Trojan

Trojan.Win32.Copak.rfya information

Malware Removal

The Trojan.Win32.Copak.rfya is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.rfya virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan.Win32.Copak.rfya?


File Info:

name: 4EB1094C4C37EAECC921.mlw
path: /opt/CAPEv2/storage/binaries/a229c866794636d297f84084fc7a6a5452e05149ececd1ef305990cfdef7d62f
crc32: A70A992B
md5: 4eb1094c4c37eaecc9215c27c954dde7
sha1: dc7361ed9fbea87afe3c1acf98669db8b214908d
sha256: a229c866794636d297f84084fc7a6a5452e05149ececd1ef305990cfdef7d62f
sha512: 37dc1fe5fa4b13f2bbd010ed380d6add2a067c2e5a55073632a27a4554391e0a39c894f6c3b32a5cf9929ab27cccc77472c6e69059511a59dec5258c5a7f718d
ssdeep: 1536:obzOl7+XB7VCWQ7opqNgaSJLxbYYR0A+u1TY5OnkX6/1/u++vzSTx:obaNgB75RImqYR0A+QY5Pw85vz8x
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D693026EAEBB220BC21C2CF534A9DCD169682EF710CB469B9718591DE1B577D0C82CC2
sha3_384: fa8c4d288c865fe60495f2e4a0e604c094827d0533e885941884a79299685ee349782056c0db06283e97776c26c2fba4
ep_bytes: b8000000005621d221ca8b1c2483c404
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.rfya also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Siggen18.32497
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.4eb1094c4c37eaec
ALYacGen:Variant.Razy.865537
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
K7GWTrojan ( 005435201 )
Cybereasonmalicious.d9fbea
BitDefenderThetaGen:NN.ZexaF.34582.fuY@aejYyMk
CyrenW32/Kryptik.ECM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
ClamAVWin.Packed.Razy-9952474-0
KasperskyTrojan.Win32.Copak.rfya
BitDefenderGen:Variant.Razy.865537
AvastWin32:Trojan-gen
TencentTrojan.Win32.Copak.pa
Ad-AwareGen:Variant.Razy.865537
VIPREGen:Variant.Razy.865537
McAfee-GW-EditionBehavesLike.Win32.Glupteba.nc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Razy.865537 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.ceri
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
ZoneAlarmTrojan.Win32.Copak.rfya
MicrosoftTrojan:Win32/IRCBot.MS!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FUBP.R493456
Acronissuspicious
McAfeeGlupteba-FUBP!4EB1094C4C37
VBA32BScope.Trojan.Wacatac
APEXMalicious
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.rfya?

Trojan.Win32.Copak.rfya removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment