Trojan

Trojan:Win32/Copak.MBKO!MTB (file analysis)

Malware Removal

The Trojan:Win32/Copak.MBKO!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Copak.MBKO!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Copak.MBKO!MTB?


File Info:

name: 088DD326F10303298998.mlw
path: /opt/CAPEv2/storage/binaries/d68a69de030f3255098e31872f211113d0b59ee702774608e62ee297942e7234
crc32: 35496372
md5: 088dd326f1030329899801ec96259d2d
sha1: 1a471ce194be9a1136464a6e16e2cf29a5eb9b18
sha256: d68a69de030f3255098e31872f211113d0b59ee702774608e62ee297942e7234
sha512: eed08df1763a080b4cb79d44454426a8fb59d105acb382dfbff53bc19a08d7be70c7d5adc49ec8b202f3689e247805844cb2be88b249a3d224b6d7dd678588bc
ssdeep: 12288:7o5D4g2Uuk49PGc1d+CD7o/tK3GZNqrtmhyBdI:Ul4gg9PICPo/MGMBdI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108C4F1BEE96CCC30E9324AB56A4C8DD3EA67212954BD41C94C2CF30B2316F1995729DF
sha3_384: 47568abcdec5c083c92fc52abd5847d9acc4705836e22c6602a533f22f8fea93cb807b7ecdf874f805a9ae2300dbed59
ep_bytes: bf000000005381c24511d86681c2a9ff
timestamp: 1971-05-16 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Copak.MBKO!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Khalesi.4!c
MicroWorld-eScanTrojan.GenericKDZ.103922
FireEyeGeneric.mg.088dd326f1030329
SkyhighBehavesLike.Win32.Generic.hc
McAfeeGlupteba-FTTQ!088DD326F103
MalwarebytesTrojan.Crypt
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/Khalesi.06f0e69f
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D195F2
BitDefenderThetaGen:NN.ZexaE.36792.H0Y@auZuXuh
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTKQ
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Khalesi.pef
BitDefenderTrojan.GenericKDZ.103922
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Khalesi.ka
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ZPACK.Gen
VIPRETrojan.GenericKDZ.103922
TrendMicroTROJ_GEN.R002C0PKL23
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.103922 (B)
SentinelOneStatic AI – Malicious PE
VaristW32/Khalesi.J.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Copak.MBKO!MTB
ZoneAlarmHEUR:Trojan.Win32.Khalesi.pef
GDataTrojan.GenericKDZ.103922
GoogleDetected
AhnLab-V3Trojan/Win.FTTQ.C5537414
Acronissuspicious
ALYacTrojan.GenericKDZ.103922
MAXmalware (ai score=86)
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
PandaTrj/Chgt.AC
TrendMicro-HouseCallTROJ_GEN.R002C0PKL23
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CTNW!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Copak.MBKO!MTB?

Trojan:Win32/Copak.MBKO!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment