Trojan

Trojan.Win32.Copak.lauu (file analysis)

Malware Removal

The Trojan.Win32.Copak.lauu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lauu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Win32.Copak.lauu?


File Info:

name: E8CAA89CD0402EEB64BC.mlw
path: /opt/CAPEv2/storage/binaries/fced958de51d0ea75397cacb4dc1ec7331c94115459c2a50cc74ef6a31857943
crc32: 3B407C17
md5: e8caa89cd0402eeb64bcd25ce62a550e
sha1: 7841eebbfeda140549923c3f058425121abfd0ae
sha256: fced958de51d0ea75397cacb4dc1ec7331c94115459c2a50cc74ef6a31857943
sha512: 76052f25d80b5959ee2a60aa1be17c7b878d813b78d28d749ca79ea19c2ceeda9c221740f0ab5c0a58cebefbf650fb6573833cd71a9965d64453f2ba61c1b520
ssdeep: 12288:7UKLj8ctHVF1BIgHGoUh3jQbAMo/zsbF1njfaveWDN0Q9gSk4E4VbAMo/zsbF1nI:6cqEcWbbnjuNP9pVcWbbnI
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14A0511A301CABB7BF455C5B28B94C3B97DADF7D5204560665BEB085F0F648D006E8EE0
sha3_384: 527e00982be9ee2192d3b5fc244b884e7a5edd0759a86d73111dbef542d59d16fd79e63c80970d82d6e69d578b17e485
ep_bytes: baafef167e21f083ec04c70424d88540
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lauu also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.7487
MicroWorld-eScanGen:Variant.Razy.870640
FireEyeGeneric.mg.e8caa89cd0402eeb
ALYacGen:Variant.Razy.870640
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.cd0402
BitDefenderThetaGen:NN.ZexaF.34114.YuZ@aOhSZ5
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
ClamAVWin.Malware.Razy-9916224-0
KasperskyTrojan.Win32.Copak.lauu
BitDefenderGen:Variant.Razy.870640
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentMalware.Win32.Gencirc.10cfb50c
Ad-AwareGen:Variant.Razy.870640
EmsisoftGen:Variant.Razy.870640 (B)
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.870640
JiangminTrojan.Copak.bjzj
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
Acronissuspicious
McAfeeGenericRXGJ-XZ!D78FC4C26C65
MAXmalware (ai score=80)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
APEXMalicious
RisingTrojan.Kryptik!1.D284 (RDMK:cmRtazrERM0iCxd9YkccePGqKbf5)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.lauu?

Trojan.Win32.Copak.lauu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment