Trojan

Trojan.Win32.Copak.kyiz (file analysis)

Malware Removal

The Trojan.Win32.Copak.kyiz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kyiz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.kyiz?


File Info:

name: 9BF0A2389BED09115D21.mlw
path: /opt/CAPEv2/storage/binaries/902d9a29601070d97f81b7af4ddaf270148b2a6c8ec52a10507bb09c3c72dffd
crc32: E1ABCD9A
md5: 9bf0a2389bed09115d210ee4bcb949f7
sha1: 3370d6d4dda92a664dc9a908b4c9617bf769230e
sha256: 902d9a29601070d97f81b7af4ddaf270148b2a6c8ec52a10507bb09c3c72dffd
sha512: 5cf8640c439950b92895ade8eb26406f7de737c6e9fb0a8ed37688a208df568b6ef81084265595da65c89b08f579a6fddcfce082e6e84a705ea906c08cde6111
ssdeep: 49152:sDiqSK0KKQPZe5CJfRj08gh2mxApfFAWKiFF1gUJ3wIIP4x7LQ:eSK0KKQRiCXpgh2malFAoF1T3AAQ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T113B53368047AFDAFF90CE932FEAA13904DF98690E4D6A51283181F1D3F311517F626A7
sha3_384: ccb05ba0a9c402569865ecb0b16e40a3b4a145f599f76d6d6111c9908a104257cb8632dea2335fb08a387931dfa4de0e
ep_bytes: b80000000083ec0489342421d14a5fba
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kyiz also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47576058
FireEyeTrojan.GenericKD.47576058
ALYacTrojan.GenericKD.47576058
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057ffc71 )
K7GWTrojan ( 0057ffc71 )
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.kyiz
BitDefenderTrojan.GenericKD.47576058
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
Ad-AwareTrojan.GenericKD.47576058
SophosMal/Generic-R
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
TrendMicroTROJ_GEN.R002C0DL521
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftTrojan.GenericKD.47576058 (B)
IkarusTrojan.Win32.Injector
GDataTrojan.GenericKD.47576058
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASBOL.C68F
GridinsoftRansom.Win32.Gen.sa
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4304577
McAfeeGenericRXAA-FA!9BF0A2389BED
VBA32Trojan.Packed
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DL521
RisingTrojan.Injector!1.C865 (CLASSIC)
YandexTrojan.Copak!JpeUGZOgFgU
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.EAHK!tr
BitDefenderThetaGen:NN.ZexaF.34062.toZ@a4gaqeb
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.kyiz?

Trojan.Win32.Copak.kyiz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment