Threat Database Backdoors Backdoor:Win32/Hupigon.CN

Backdoor:Win32/Hupigon.CN

By Sumo3000 in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 6
First Seen: March 22, 2013
Last Seen: January 28, 2022
OS(es) Affected: Windows

Backdoor:Win32/Hupigon.CN is a backdoor Trojans that enables a remote cybercriminal to obtain full access and control over the corrupted PC. While being installed, Backdoor:Win32/Hupigon.CN makes system modifications by adding malevolent files on the infected computer. Backdoor:Win32/Hupigon.CN also modifies the Windows Registry. Backdoor:Win32/Hupigon.CN inserts and executes its copyon the targeted PC. Backdoor:Win32/Hupigon.CN's copies have the read-only and hidden attributes set. Backdoor:Win32/Hupigon.CN modifies the registry entries to make sure that it launches when you start Windows. Backdoor:Win32/Hupigon.CN executes a variety of harmful activities, such as, logging keystrokes or stealing confidential information, controlling and taking screenshots, controlling a web camera of the desktop, turning on a microphone to listen to and record the victim, recording the affected PC owner's private details such as usernames, passwords and the websites visited, once the attacked PC is corrupted and connected to the web or a network.

File System Details

Backdoor:Win32/Hupigon.CN may create the following file(s):
# File Name Detections
1. [system folder] \windows.exe
2. [system folder] \ windowsapplication1.exe
3. %APPDATA% \svchost.exe\multistarter.exe
4. %APPDATA% \svchost.exe
5. [system folder] \taskmrg.exe (not taskmgr.exe)

Registry Details

Backdoor:Win32/Hupigon.CN may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run "Policies" = "%SYSTEM%\server.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\[RANDOM CHARACTERS] "StubPath" = "%SYSTEM%\windows.exe restart" or "%SYSTEM%\server.exe restart"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Policies" = "%SYSTEM%\windows.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\2DW0SJYE-LCXY-1KR2-V0J8-4JW360NX073R" "StubPath" = [system folder]\windows.exe restart

Trending

Most Viewed

Loading...