Files
MBCProject-mbc-markdown/xample-malware/hupigon.md
T
2019-08-07 09:26:33 -04:00

754 B

ID X0008
Aliases Delf, Emerleox, Logsnif, Graybird, Pcclient
Platforms Windows
Year 2013

Hupigon

A family of backdoors.

Behaviors

Name Use
Registry Run Keys / Startup Folder Hupigon drops the file "Systen.dll" and adds the registry entry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS DllName = "%System%\Systen.dll". [1]

References

[1] https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/HUPIGON