Trojan

Trojan.Win32.Copak.lbpr (file analysis)

Malware Removal

The Trojan.Win32.Copak.lbpr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lbpr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lbpr?


File Info:

name: 5F70FDCDD173A0E69CCC.mlw
path: /opt/CAPEv2/storage/binaries/145a4a8bee5cf852faec7899f5a3bb274326e94291f66c30a5964f9892dae150
crc32: DD1510EB
md5: 5f70fdcdd173a0e69ccc0ee353659225
sha1: 685b384d96c8cf8b30f38aa570ad97d7d5542751
sha256: 145a4a8bee5cf852faec7899f5a3bb274326e94291f66c30a5964f9892dae150
sha512: 88c859df465b4539d9c8c8656c946aa1d34c54e2179be2e01db7f0acde5551e5e4c44e06906f837ae0be1c73a559032c3d3ccad1703eb328aaf4ad447969fc99
ssdeep: 3072:IXcIqaL74zdm2aXJSpFOz5P1Yml/ErQy7E362HlJHaG69xFFnAvh033:Kc/E74wkQDYm1TVtR69xFFnNH
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D5F3E137F9B3F1B8ECF6E131A12947AD1FBB7C01C47A9492878C414B9B64639D914B48
sha3_384: 8cd4d077cd7681dcffea71f9421670ea6182b9e96925e01e97b4cdd4d47af88c6fb5c53c44fbdac41751e470c2ab5997
ep_bytes: ba44ff68c768fee17b7f5e29c668d885
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lbpr also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.5f70fdcdd173a0e6
McAfeeGenericRXGJ-XZ!1496E7F2DB68
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.lbpr
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10cfae70
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.865537
JiangminTrojan.Copak.bmsx
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Injector
ArcabitTrojan.Razy.DD3501
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MAXmalware (ai score=88)
MalwarebytesTrojan.Crypt
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazofDNSwfpCe5dULIOz92W4/)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_89%
FortinetW32/Copak.AGMG!tr
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.dd173a
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Win32.Copak.lbpr?

Trojan.Win32.Copak.lbpr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment