Backdoor

Backdoor.Win32.Hupigon removal guide

Malware Removal

The Backdoor.Win32.Hupigon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Hupigon virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor.Win32.Hupigon?


File Info:

name: 4E59182DF73A0C87A21B.mlw
path: /opt/CAPEv2/storage/binaries/7750a7328b7afd515005791e734518767a5fe52d6dbe6e98d86f21bdcc056ddc
crc32: DFB368EC
md5: 4e59182df73a0c87a21bc44492b15788
sha1: 9b65456c7aa36275fd63a61b4e8936fc05934e98
sha256: 7750a7328b7afd515005791e734518767a5fe52d6dbe6e98d86f21bdcc056ddc
sha512: 1b1185e76e9b1d2717ad82339f37528316e0844ad83588cf17809897c31312f9d96b2381c0b625f88196db8253754db3d605ec8a18b89c9c8a144fed2282f668
ssdeep: 12288:3tebadY9MEOQbe25Lbge4o8eGsw4v5TF8xXrLTEQGUC7nVA5wl:9ebb9b7hjfw4xTSxXoHUC7nVAml
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T139E423FEA7014C49E0859930A899D36CBBDCE1E70DBCE715673E6C8CEA680DCE791524
sha3_384: 0f79decd3ca3e4af4700dcbb08e0e11f491c9bfa994e45c797f220859fca22973414f675af274ee9e3509cf78fa4c48f
ep_bytes: 6803234c006811234c00c369e9090000
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor.Win32.Hupigon also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Hupigon.lonp
tehtrisGeneric.Malware
DrWebBackDoor.Pigeon.57541
MicroWorld-eScanGen:Trojan.ExplorerHijack.PyW@am@bVojj
SkyhighBehavesLike.Win32.Backdoor.jc
McAfeeBackDoor-EXZ
MalwarebytesGeneric.Malware.AI.DDS
ZillyaBackdoor.Hupigon.Win32.109680
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052c8a31 )
AlibabaBackdoor:Win32/Hupigon.dd4e738c
K7GWTrojan ( 0052c8a31 )
Cybereasonmalicious.df73a0
BitDefenderThetaAI:Packer.9885C65E1D
VirITTrojan.Win32.Agent.BWB
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Hupigon
APEXMalicious
ClamAVWin.Ransomware.FileCoder-9853970-0
KasperskyHEUR:Backdoor.Win32.Hupigon.gen
BitDefenderGen:Trojan.ExplorerHijack.PyW@am@bVojj
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Generic.Pqil
EmsisoftGen:Trojan.ExplorerHijack.PyW@am@bVojj (B)
F-SecurePacked:W32/PeCan.A
VIPREGen:Trojan.ExplorerHijack.PyW@am@bVojj
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.4e59182df73a0c87
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
JiangminBackdoor/Hupigon.boeb
GoogleDetected
AviraBDS/Hupigon.Gen
VaristW32/FakeVideo.A.gen!Eldorado
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.HeurC.KVM007.a
MicrosoftBackdoor:Win32/Hupigon.CK
XcitiumMalware@#3if5g5fx88ggn
ArcabitTrojan.ExplorerHijack.EAF3BB
ZoneAlarmHEUR:Backdoor.Win32.Hupigon.gen
GDataGen:Trojan.ExplorerHijack.PyW@am@bVojj
CynetMalicious (score: 100)
VBA32Malware-Cryptor.Inject.gen
ALYacGen:Trojan.ExplorerHijack.PyW@am@bVojj
Cylanceunsafe
PandaTrj/CI.A
RisingMalware.Undefined!8.C (TFE:5:IrRm2I2Kc7Q)
YandexTrojan.GenAsa!AEDmP44rvSo
IkarusBackdoor.Win32.Zegost
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Piegon.NTAA!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)
alibabacloudTrojan:Win/Hupigon.Gen

How to remove Backdoor.Win32.Hupigon?

Backdoor.Win32.Hupigon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment