Trojan

Trojan.Win32.Copak.lwbt (file analysis)

Malware Removal

The Trojan.Win32.Copak.lwbt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.lwbt virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.lwbt?


File Info:

name: F95C3EA2780B64354DCC.mlw
path: /opt/CAPEv2/storage/binaries/160c7269d46f72815a91fc8e97542b121b227ef401faa46c05dd78cdbce56f42
crc32: 227B6F7E
md5: f95c3ea2780b64354dccbf09dd521233
sha1: f1a200d2279067f50e395d6311a31a80819cb887
sha256: 160c7269d46f72815a91fc8e97542b121b227ef401faa46c05dd78cdbce56f42
sha512: 29917967da62baeff04427cd1a9603789e39759ee763da45da5ac3fa8376194794255cf87fae9ff750131332e62fdc8d9a5d42a57535fe757e4b0d88c8f9cf07
ssdeep: 3072:l3RAImwvoyFcvkDTE3FJjN268lullGUTkEDQwHgSLhlw5xrOi1Q:l3+ImCj6sDT0WnA0wvT2ii1Q
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T178F3C0943FD0DE63FB47C9B00576CEF915064CE6E6CF580A835A302ED575A8A6B8D470
sha3_384: 4dc5bedcb0d891ebee2040196367f7a1ea17b8a8189f3f01c5b9431fe62a82f2761bb3e70d350b6c5c89222264aed2e2
ep_bytes: 68f052d0a48b142483c40409f089f183
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.lwbt also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.f95c3ea2780b6435
McAfeeArtemis!F95C3EA2780B
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00577ea11 )
AlibabaTrojan:Win32/Copak.22c4857f
K7GWTrojan ( 00577ea11 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34114.kuZ@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
ClamAVWin.Packed.Iboz-9871857-0
KasperskyTrojan.Win32.Copak.lwbt
BitDefenderGen:Variant.Razy.865537
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce5d3c
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DA422
McAfee-GW-EditionBehavesLike.Win32.Glupteba.cc
SophosML/PE-A + Troj/Agent-BGOS
GDataGen:Variant.Razy.865537
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.3356661
MicrosoftTrojan:Win32/Glupteba.DB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R293305
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Razy.865537
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0DA422
RisingTrojan.Kryptik!1.D284 (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/Copak.AGMG!tr
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.2780b6

How to remove Trojan.Win32.Copak.lwbt?

Trojan.Win32.Copak.lwbt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment