Trojan

Trojan.Win32.Copak.nnwo (file analysis)

Malware Removal

The Trojan.Win32.Copak.nnwo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.nnwo virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.nnwo?


File Info:

name: F084D40AF6800457DD83.mlw
path: /opt/CAPEv2/storage/binaries/1d12ceb29116424ac5d94a3e011726270361546471e52ad2e0a6c29dbf8fe76a
crc32: 1A825649
md5: f084d40af6800457dd8383348ed50cec
sha1: 9034aa36bba526659578da01dd827dc40ebdd863
sha256: 1d12ceb29116424ac5d94a3e011726270361546471e52ad2e0a6c29dbf8fe76a
sha512: 39b91d24fd67e60a2ca867018ad708c23badc6d6b5261af2fb0c7a8cf96298ad6c5cb028da1d201325e027454c5d4a66062dc59a2c78d5b77f383d8323fdab8f
ssdeep: 1536:3EKHhSxicLMrnT3BwcDhJGh+By0QmyqcAskbiYTXG7yMTbyEEAjCJDfv2:UYdwMrT3B7hQ5Z4dxTXyPVLjSn2
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11693AE35A0691DFFE197DA329549C4EF2BFE15F232A20E3A867278502757D4D1E328E0
sha3_384: dbc70dc899cd3d4a63746843b621bc7e3b1c5750e455c1989bbcbe816e33f1d35afebc9934fa9a970f2c5da9b69f115c
ep_bytes: 6845930bc25a29c629c068d885400001
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.nnwo also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.865537
FireEyeGeneric.mg.f084d40af6800457
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Razy.865537
K7GWTrojan ( 00577ea11 )
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderThetaGen:NN.ZexaF.34160.fuY@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0DAD22
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.nnwo
AlibabaTrojan:Win32/Copak.e046d298
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ViRobotTrojan.Win32.Z.Razy.94900.CT
RisingTrojan.Kryptik!1.D284 (CLOUD)
Ad-AwareGen:Variant.Razy.865537
EmsisoftGen:Variant.Razy.865537 (B)
DrWebTrojan.Siggen14.7487
TrendMicroTROJ_GEN.R002C0DAD22
SophosML/PE-A + Troj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.boki
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
ArcabitTrojan.Razy.DD3501
APEXMalicious
MicrosoftTrojan:Win32/Glupteba.DB!MTB
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeArtemis!F084D40AF680
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TencentTrojan.Win32.Copak.wa
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_98%
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Trojan.Win32.Copak.nnwo?

Trojan.Win32.Copak.nnwo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment