Backdoor

What is “Backdoor:Win32/Hupigon!pz”?

Malware Removal

The Backdoor:Win32/Hupigon!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Hupigon!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the embedded win api malware family
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Hupigon!pz?


File Info:

name: 360613C784345B9A8B2B.mlw
path: /opt/CAPEv2/storage/binaries/11b23a3c04fc65720951d797ac53b67ec33a0820dff523e523c2d14da77a75fd
crc32: B76BD008
md5: 360613c784345b9a8b2b46a35354780b
sha1: 1d7e9462d54b15662c5147f20957cfc1a65bab9b
sha256: 11b23a3c04fc65720951d797ac53b67ec33a0820dff523e523c2d14da77a75fd
sha512: f190a80aab263d63a5123048ba63934b16a3194aa2d4221b2cb9b4c3b3d2ef2dee1a8a1d50c87ff92e00a81522a11973e1ef800a24685e1bf54e8d2c56527d16
ssdeep: 12288:x37RJE0tZviU+V6UTy9b4KuiVDznzlfP1PcI7GF3Z4mxxFoEtlK+kt9T2Mq:VR6wZvZwLTy97RVDX9PhcCGQmXWGr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118052319456B586BE4073FBF5831E1B28FE6E73909B1557CB3B78D272C3A9812C0439A
sha3_384: 46727231b5affc233074582c8b51f87d485d18e29e76720712cde7b16933055be55c8a3450ca25469cb6fb7c6edb74e7
ep_bytes: 6801301c01e801000000c3c3b0eca719
timestamp: 2008-04-13 18:32:45

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 6.00.2900.5512 (xpsp.080413-2105)
InternalName: Wextract
LegalCopyright: (C) Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 6.00.2900.5512
Translation: 0x0804 0x04b0

Backdoor:Win32/Hupigon!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Hupigon.lriU
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Hupigon.AYPE
FireEyeGeneric.mg.360613c784345b9a
SkyhighBehavesLike.Win32.Generic.bc
McAfeeArtemis!360613C78434
Cylanceunsafe
VIPREBackdoor.Hupigon.AYPE
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Hupigon.e62f05cb
K7GWTrojan ( 005376ae1 )
K7AntiVirusTrojan ( 005376ae1 )
BitDefenderThetaAI:Packer.C3FD6BB91D
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Packed.ASProtect.AAB
APEXMalicious
TrendMicro-HouseCallMal_Pai-6
KasperskyBackdoor.Win32.Hupigon.pv
BitDefenderBackdoor.Hupigon.AYPE
NANO-AntivirusTrojan.Win32.Hupigon.bhkvrh
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Hupigon.pije
TACHYONTrojan/W32.Agent.799232
EmsisoftBackdoor.Hupigon.AYPE (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.Pigeon1.5760
ZillyaBackdoor.Hupigon.Win32.26942
TrendMicroMal_Pai-6
Trapminemalicious.high.ml.score
SophosMal/Behav-270
IkarusBackdoor.Win32.Hupigon
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Hupigon.G.gen!Eldorado
Antiy-AVLTrojan[Packed]/Win32.Asprotect
KingsoftWin32.Infected.AutoInfector.a
MicrosoftBackdoor:Win32/Hupigon!pz
XcitiumPacked.Win32.Aspack.AB@1s8lrk
ArcabitBackdoor.Hupigon.AYPE
ZoneAlarmPacked.Win32.Black.d
GDataBackdoor.Hupigon.AYPE
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Hupigon3.Gen
VBA32Trojan-Dropper.Kaos
ALYacBackdoor.Hupigon.AYPE
MAXmalware (ai score=95)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
RisingBackdoor.Hupigon!1.6484 (CLOUD)
YandexBackdoor.Hupigon!BJ/PV4BWsQQ
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.22162.susgen
FortinetW32/Hupigon.GE!tr.bdr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.784345
DeepInstinctMALICIOUS
alibabacloudVirtool:Win/Black.d

How to remove Backdoor:Win32/Hupigon!pz?

Backdoor:Win32/Hupigon!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment