Backdoor.Win32.Hupigon.haqj / Insecure Service Path
Discovery / credits: Malvuln - (c) 2022
Original source:
Contact: [email protected]

Threat: Backdoor.Win32.Hupigon.haqj
Vulnerability: Insecure Service Path
Description: The malware creates a service with an unquoted path. Third party attackers who can place an arbitrary executable under c:\ drive can potentially undermine the integrity of the malware by having it run theirs instead with SYSTEM privs.
Family: Hupigon
Type: PE32
MD5: d9542df20f8df457747451dd9e16d1c0
Vuln ID: MVID-2022-0557
Disclosure: 04/18/2022

C:\dump>sc qc "Outlook Express"
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: Outlook Express
        TYPE               : 110  WIN32_OWN_PROCESS (interactive)
        START_TYPE         : 2   AUTO_START
        ERROR_CONTROL      : 0   IGNORE
        BINARY_PATH_NAME   : C:\Program Files (x86)\Express.exe
        LOAD_ORDER_GROUP   :
        TAG                : 0
        DISPLAY_NAME       : Outlook Express
        DEPENDENCIES       :
        SERVICE_START_NAME : LocalSystem

