighBehavesLike.Win32.Suspicious.cc
MalwarebytesMalware.AI.354266180
Cybereasonmalicious.729872
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan-Spy.Win32.Windigo.gen
BitDefenderGen:Variant.Nemesis.31305
AvastWin32:Malware-gen
EmsisoftGen:Variant.Nemesis.31305 (B)
F-SecureHeuristic.HEUR/AGEN.1373317
VIPREGen:Variant.Nemesis.31305
TrendMicroTROJ_GEN.R002C0DB824
Trapminemalicious.moderate.ml.score
VaristW32/Downloader.SNXK-4798
AviraHEUR/AGEN.1373317
Antiy-AVLGrayWare/Win32.Wacapew
MicrosoftTrojan:Win32/Offloader.CCHL!MTB
ArcabitTrojan.Nemesis.D7A49
ZoneAlarmHEUR:Trojan-Spy.Win32.Windigo.gen
GDataGen:Variant.Nemesis.31305
GoogleDetected
VBA32suspected of Trojan.Downloader.gen
ALYacGen:Variant.Nemesis.31305
MAXmalware (ai score=81)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DB824
IkarusTrojan-Downloader.NSIS.Adload
FortinetNSIS/Adload.DS!tr
CrowdStrikewin/grayware_confidence_90% (D)

How to remove Trojan:Win32/Offloader.CCHL!MTB?

Trojan:Win32/Offloader.CCHL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment