Trojan

Trojan.Win32.Copak.aeryu (file analysis)

Malware Removal

The Trojan.Win32.Copak.aeryu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.aeryu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Copak.aeryu?


File Info:

name: 3A11501B8BFB77556F28.mlw
path: /opt/CAPEv2/storage/binaries/b758a51d8d87136aec83527697b4e30de7ff03d3b1547b7719532fe42ddba0ae
crc32: 7A8123AB
md5: 3a11501b8bfb77556f287b4f5d70fc4f
sha1: 4cb260c915c1f9fe441665b9c8539186b619bac8
sha256: b758a51d8d87136aec83527697b4e30de7ff03d3b1547b7719532fe42ddba0ae
sha512: af0a4b4c578444d01473dddec5a275af79ad913dace5c22eeeb93b7b52eb695ccc070b6e68223d5bf95141364b5af619231aaeb9b6e0ce6b2af1d13e01537961
ssdeep: 12288:n4t5NRXhGXzv3B0vKjVDa/ZSoPDm3Xx/MCtjW:M5NeXzv3B6Ya/ZSoPDQ+ei
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11655D3581E5576B3CC06367D692EAE620010AF3F661AF2613783B5FE7E112C0DF1692E
sha3_384: 4e229239cdf45426fa050f29a747a0e615b9001405789129f0b40aebe3b275279831c4fedc0b6017e443e0bf2acdc42e
ep_bytes: d58dfd0485e4798380057012024f18a8
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.aeryu also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.98449
ClamAVWin.Packed.Dridex-9860931-1
FireEyeGeneric.mg.3a11501b8bfb7755
SkyhighBehavesLike.Win32.Generic.tm
McAfeeTrojan-FVOQ!3A11501B8BFB
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.2644245
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
AlibabaTrojan:Win32/Glupteba.e19b6c18
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D18091
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GIFY
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.aeryu
BitDefenderTrojan.GenericKDZ.98449
NANO-AntivirusTrojan.Win32.Selfmod.ifcxaw
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
TACHYONTrojan/W32.Selfmod
EmsisoftTrojan.GenericKDZ.98449 (B)
F-SecureTrojan.TR/Glupteba.glcdx
DrWebTrojan.Siggen12.42976
VIPRETrojan.GenericKDZ.98449
TrendMicroTROJ_GEN.R049C0DHM23
Trapminesuspicious.low.ml.score
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Selfmod.zqn
GoogleDetected
AviraTR/Glupteba.glcdx
Antiy-AVLTrojan/Win32.Kryptik.gify
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmTrojan.Win32.Copak.aeryu
GDataWin32.Trojan.PSE.11YPVZ
VaristW32/Trojan.MJSE-7842
AhnLab-V3Trojan/Win.OB.C5394211
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36792.q9Z@aaiSldb
ALYacTrojan.GenericKDZ.98449
MAXmalware (ai score=81)
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R049C0DHM23
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.915c1f
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Copak.aeryu?

Trojan.Win32.Copak.aeryu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment