Trojan

Trojan.Win32.Copak.rhfx information

Malware Removal

The Trojan.Win32.Copak.rhfx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Copak.rhfx virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Trojan.Win32.Copak.rhfx?


File Info:

name: 496B4A48EC3A18D938FA.mlw
path: /opt/CAPEv2/storage/binaries/5f762e24e0b858610923628ca39398b4bbe859e241b215a01a01a44c5ad18b6b
crc32: 129C5F1B
md5: 496b4a48ec3a18d938fa74ff1248bdc2
sha1: e8a1ea2becebcf26217cac09d173feea30970ab8
sha256: 5f762e24e0b858610923628ca39398b4bbe859e241b215a01a01a44c5ad18b6b
sha512: bf3de11a48aa9015656b7d168ac69d3113720170757768a3fa26c016d08f284d17602a42fb1d476a43002d9258622d8320b03acea0b64d91a3fb76439e9a1c3e
ssdeep: 3072:WThLlqdpspm6EaLbBbd4M5baUM/pRY6lY+lBbd4M5vu8GISBWacdBg9NBbd4M5bh:W1L8WeCQXEQgQSAroDQXEQQ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BD840204A3425FE8D9B436F312A3AFC97609E0F4B28D9703D5208EE89B15595B8DDF1B
sha3_384: e78674aa74767b31179dc61d89c143f9884c5778b08c99ff1f6239dd598b6a7b0bfb419739924fa5de481415e489271d
ep_bytes: bb0000000083ec0489042481c6fd1a0b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan.Win32.Copak.rhfx also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.46124967
ClamAVWin.Packed.Copak-9853643-0
FireEyeGeneric.mg.496b4a48ec3a18d9
McAfeeGenericRXAA-FA!496B4A48EC3A
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
K7GWTrojan ( 0058c5ff1 )
Cybereasonmalicious.becebc
VirITWin32.NSPacker.A
CyrenW32/Kryptik.DCC.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Copak.rhfx
BitDefenderTrojan.GenericKD.46124967
NANO-AntivirusTrojan.Win32.Agent.ixszcw
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.hb
Ad-AwareTrojan.GenericKD.46124967
SophosML/PE-A + Troj/Agent-BGZJ
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
VIPRETrojan.GenericKD.46124967
TrendMicroPAK_Xed-10
McAfee-GW-EditionBehavesLike.Win32.Glupteba.fc
EmsisoftTrojan.GenericKD.46124967 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.civ
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASBOL.C686
MicrosoftTrojan:Win32/Injector.RAQ!MTB
GDataTrojan.GenericKD.46124967 (2x)
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34646.xmZ@aqxLbnk
ALYacTrojan.GenericKD.46124967
VBA32BScope.Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallPAK_Xed-10
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Kryptik
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HITO!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Copak.rhfx?

Trojan.Win32.Copak.rhfx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment