Trojan

Trojan.Win32.Copak.kynm (file analysis)

Malware Removal

The Trojan.Win32.Copak.kynm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.kynm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan.Win32.Copak.kynm?


File Info:

name: 75F35B82A919B778AD55.mlw
path: /opt/CAPEv2/storage/binaries/b890c2afdd59df655e0f461099e82376cfdd0433a91b7fc7bb30c6b8868ace82
crc32: 6F742EAC
md5: 75f35b82a919b778ad5597d874715c56
sha1: 45f158cfb0ce5df6b155bd885f26a1c03e65a446
sha256: b890c2afdd59df655e0f461099e82376cfdd0433a91b7fc7bb30c6b8868ace82
sha512: 19bd86e65f356ffe66a003719529c385c4348ac9a66617b69bba802daa9c19837bba17bf41b49cfe30273d06787f47e8fec672542ef316d0d276a4c4ad5ffe72
ssdeep: 49152:F2G8o/lolrowvuPJURFiMnshax+nOEiLzW:F2go9zvuPJ+HqNnOxnW
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11475339F441B2EE0FD89CA366159EB0ABF9A3D595C14001CF72913A325F973F1429AF1
sha3_384: 086a95cc558fc153bd290cb884cd7148fe5128a3f2609408df3b6b1833e9fd66097afb7568c5ed4a720edecaaff046f4
ep_bytes: be000000005129c05f01d821c309c083
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.kynm also known as:

BkavW32.AIDetect.malware2
LionicRiskware.Win32.BitCoinMiner.1!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.75f35b82a919b778
CylanceUnsafe
VIPREPacker.NSAnti.Gen (v)
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 0057ffc71 )
K7AntiVirusTrojan ( 0057ffc71 )
CyrenW32/Kryptik.FGA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Pacex.Gen
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Copak.kynm
AvastWin32:CoinminerX-gen [Trj]
TencentTrojan.Win32.Coinminer.yi
SophosMal/Generic-R
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
TrendMicroTROJ_GEN.R002C0DL721
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
IkarusTrojan.Win32.Injector
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASBOL.C68F
GridinsoftRansom.Win32.Gen.sa
MicrosoftTrojan:Win32/Injector.RAQ!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R365685
McAfeeArtemis!75F35B82A919
VBA32Trojan.Packed
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R002C0DL721
RisingTrojan.Kryptik!1.D12D (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.EAHK!tr
BitDefenderThetaGen:NN.ZexaF.34062.InZ@auJi83j
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.fb0ce5
MaxSecureVirus.Sality.AA

How to remove Trojan.Win32.Copak.kynm?

Trojan.Win32.Copak.kynm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment