Trojan

Trojan.Win32.Copak information

Malware Removal

The Trojan.Win32.Copak is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Copak?


File Info:

name: 8165D97BEF0954D98311.mlw
path: /opt/CAPEv2/storage/binaries/8a1f7480184c41d5e71ee33222a1efef974d6743aff8180dfa1272b3cc1e5e3f
crc32: 007A432C
md5: 8165d97bef0954d98311d9e9ffaa4658
sha1: 9714981d154041b81cddd8b7f256085ef72be1df
sha256: 8a1f7480184c41d5e71ee33222a1efef974d6743aff8180dfa1272b3cc1e5e3f
sha512: fdfde788f1dc2e22b832107733a68f80d07c472641dfe2b2df435cefc5ad8c12fecc8906ae30ffcebefec27c2dcb6319283bf5fef4b91f9ca5cca7d7a9c2b231
ssdeep: 3072:qIiffQ/4Ra575Qgzn9QRvw2ToMrDrx2hZ2GBgXk/5rxhO1rBtKcCrHeQimbUfKc4:tf/8a7Q2R2To4126GOcfVTbimiKS8Zrt
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19704E06FB34513B1C28203B33A0E99D2F71AD67A237A8AE05069445E2353DB853BF7D5
sha3_384: 446ecaac4e83f48f907767c0845e7af1b60b9655dca635df6458431dcf43f74ef150e107a17f848c15e1942e2a22d6ef
ep_bytes: 5589e5be0000000089cb81ef8eb417ba
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.866955
SkyhighBehavesLike.Win32.Generic.cm
McAfeeGenericRXOS-KI!8165D97BEF09
MalwarebytesTrojan.MalPack.Generic
ZillyaTrojan.CopakGen.Win32.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
BitDefenderGen:Variant.Razy.866955
K7GWTrojan ( 0058c5ff1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Packed.Razy-10010080-0
KasperskyHEUR:Trojan.Win32.Copak.gen
RisingTrojan.Generic@AI.100 (RDML:j9tV+j5sROhBmIVlg9u23Q)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Packed2.43250
VIPREGen:Variant.Razy.866955
FireEyeGeneric.mg.8165d97bef0954d9
EmsisoftGen:Variant.Razy.866955 (B)
IkarusTrojan.Win32.Injector
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Kryptik.DZR.gen!Eldorado
Kingsoftmalware.kb.b.956
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Razy.DD3A8B
ZoneAlarmHEUR:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.855VXQ
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2860595
BitDefenderThetaGen:NN.ZexaF.36792.kmZ@aeBy@@e
ALYacGen:Variant.Razy.866955
MAXmalware (ai score=89)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Copak.pe
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.d15404
AvastWin32:Evo-gen [Trj]

How to remove Trojan.Win32.Copak?

Trojan.Win32.Copak removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment