Benign Download

Backdoor.Win32.Hupigon.bkp

Image list icon size importExecute shell command (ShellExecuteA)
SHA-256d3f2323e722535cc3e486c0d50b11ccc9350fc30bd36a46391f35f9f254c5bb4
MaleculeH₂(PoU)

Evidence

Query/set system parameters (symbol) 0xa85dc–0xa86cc
0xa85dc65000000546c7347657456616c756500e...TlsGetValue.
0xa85ec00004c6f63616c416c6c6f6300000000..LocalAlloc....
0xa85fc4765744d6f64756c6548616e646c6541GetModuleHandleA
0xa860c000061647661706933322e646c6c0000..advapi32.dll..
0xa861c00005265706f72744576656e74410000..ReportEventA..
⋯11 more rows
Execute shell command (ShellExecuteA) 0xa87d0–0xa89a0
⋯13 more rows
0xa88a074436f6d70757465724e616d65410000tComputerNameA..
0xa88b00000526573756d655468726561640000..ResumeThread..
0xa88c0000052657365744576656e7400000000..ResetEvent....
0xa88d052656d6f76654469726563746f727941RemoveDirectoryA
0xa88e0000000005265616446696c6500000000....ReadFile....
0xa88f05065656b4e616d656450697065000000PeekNamedPipe...
0xa89004f70656e50726f636573730000004d75OpenProcess...Mu
0xa89106c446976000000004d6f766546696c65lDiv....MoveFile
0xa8920410000004c6f636b5265736f75726365A...LockResource
0xa8930000000004c6f61645265736f75726365....LoadResource
⋯7 more rows
Query/set system parameters (string) 0xa942e–0xa94ce
0xa942e6765000000005472616e736c6174654dge....TranslateM
0xa943e4449537973416363656c000000005472DISysAccel....Tr
0xa944e61636b506f7075704d656e7500000000ackPopupMenu....
0xa945e53797374656d506172616d6574657273SystemParameters
0xa946e496e666f4100000053686f7757696e64InfoA...ShowWind
0xa947e6f770000000053686f775363726f6c6cow....ShowScroll
⋯5 more rows

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.