Skip to main content

Trojan.Downloader.JPUY

Classification

Category:

Malware

Type:

Trojan-downloader

Aliases:

  • Trojan.Downloader.JPUY

Summary

Trojan.Downloader.JPUY is distributed in a file named 'hpupdate.exe'. Once installed on a machine, the trojan-downloader attempts to contact a remote server to download a file. It is also able to upload arbitrary files from the machine to the remote server.

Removal

Technical Details

Trojan.Downloader.JPUY is distributed as an executable program with the filename, 'hpupdate.exe' (SHA1:9a0386dc813407ae7073ed148161c65caf499874).

This filename is the same as a legitimate software update program for Hewlett-Packard printers, and is likely used to trick users into believing that the trojan-downloader is authentic.

Installation

If the malicious program is installed onto a machine, it creates a batch file and installs itself at the following location:

  • C:autoexec.bat

This ensures that the trojan-downloader is automatically launched at each system startup.

The trojan-downloader also checks for and, if necessary, creates a mutex object (straightforwardly named 'Mutex') to prevent re-infection of a machine that has already been infected by the same malware.

File download and upload

Once the trojan-downloader is installed and running on the machine, it attempts to contact a remote command and control server, report its status and download a file:

  • w w w.musicfile[obfuscated]/doc/<17-digit-random-number>.html

If the file is successfully downloaded, the trojan-downloader then executes it on the machine.

The trojan-downloader is also able upload arbitrary files on the infected machine to its command and control server.

Additional

In the sample analyzed, the malware also harvested browsing history details from the web browser on the infected machine.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.