Trojan

Trojan.Win32.Copak.luro (file analysis)

Malware Removal

The Trojan.Win32.Copak.luro is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.luro virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Trojan.Win32.Copak.luro?


File Info:

name: 300465B1F66CA50CCE91.mlw
path: /opt/CAPEv2/storage/binaries/3c07d45150d4584940980f3ab03d3429bf02c1d520bb4fb577d4ee256d98f939
crc32: 3DF924E7
md5: 300465b1f66ca50cce9191e3a31d42de
sha1: 4c30393a2d14319a3fc96f133c1b9fdd96619108
sha256: 3c07d45150d4584940980f3ab03d3429bf02c1d520bb4fb577d4ee256d98f939
sha512: 58452b6c595fe1f1a615874e4f73902b47e4c1e1c1ae0a45615daf2561a1da63792722fb67abe3d9331c77ec25e8bcbd10c273eb94b9354c263cccc8e56ab969
ssdeep: 3072:7RV5ZUJunBxJ0OWiCAtXlbi76V44bEuPw1H1QybfRc/3Q/YQ:rAJkB3Wi/RRJzo1H1hu/A/YQ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E9F3E0CED7D63435ED0F0B37C9C64462B9198372E35E284A16A6CF52C4AB2CD879127B
sha3_384: d8e6ef2aa9cdaf6b408207eca156f2f264adb42ecdead040635486bac4e9617e8f0cdb508f16f045605769bdcc548ce9
ep_bytes: 6809eaabc25e01c981e931da8ae483ec
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.luro also known as:

BkavW32.AIDetect.malware2
CynetMalicious (score: 100)
FireEyeGeneric.mg.300465b1f66ca50c
McAfeeGenericRXGJ-XZ!533494D178CC
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.865537
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.1f66ca
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyTrojan.Win32.Copak.luro
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Razy.865537
AvastWin32:Trojan-gen
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazrLrDw0CE5Lvb3SyjI9GJ72)
Ad-AwareGen:Variant.Razy.865537
SophosML/PE-A + Troj/Agent-BGOS
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
EmsisoftGen:Variant.Razy.865537 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.330B9D7
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.865537
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MalwarebytesTrojan.Crypt
TencentTrojan.Win32.Copak.wa
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Copak.AGMG!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.luro?

Trojan.Win32.Copak.luro removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment