Threat Database Trojans Trojan.Chapak.FI

Trojan.Chapak.FI

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,304
Threat Level: 80 % (High)
Infected Computers: 9
First Seen: September 28, 2023
Last Seen: November 10, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Chapak.FI
Signature status: No Signature

Known Samples

MD5: 02a95c32ba0d22c3c63d77ec79491924
SHA1: 3bb3dc3c7dfcdbeafd249aaa1d0223d9b9326ec3
SHA256: ACF611222DEDF92B6C9E37F600FBC7D0E575E49D45119FB65863F1EDE4A5BBEE
File Size: 6.79 MB, 6787128 bytes
MD5: e76aa6974a75830cabd942b1faf25aa1
SHA1: 084e8ff840004bc927d8e085cf36cdea8285bbab
SHA256: F41C011C1889D41E369FE8271E6A64245DF876EBA72495891381ED6728931019
File Size: 7.33 MB, 7330053 bytes
MD5: 2b8f5c2baddf8db47562a674f98ea849
SHA1: 50b6babfab02e51ab5d50b490315ce821af1c66b
SHA256: FD6AD175F0E07E57C7D57303B1B7C908926FF473E3CC6E2A6A09A2E0E13C6D36
File Size: 7.86 MB, 7863193 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Igor Pavlov
File Description 7z Setup SFX
File Version 9.20
Internal Name 7zS.sfx
Legal Copyright Copyright (c) 1999-2010 Igor Pavlov
Original Filename 7zS.sfx.exe
Product Name 7-Zip
Product Version 9.20

File Traits

  • 2+ executable sections
  • VirtualQueryEx
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\adobenotificationhelper.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\adobenotificationhelper.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\config.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\config.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\control surface.nfo Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\control surface.nfo Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\dns_sd.jar Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\dns_sd.jar Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\fruity delay 2.nfo Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\7zs3b11.tmp\fruity delay 2.nfo Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\fruity x-y-z controller.nfo Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\fruity x-y-z controller.nfo Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\imagearray.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\imagearray.json Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\license.rtf Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\license.rtf Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\mdnsnsp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\mdnsnsp.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\mdnsresponder.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\mdnsresponder.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\microsoft_vc110_debugopenmp_arm.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\microsoft_vc110_debugopenmp_arm.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\microsoft_vc120_cxxamp_x86.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\microsoft_vc120_cxxamp_x86.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\qp5blml9lnxw.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3b11.tmp\qp5blml9lnxw.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\cofr.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\cofr.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\config.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\config.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\fruity peak controller.fst Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\fruity peak controller.fst Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\fruity x-y controller.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\fruity x-y controller.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\qt5svg.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\qt5svg.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\smpte-c.icc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\smpte-c.icc Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\vrfauto.h Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs516c.tmp\vrfauto.h Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\ bonjour.lnk Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\config.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\config.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\euroscaleuncoated.icc Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\euroscaleuncoated.icc Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\fruity delay 2.fst Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\fruity delay 2.fst Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\fruity reeverb 2.fst Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\fruity reeverb 2.fst Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\hl34tpxcm.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\hl34tpxcm.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\imagearray.json Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\imagearray.json Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\pcd.db Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\pcd.db Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\unzip32.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\unzip32.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\vrfauto.h Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs63bc.tmp\vrfauto.h Synchronize,Write Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

.\cOFR.exe
.\QP5BLML9lnxW.exe

Trending

Most Viewed

Loading...