Backdoor

Backdoor.Win32.Hupigon.axbr malicious file

Malware Removal

The Backdoor.Win32.Hupigon.axbr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Hupigon.axbr virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Starts servers listening on 0.0.0.0:802
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Backdoor.Win32.Hupigon.axbr?


File Info:

name: 45F7842FF56E9587113E.mlw
path: /opt/CAPEv2/storage/binaries/037c54b0df48419d273182a2d58042b879c0d08ea97d1e88cb88d120fa82dba2
crc32: 2E0DA78E
md5: 45f7842ff56e9587113ef42eed01c9ff
sha1: c577f052886cad3443f5e73902a7138f16cc907b
sha256: 037c54b0df48419d273182a2d58042b879c0d08ea97d1e88cb88d120fa82dba2
sha512: 59d0f306b6e259a767563ad74bf082bbc963e19d21e51fab3ecfe2303d68095b49e4ab5721b13e14ce35f6456dee481377f1a9f4cd69c8233ae98b8e1ec0bfa8
ssdeep: 6144:LywrTyvNGBJLms+hFyKvcRplVAK8Lf23vgjSiU6KpeTRURKZ:LXogLH+hFygcrlViYvg2iYeN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A164236FA48C1BB6CE6827B5CD0ADED7D596C0D284B22ED887C1341B7E92B113C71746
sha3_384: c45b59233df768a338f8985f0e8727f7da4b28eef40200aef15a47e8cac0855e502b396d7422a106ba73bf3808f34afe
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor.Win32.Hupigon.axbr also known as:

DrWebWin32.Induc
MicroWorld-eScanWin32.Induc.A
FireEyeWin32.Induc.A
CAT-QuickHealW32.Induc.A
CylanceUnsafe
K7AntiVirusVirus ( f10009011 )
K7GWVirus ( f10009011 )
Cybereasonmalicious.ff56e9
BitDefenderThetaAI:FileInfector.CFA710080D
CyrenW32/Induc.B.gen!Eldorado
SymantecW32.Induc.A
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Induc.A
APEXMalicious
KasperskyBackdoor.Win32.Hupigon.axbr
BitDefenderWin32.Induc.A
NANO-AntivirusVirus.Win32.Induc.dffkeg
AvastWin32:Induc
Ad-AwareWin32.Induc.A
TACHYONVirus/W32.Induc
SophosW32/Induc-A
ComodoVirus.Win32.Induc.A0@1q1u4b
VIPREWin32.Induc.A
TrendMicroPE_INDUC.A
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
EmsisoftWin32.Induc.A (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/Induc.a
AviraW32/Induc.blr
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitWin32.Induc.A
GDataWin32.Virus.Induct.A
CynetMalicious (score: 100)
McAfeeW32/Induc
MAXmalware (ai score=82)
VBA32Virus.Win32.Induc.c
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallPE_INDUC.A
RisingVirus.Induc!8.7E5 (TFE:dGZlOgVFP/KBX9iZkQ)
YandexWin32.Induc
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Induc.A
AVGWin32:Induc
PandaGeneric Malware

How to remove Backdoor.Win32.Hupigon.axbr?

Backdoor.Win32.Hupigon.axbr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment