Malware

Win32:Hupigon-FB [Trj] (file analysis)

Malware Removal

The Win32:Hupigon-FB [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Hupigon-FB [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Win32:Hupigon-FB [Trj]?


File Info:

name: DA59B8015DA51C64F195.mlw
path: /opt/CAPEv2/storage/binaries/aedd8fded64a8c95cdb2b7c0b4b7e4dcc5aca47ec2e25dd5b83452cb4a7c11e1
crc32: 7E3CB4D2
md5: da59b8015da51c64f195d4bd3ab929b1
sha1: 2c2947447bc9e62c2e41176ed3f08045e102c01a
sha256: aedd8fded64a8c95cdb2b7c0b4b7e4dcc5aca47ec2e25dd5b83452cb4a7c11e1
sha512: 5c38d48eb39dd8aa49f23cd16198486eed77c7d280a55387fb64c4745e080244a8d7aca8eab92cc5e26b93fe782326f2c28a31e08b74f794d6871244178d5627
ssdeep: 12288:WO38wMIr/1Fsfvy3K7p8Iu5kPPRS69oIG76YnNFTsP8:hMwd/1FOyO8rycj5/nNFT9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135E46D21F6909477D1732B789C2B91A99825BE203E2879473BED1E0D4FFD38179392D2
sha3_384: b830405c23b251549e88cdf89002493926e2cd2c752909c332d5422d0c0542daf6dad0b87268afa1f1c34b9a3a501e51
ep_bytes: 558bec83c4f0b8b88a4900e824def6ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32:Hupigon-FB [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Hupigon.liai
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ExplorerHijack.QGW@aOXBWydb
FireEyeGeneric.mg.da59b8015da51c64
SkyhighBehavesLike.Win32.Dropper.jh
McAfeeBackDoor-AWQ.ak
MalwarebytesGeneric.Malware.AI.DDS
ZillyaBackdoor.Hupigon.Win32.60262
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Hupigon.b03d0a2e
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderThetaGen:NN.ZelphiF.36802.QGW@aOXBWydb
VirITBackdoor.Win32.Hupigon.XXZ
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Hupigon
APEXMalicious
TrendMicro-HouseCallMal_HPGN-11
ClamAVWin.Trojan.Delf-1518
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.ExplorerHijack.QGW@aOXBWydb
NANO-AntivirusTrojan.Win32.Hupigon.jdsc
SUPERAntiSpywareTrojan.Agent/Gen-Kryptor
AvastWin32:Hupigon-FB [Trj]
TencentWin32.Trojan.Generic.Vimw
TACHYONBackdoor/W32.DP-Hupigon.689664.E
EmsisoftGen:Trojan.ExplorerHijack.QGW@aOXBWydb (B)
BaiduWin32.Trojan.Hupigon.c
F-SecureBackdoor.BDS/Hupigon.Gen
DrWebBackDoor.Huai.5336
VIPREGen:Trojan.ExplorerHijack.QGW@aOXBWydb
TrendMicroMal_HPGN-11
Trapminemalicious.moderate.ml.score
SophosMal/Pigeo-G
IkarusBackdoor.Win32.Hupigon
JiangminBackdoor/Huigezi.Gen
ALYacGen:Trojan.ExplorerHijack.QGW@aOXBWydb
WebrootW32.Trojan.Backdoor-GrayPigeon
VaristW32/Downloader.C.gen!Eldorado
AviraBDS/Hupigon.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Hupigon
KingsoftWin32.HeurC.KVM007.a
MicrosoftBackdoor:Win32/Hupigon.CK
XcitiumBackdoor.Win32.Hupigon.~A@4q7s6
ArcabitTrojan.ExplorerHijack.EA7BB9
ViRobotBackdoor.Win32.Hupigon.689664.T
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.14IIXYG
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Hupigon.R7676
VBA32Malware-Cryptor.Inject.gen
GoogleDetected
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
RisingBackdoor.Win32.ShangXing.jh (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1195585.susgen
FortinetW32/Hupigon.L!tr
AVGWin32:Hupigon-FB [Trj]
Cybereasonmalicious.15da51
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Hupigon

How to remove Win32:Hupigon-FB [Trj]?

Win32:Hupigon-FB [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment