PUP.Softcnapp.AB
The detection of PUP.Softcnapp.AB on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent any potential harm.
Table of Contents
What Is PUP.Softcnapp.AB?
PUP.Softcnapp.AB is a type of malware that is classified as a potentially unwanted program. This means that it is not necessarily malicious in nature, but it can still cause problems with your system, such as slowing it down, displaying unwanted advertisements, or collecting your personal data without your consent. PUPs can be installed on your system through various means, including bundled software downloads, infected websites, or malicious email attachments.
How PUP.Softcnapp.AB Operates
Once installed, PUP.Softcnapp.AB can operate in the background, consuming system resources and potentially causing issues with your computer's performance. It may also collect your personal data, such as browsing history, search queries, or other sensitive information, and transmit it to its creators or third-party advertisers. In some cases, PUPs can also install additional malware or unwanted software on your system, leading to further problems.
Symptoms of Infection
If your system is infected with PUP.Softcnapp.AB, you may notice various symptoms, including slow system performance, unwanted pop-ups or advertisements, unfamiliar programs or icons on your desktop, or changes to your browser settings. You may also experience issues with your internet connection or notice that your system is crashing frequently. It's essential to be aware of these symptoms and take action immediately to remove the PUP and prevent any further damage.
How to Remove PUP.Softcnapp.AB
- Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow you to download and install removal tools.
- Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove PUP.Softcnapp.AB and any other malware that may be present.
- Uninstall any suspicious programs or software that you don't recognize or that were installed without your consent.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions or add-ons that may be associated with the PUP.
- Reboot your system and perform another scan with your anti-malware tool to ensure that the PUP has been completely removed.
Conclusion
Removing PUP.Softcnapp.AB from your system is crucial to prevent any potential harm and to restore your computer's performance and security. By following the steps outlined above, you can effectively remove the PUP and prevent any further issues. It's also essential to be cautious when downloading software or clicking on links from unknown sources to prevent similar infections in the future. Regularly updating your operating system, browser, and anti-malware software can also help to protect your system from various threats, including PUPs and other types of malware.
Analysis Report
General information
| Family Name: | PUP.Softcnapp.AB |
|---|---|
| Signature status: | Self Signed |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
6eff77e5159561abb760143d6ee0d3eb
SHA1:
192e9e2ea3359b36508b5db2ef45bf8e6ba59783
File Size:
5.00 MB, 5003288 bytes
|
|
MD5:
b9126e3beea5d5c68c633e0f9e195817
SHA1:
3900475b4923f560638734fe68f2a1e1dae09154
SHA256:
84B10DE148B5F5FE837303CF841956060663D5B5D905AAE73E6029FC8BA21C74
File Size:
4.53 MB, 4530792 bytes
|
|
MD5:
8adfc4f06b884ab8e068b674eaac80d1
SHA1:
2833846ef5de94eb2690427158b428996c318106
SHA256:
E060AC0B20BAAAE75EE43789DFA95DBA9026C7CF80C01557B73568A99DF763CB
File Size:
1.73 MB, 1727488 bytes
|
|
MD5:
c4206e4710806e2860c226303371d63f
SHA1:
547d80391263079f2e025a773fe0d313212e34da
SHA256:
267F35AE042E24D06D5E9D8EADBC757446C92BC0269E6556A7744481DF0D1C61
File Size:
5.30 MB, 5297544 bytes
|
|
MD5:
f9cdec83cebc8004aca438bc2d5c3897
SHA1:
0e5512d94c0e32e58fc20b2aa368dd0c53ac84c8
SHA256:
69230DD891D94A869FDAF5C4636C9633EF36EB3BF4CDBBCAFE9FA77083DB2CD5
File Size:
3.83 MB, 3830384 bytes
|
Show More
|
MD5:
551263405b762e493272a33741f54d7a
SHA1:
06cc0a3e874b32f8021efd5a519b0e063b8cc017
SHA256:
5E19825ADE981A8BF6B15109F4BEF3785C0BF3A54A4650EDB97B849D6CFE8AFB
File Size:
5.60 MB, 5595352 bytes
|
|
MD5:
7a08ae434a0a134eacaa50ec773bac86
SHA1:
3db3e8fe98e84ed3067522b714ea608b2d6db8b7
SHA256:
3A29B559FB5CAC724B15FD5DDC24D6B96A6DE7E366F3A6C655049F6EEDB26FAA
File Size:
5.10 MB, 5095448 bytes
|
|
MD5:
f00b512bf66a4c122b581ea2365fa1f7
SHA1:
ebb920d5b464a37aaee5a4aaab9aca901bfa6204
SHA256:
F28119F96FE673C80E72085A86E2724BC0D9054318B628A32646C4DDA46C0465
File Size:
4.52 MB, 4520960 bytes
|
|
MD5:
f9579f267dbab5f46a55784a5b16eb0d
SHA1:
6a11acefd6f1f58405586c60d724f58cf6928372
SHA256:
4B8F396D71D368D8993702B8CE0481F32AC74DF76C31545BE311F670A0C40E4D
File Size:
4.70 MB, 4702304 bytes
|
|
MD5:
f1bb88defc7f5b1e0cb52475b9df1436
SHA1:
31839a57a0032c2c534128b68b99eda9974e34e5
SHA256:
7E92BE1D877C878FF8BBF73AAEAED7EB50D7ED25D9D6F71119CAE04BD0CCD1C7
File Size:
3.51 MB, 3513128 bytes
|
|
MD5:
8aa5710a5a48b4d5a1e3592cfd627386
SHA1:
a8e3e89fa1d1d9dc938db51fda5fdc97e0cbde28
SHA256:
2C0CCB4B470ED337AF903590854724B7B55EC10CB5A955ED9FFC8D700C66F1A4
File Size:
4.72 MB, 4718688 bytes
|
|
MD5:
1efe1a1f39ad445fb815863e21202b35
SHA1:
c6396081ba43959cbdbeede6841c3542171f2a72
SHA256:
2195489CC6C6FA4581CA88AEEAE232070E3022954649920641A9B78C81747C58
File Size:
5.67 MB, 5665496 bytes
|
|
MD5:
c944045050e46bcf6bc3159d2fb944e5
SHA1:
649a0403f777fe8c7a72704266cdf9730ddf7070
SHA256:
1130D5B104FA27BA2B864FC36959EEBA8E968B4C6194447F608C9C459F416378
File Size:
4.43 MB, 4434949 bytes
|
|
MD5:
fb87c0ec9402bb3b0fae0f7e5c4870a2
SHA1:
60c91039596bc216a5892fb6f2c217943011cf8f
SHA256:
939E5BAB90B2B5AA81DABBC079240DE6A9828BEA9AB58C594DDE284EF0C84007
File Size:
4.06 MB, 4061992 bytes
|
|
MD5:
c2d9f7c7eb88822615bbcd333388ecc4
SHA1:
2fa4cbebe7d6c71d5fd816e7f6251ac137dc6bde
SHA256:
3D669F04A6D493F68140BAC4662E99E3E3B0B48F7E1EA95C43986AF337579945
File Size:
5.25 MB, 5250288 bytes
|
|
MD5:
e784f89f813e7f2cf77d055c1d6c3b82
SHA1:
3f0e16c250a9a9b93ae8f1b13478da47aeabaea7
SHA256:
A9866CD4EC2387BC9F36EF2BE701C2F79DA521820D17904382A1A92E357240CB
File Size:
1.79 MB, 1789952 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has exports table
- File has TLS information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
Show More
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Show More
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name |
|
| File Description |
|
| File Version |
Show More
|
| Internal Name |
|
| Legal Copyright |
|
| Original Filename |
|
| Product Name |
|
| Product Version |
Show More
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| 天津旗鱼网络科技有限公司 | DigiCert SHA2 Assured ID Code Signing CA | Self Signed |
| Shanghai Baizhi Network Technology Co., Ltd. | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Hash Mismatch |
| Shanghai Chang Zhi Network Technology Co,. Ltd. | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Self Signed |
| 成都奇鲁科技有限公司 | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Self Signed |
| Hangzhou Shunwang Technology Co.,Ltd | DigiCert Trusted Root G4 | Root Not Trusted |
Show More
| Shanghai Baizhi Network Technology Co., Ltd. | DigiCert Trusted Root G4 | Hash Mismatch |
| Shanghai Chang Zhi Network Technology Co,. Ltd. | DigiCert Trusted Root G4 | Root Not Trusted |
File Traits
- 2+ executable sections
- HighEntropy
- imgui
- Installer Version
- No Version Info
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 3,283 |
|---|---|
| Potentially Malicious Blocks: | 221 |
| Whitelisted Blocks: | 2,658 |
| Unknown Blocks: | 404 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\harddisk0\dr0 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\cacert.pem | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\dat.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\dat.ini | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\installer20260403.log | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\lefttitle.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\netlink.dat | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\netlink.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\netlink.ini | Synchronize,Write Attributes |
| c:\users\user\appdata\local\temp\oem.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
Show More
| c:\users\user\appdata\local\temp\playphoto.gif | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\roaming\360netul\547d80391263079f2e025a773fe0d313212e34da_0005297544.netul.log | Generic Write,Read Attributes |
| c:\users\user\appdata\roaming\microgame\netbridge.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\roaming\microgame\netbridge.zip | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\roaming\microgame\netbridge.zip | Synchronize,Write Attributes |
| c:\users\user\appdata\roaming\microgame\netbridge.zip | Synchronize,Write Data |
| c:\users\user\appdata\roaming\microgame\netbridge.zip.temp | Generic Write,Read Attributes |
| c:\users\user\appdata\roaming\microgame\utils\7z.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\downloads\cacert.pem | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\downloads\log\update20260109.log | Generic Read,Write Data,Write Attributes,Write extended,Append data |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\com_key::user_id | 6Sdt9LS1p4tLBHLhCa+3pwff8IJVyZzGMsCAPr2cajWw/5M8juyjJUgMWohVZzEvWZSDHJ9eV2H+Y3CSu8+W0g== | RegNtPreCreateKey |
| HKCU\software\com_key::id_check | �^'o�l4tfTqt���� | RegNtPreCreateKey |
| HKLM\software\wow6432node\com_user::m2 | ����X�E�]�C��T��}iV< | RegNtPreCreateKey |
| HKLM\software\wow6432node\commaster::mid | w�sGު�$�*4k��^v���z�2Z�i��4٬ | RegNtPreCreateKey |
| HKLM\software\wow6432node\commaster::m2 | ����4�(S��O��˥ٽ�J | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix | RegNtPreCreateKey |
Show More
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix | Cookie: | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix | Visited: | RegNtPreCreateKey |
| HKLM\software\microsoft\systemcertificates\authroot\certificates\3679ca35668772304d30a5fb873b0fa77bb70d54::blob | ︗ꕰ葧듊ḋɡ໕ꃊᵓ䵫箙妼 ` VeriSign Universal Root Certification Authority S B 䀰ℰଆ虠ňŅᜇ〆〒ؐ⬊ĆĄ㞂ļ́ダ؛朅ಁ́ሰူਆثЁ舁㰷āȃ쀀 4 ㈰ࠆثԁ܅ȃࠆ | RegNtPreCreateKey |
| HKLM\software\microsoft\systemcertificates\authroot\certificates\0563b8630d62d75abbc8ab1e4bdfb5a899b24d43::blob | 캇笋สI壡魱꠷犓 쩭큛켍༜瀲퍙뉴ꚜ엣ꘊS @ 㸰ἰआ虠ňﶆɬ、〒ؐ⬊ĆĄ㞂ļ́ダ؛朅ಁ́ሰူਆثЁ舁㰷āȃ쀀 4 ㈰ࠆثԁ܅ȃࠆثԁ܅̃ࠆثԁ܅Ѓࠆثԁ܅ăࠆثԁ܅ࠃb 逾떙币䢏lᆝ﨡㖺襚槟Ṗ옽尲 | RegNtPreCreateKey |
| HKLM\software\microsoft\systemcertificates\authroot\certificates\0563b8630d62d75abbc8ab1e4bdfb5a899b24d43::blob | \ t�f�̕��A��r�� c�c b�Z�ȫKߵ���MC O_i09� {@��ʏ D i g i C e r t E뢯�˂1-Q���!��m�b >���^�Hl ���!��5Z����iV=�2\ 4 02+++ | RegNtPreCreateKey |
| HKLM\software\microsoft\systemcertificates\authroot\certificates\3679ca35668772304d30a5fb873b0fa77bb70d54::blob | 涭␛豪 礶㗊蝦ひきﮥ㮇꜏띻名~ 쀀⼃ǖ 魃前涐ꃷ焗⧗蝒댣 瞶槺䝈原픒㈇ݶ韑ᤇ ᐰࠆثԁ܅̃ࠆثԁ܅ăb 餣ᅖꔧ╱賞ൡ碠좵缆艎邂뢿㱋 4 ㈰ࠆثԁ܅ȃࠆثԁ܅̃ࠆث | RegNtPreCreateKey |
| HKLM\software\microsoft\systemcertificates\authroot\certificates\3679ca35668772304d30a5fb873b0fa77bb70d54::blob | 궎Ƶ䶪ᶌᦕ ︗ꕰ葧듊ḋɡ໕ꃊᵓ䵫箙妼 ` VeriSign Universal Root Certification Authority S B 䀰ℰଆ虠ňŅᜇ〆〒ؐ⬊ĆĄ㞂ļ́ダ؛朅ಁ́ሰူਆثЁ舁㰷āȃ | RegNtPreCreateKey |
| HKLM\software\microsoft\systemcertificates\authroot\certificates\3679ca35668772304d30a5fb873b0fa77bb70d54::blob | \ ࠀ 涭␛豪 礶㗊蝦ひきﮥ㮇꜏띻名~ 쀀⼃ǖ 魃前涐ꃷ焗⧗蝒댣 瞶槺䝈原픒㈇ݶ韑ᤇ ᐰࠆثԁ܅̃ࠆثԁ܅ăb 餣ᅖꔧ╱賞ൡ碠좵缆艎邂뢿㱋 4 ㈰ࠆثԁ܅ | RegNtPreCreateKey |
| HKCU\software\com_key::user_id | FRiUHCqJT7wtBFxJK/KmHG8oXf2f8Y2StQ54HLZ3Fswb7dgGBLkhGFH6bETdzpEhiZJ2H4MS6crANFdWerz+nQ== | RegNtPreCreateKey |
| HKCU\software\com_key::id_check | X*ܶE�R��Tw*w�[1 | RegNtPreCreateKey |
| HKLM\software\wow6432node\com_user::m2 | �������A�N�7���G�T" | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Network Winsock2 |
|
| Network Info Queried |
|
| Network Winsock |
|
| Anti Debug |
|
| Network Winhttp |
|
| Encryption Used |
|
| Network Wininet |
|
| User Data Access |
|
| Other Suspicious |
|