Backdoor

Backdoor.Win32.Hupigon.tipv (file analysis)

Malware Removal

The Backdoor.Win32.Hupigon.tipv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Hupigon.tipv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup

How to determine Backdoor.Win32.Hupigon.tipv?


File Info:

name: 892CFE77487F8819A1A6.mlw
path: /opt/CAPEv2/storage/binaries/cdaa4c9b1454c3f56119cfc9e7cba22d6285eb635a236d6e0a0b79e887eee064
crc32: 73B5F0D3
md5: 892cfe77487f8819a1a699338f9e411a
sha1: 68227f7eb63d5c2cde31f6572e3cf639266620a6
sha256: cdaa4c9b1454c3f56119cfc9e7cba22d6285eb635a236d6e0a0b79e887eee064
sha512: e725e1699a5305da6c0975ee487d234abae1045b4e2f215ffcfb82247f1a4d49ee18680816f2503809a3eba626f3232bfc0803a0b9c1fd5797c61bef80983e1d
ssdeep: 1536:Yz44CpRkr9DXhH/2m//56RrufqjhzrmKIFAV0E:YzvokZRfN/yFj1qrFAH
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FA932971E215E487C917D8F2991ECD2168627D7D8AA0851E32E97F6D68B3BE30049F0F
sha3_384: 220aca7eded03243579e5f423b65b6e21b07d518896e3bd703f031b22b62a545d32d2eebc84c7faee9d8d50b2845a3b3
ep_bytes: 5589e55683ec4066c745f2d023c745e8
timestamp: 2014-12-30 22:12:58

Version Info:

CompanyName: Sun Microsystems, Inc.
FileDescription: Java(TM) Platform SE binary
FileVersion: 6.0.310.5
Full Version: 1.6.0_31-b05
InternalName: java
LegalCopyright: Copyright © 2012
OriginalFilename: java.exe
ProductName: Java(TM) Platform SE 6 U31
ProductVersion: 6.0.310.5
Translation: 0x0000 0x04b0

Backdoor.Win32.Hupigon.tipv also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.336590
FireEyeGeneric.mg.892cfe77487f8819
McAfeeGenericRXHB-CT!892CFE77487F
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderGen:Variant.Zusy.336590
K7GWTrojan ( 004b9f111 )
Cybereasonmalicious.7487f8
VirITTrojan.Win32.Tinba.RL
CyrenW32/S-bd04db17!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Tinba.BF
APEXMalicious
AvastWin32:BackdoorX-gen [Trj]
ClamAVWin.Malware.TinyBanker-9877962-1
KasperskyBackdoor.Win32.Hupigon.tipv
NANO-AntivirusTrojan.Win32.Hupigon.dogvlz
RisingTrojan.Kryptik!1.AF53 (RDMK:cmRtazorqyr7LMBaR8Y7nCMpvMp1)
Ad-AwareGen:Variant.Zusy.336590
EmsisoftGen:Variant.Zusy.336590 (B)
ComodoTrojWare.Win32.TrojanDownloader.Dofoil.GN@79ajoh
DrWebTrojan.PWS.Tinba.453
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nm
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.17SHAL
MaxSecureTrojan.Malware.121218.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.E7079F
ArcabitTrojan.Zusy.D522CE
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicrosoftTrojan:Win32/Tinba.V!MTB
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.Hupigon.C4855088
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34182.fq1@a0yzYyh
ALYacGen:Variant.Zusy.336590
MAXmalware (ai score=85)
VBA32Backdoor.Hupigon
MalwarebytesMalware.AI.3181727957
PandaTrj/Ransom.BH
TencentMalware.Win32.Gencirc.10b4633c
TACHYONBackdoor/W32.Hupigon.94720.Z
eGambitUnsafe.AI_Score_90%
FortinetW32/Tinba.BF!tr
AVGWin32:BackdoorX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Win32.Hupigon.tipv?

Backdoor.Win32.Hupigon.tipv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment