Backdoor

Backdoor.Hupigon.S1506844 (file analysis)

Malware Removal

The Backdoor.Hupigon.S1506844 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Hupigon.S1506844 virus can do?

  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Hupigon.S1506844?


File Info:

crc32: 46F79532
md5: 2e297c6a5e986e7020b98180b52d1a84
name: 2E297C6A5E986E7020B98180B52D1A84.mlw
sha1: d425946e5676253ce381d9d5d789edd0a6602235
sha256: 13771b92fbd6b0c3c84e483e7a0de93977f6a3921e5dbbdce5ae70d4600836c5
sha512: c51503a9a33735c01b710d10554e792b2bbdb394766ce23e92d78fe2327eb2fe307b0e2d48cb063377784f8dcda9e53b58ba78fcfb3c43d30dca07a51ebb965e
ssdeep: 96:1dk491Sp4hJAyV7nS62sQC4o4fOYyTSzm9izZp43Z9NEUD:PR964bAyV7SM4o4feeEEZpaHLD
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Hupigon.S1506844 also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop.8805
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.Hupigon.S1506844
ALYacTrojan.GenericKD.34711750
CylanceUnsafe
ZillyaTrojan.Genome.Win32.1
SangforTrojan.Win32.Wacatac.C
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaBackdoor:Win32/Hupigon.42653854
Cybereasonmalicious.a5e986
CyrenW32/Hupigon.MHRD-3116
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-53343
BitDefenderTrojan.GenericKD.34711750
NANO-AntivirusTrojan.Win32.Drop.eaikex
ViRobotBackdoor.Win32.Hupigon.9728.B
MicroWorld-eScanTrojan.GenericKD.34711750
TencentMalware.Win32.Gencirc.10b7d4cb
Ad-AwareTrojan.GenericKD.34711750
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Kryptik.ATA@4na219
BitDefenderThetaGen:NN.ZexaF.34266.amW@aavd@gbc
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.2e297c6a5e986e70
EmsisoftTrojan.GenericKD.34711750 (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor/Agent.dqw
MicrosoftTrojan:Win32/Ymacco.AA13
ArcabitTrojan.Generic.D211A8C6
GDataWin32.Trojan.Small.A
TACHYONBackdoor/W32.Small.8704.J
AhnLab-V3Trojan/Win32.Hupigon.R30344
Acronissuspicious
McAfeeArtemis!2E297C6A5E98
MAXmalware (ai score=82)
PandaMalicious Packer
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqaAQfIj0VnMdT4bjFSxYGW)
YandexTrojan.GenAsa!FAA7mshoX/8
Ikarusnot-a-virus:RemoteAdmin.Win32.RAdmin
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Hupigon.AVO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor.Hupigon.S1506844?

Backdoor.Hupigon.S1506844 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment