Trojan

Trojan.Win32.Copak.qbjr (file analysis)

Malware Removal

The Trojan.Win32.Copak.qbjr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.qbjr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Trojan.Win32.Copak.qbjr?


File Info:

name: DA4487BEDEF8E05FE41B.mlw
path: /opt/CAPEv2/storage/binaries/0b07e257e4581a0767fd2f86d2cc04f8c7eb2e55e4bfc31b6370076689627acd
crc32: 6BD76BE0
md5: da4487bedef8e05fe41b66022c2e039c
sha1: 255b3d4c0e9d769d0094e04f06f7a6832438fb1c
sha256: 0b07e257e4581a0767fd2f86d2cc04f8c7eb2e55e4bfc31b6370076689627acd
sha512: 4ce03d2919c23be122a955abe13b89c88bc9cb07a180ac9316744097682538f18debc73efa56c26c5cb924de98edd0df62aad1b3aa15cb051be3bc271e1e53b4
ssdeep: 1536:3ERBYIA1B3SrxHie+wE6Y6dzebBhDWZV/QJvthEGwO3xznOgn3XgYhXNolI:3ERBYgrxHX9z/6BZcCFhEGtJOgn3Xni2
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1CAA3BE757488FC85F05292B01D69DEAF37FF1E2F0466E3294B27129A34578B8B942DC1
sha3_384: 6d953d8b306ae0017c1a9b2eed6c95b0ae06b644a5e6012e7dfe643d832c9c06721fc7d3597fa23440fb1900886d7543
ep_bytes: ba18e13d7d68d8854000680010400089
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.qbjr also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Razy.900994
FireEyeGeneric.mg.da4487bedef8e05f
CAT-QuickHealTrojan.Glupteba
McAfeeGlupteba-FTSD!DA4487BEDEF8
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1438650
K7AntiVirusTrojan ( 00577ea11 )
BitDefenderGen:Variant.Razy.900994
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.edef8e
BitDefenderThetaGen:NN.ZexaF.34212.guY@aeSC5Sd
CyrenW32/Zbot.W.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.qbjr
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Injector!1.CD26 (RDMK:cmRtazrjXgvsmpy37qS09d6L+65b)
Ad-AwareGen:Variant.Razy.900994
EmsisoftGen:Variant.Razy.900994 (B)
DrWebTrojan.Siggen14.7487
McAfee-GW-EditionBehavesLike.Win32.RAHack.nc
SophosML/PE-A + Troj/Agent-BGOS
APEXMalicious
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.335000B
MicrosoftTrojan:Win32/Glupteba.DB!MTB
GDataGen:Variant.Razy.900994
AhnLab-V3Malware/Win32.RL_Generic.R293305
ALYacGen:Variant.Razy.900994
MAXmalware (ai score=88)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TencentTrojan.Win32.Copak.wd
YandexTrojan.Copak!p8KJvtrIVkI
SentinelOneStatic AI – Malicious PE
FortinetW32/Copak.AGMG!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Copak.qbjr?

Trojan.Win32.Copak.qbjr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment