Threat Level: The level of threat a particular PC threat could have on an infected computer. Many Hupigon variants therefore create mutexes in the following format: xxx.com.cn_MUTEX The "xxx" being a variable, for example: Hacker.com.cn_MUTEX Registry Modifications Creates these keys: HKLM\System\CurrentControlSet\Services\system32 ImagePath = C:\WINDOWS\Hacker.com.cn.exe HKLM\System\CurrentControlSet\Services\system32 HKLM\System\CurrentControlSet\Services\system32\Security

This is the stealth component of Win32/Hupigon. Backdoor:Win32/Hupigon!hook. It too is injected into other processes by TrojanDropper:Win32/Hupigon using CreateRemoteThread. These files, folders and registry elements are respectively listed in the Files, Folders, Registry Keys and Registry Values sections on this page.For instructions on deleting the Hupigon registry keys and registry

This DLL is a plugin that logs keystrokes and steals passwords. Backdoor:Win32/Hupigon.CN's copies have the read-only and hidden attributes set.

Upon installation, backdoor trojans can be instructed to send, receive, execute and delete files, gather and transfer confidential data from the computer, log all activity on the computer, and perform other Backdoor:Win32/Hupigon!hook is injected into other processes by TrojanDropper:Win32/Hupigon using CreateRemoteThread. TrojanDropper:Win32/Hupigon may also install PWS:Win32/Hupigon. These are usually dropped by other malware onto a system or are downloaded unknowingly by users when visiting malicious sites. The common link here seems to be the "Search Assistant" as that is the Microsoft folder in which the backdoor.hupigon.GEN file was found.

Other aliases[edit] Trojan.Win32.Boht (Kaspersky Labs and Fortinet) Backdoor:Win32/Bezigate (Microsoft) Backdoor.Win32.Graftor (Bitdefender) [2] External links[edit] Analysis of a file - VirusTotal Analysis of a file - Threat Expert References[edit] ^ Backdoor.Win32.Hupigon @

Backdoor:Win32/Hupigon.CN also modifies the Windows Registry. Each of the fields listed on the ESG Threat Scorecard, containing a specific value, are as follows: Ranking: The current ranking of a particular threat among all the other threats found

The following text strings can typically be found in a Hupigon variant: 6600.org BEI_ZHU GrayPigeon Hacker.com.cn.exe huaihuaitudou Rejoice2007 woainisisi Installation When the backdoor's file is started, it copies itself as a