Backdoor

Backdoor.HangUp malicious file

Malware Removal

The Backdoor.HangUp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.HangUp virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Backdoor.HangUp?


File Info:

name: 969915AD6B477CF94E64.mlw
path: /opt/CAPEv2/storage/binaries/6273c5c55f4c9644e48e94ed95be48bc7df7b5036ba85ce403b0c271b231bc79
crc32: 1976CD93
md5: 969915ad6b477cf94e64475224a69662
sha1: b8b5a97388d272581b9df0e029fb5fd9ee30e6e5
sha256: 6273c5c55f4c9644e48e94ed95be48bc7df7b5036ba85ce403b0c271b231bc79
sha512: 0220e7f63b188d411732a02fcb97b1f21ef582e24ec0575877636a9be3baa2a8d478a4fe56781782e71cf07c76adcca1b60c5dc057f55f06857ebc05ccfc2951
ssdeep: 6144:wrYU/glCKYRHjXT83nL0qzdwOSzhrQD2s68RXT83nL0qzdwOSL:nU/bRw3P+hrYw3P0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T136448C872E704FBADEDAC4F70B651A0B53DA9171139ED09E01919D04B83EF8D1879B8E
sha3_384: 0724beb41984e49fe1ce0fdb1983f177b81d39702142cfc5cd0698a6ee23da6b1089b14eb70f3972dcbd8bca996afd96
ep_bytes: 90909060909067e80000000090909090
timestamp: 2036-08-19 07:39:47

Version Info:

0: [No Data]

Backdoor.HangUp also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGenPack:Generic.Dacic.1.Backdoor.Hangup.A.0305F788
ClamAVWin.Trojan.Crypted-29
CAT-QuickHealWorm.Dorkbot.A
ALYacGenPack:Generic.Dacic.1.Backdoor.Hangup.A.0305F788
CylanceUnsafe
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Spy.Quart.a
VirITWorm.Win32.Berbew.G
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.Qukart.fotkcn
ViRobotTrojan.Win32.Padodor.Gen.A
Ad-AwareGenPack:Generic.Dacic.1.Backdoor.Hangup.A.0305F788
ComodoWorm.Win32.Qukart.K@565w5t
DrWebBackDoor.HangUp.43784
ZillyaTrojan.QukartGen.Win32.1
TrendMicroTSPY_ZBOT.SMOZ
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.969915ad6b477cf9
SophosML/PE-A + Troj/Padodo-Gen
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan/Generic.ASBOL.16B
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeBackDoor-AXJ.gen
MAXmalware (ai score=81)
VBA32Backdoor.HangUp
MalwarebytesPadodor.Backdoor.Stealer.DDS
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallTSPY_ZBOT.SMOZ
TencentTrojan.Win32.Pornoasset.a
YandexTrojan.GenAsa!YJadCSKUggw
TACHYONBackdoor/W32.Padodor
MaxSecureProxy.Qukart.gen
FortinetW32/Qukart.A!tr
BitDefenderThetaAI:Packer.6598B5D11E
Cybereasonmalicious.d6b477

How to remove Backdoor.HangUp?

Backdoor.HangUp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment