PUP.Softcnapp.D

Analysis Report

General information

Family Name: PUP.Softcnapp.D
Signature status: Self Signed

Known Samples

MD5: 122fe3c3e41fa690e63ba7aa6cd4719f
SHA1: 880e40a23b69164d9bc83768351f3a42518597da
File Size: 4.61 MB, 4607784 bytes
MD5: 554bb4f266bca4d1dc062165e93f9bb2
SHA1: 5d174253a6192371fc88bfdf77c241b9c42e11dd
SHA256: F63ED4E81C7F674CFCE4F607BC8EBE377D740D72AB2E7BEF4681EDCF8BDE4425
File Size: 4.00 MB, 3995648 bytes
MD5: 04b518ff5b513f3b2cd483a330ef0c23
SHA1: c985221c85c82b593999abb359797aea409f7b6d
SHA256: ABBCCA4E5136C4FF3A7AA802E5A9D31F0FDE62D9ED25534F580A19F979D07AFC
File Size: 3.21 MB, 3206656 bytes
MD5: fa058f4ba27841cd9de8778cfde43c6c
SHA1: 850943034dc6f8292db79db1226b85db509a20cf
SHA256: D29FCBC05A79E7F948CFA42A866A37D9D2CF23DD3EB19C55075F8CD3350F1A86
File Size: 3.21 MB, 3206656 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • 北京华网智讯软件有限公司
  • 深圳市开心袋鼠科技有限公司
File Description
  • GoodZip
  • GoodZip-全能助手
  • 全能电脑助手-压缩
File Version
  • 1.4.7.51208
  • 1.4.2.50912
  • 1.2.0.40320
Internal Name
  • GoodZip
  • GoodZip-全能助手
  • 全能电脑助手-压缩
Legal Copyright
  • Copyright (C)2022深圳市开心袋鼠科技有限公司
  • Copyright (C)2024 北京华网智讯软件有限公司
  • Copyright (C)2025 北京华网智讯软件有限公司
  • Copyright (C)2025 深圳市开心袋鼠科技有限公司
Original Filename
  • SfxWin.sfx
  • Uninst.exe
Product Name
  • GoodZip
  • GoodZip-全能助手
  • 全能电脑助手-压缩
Product Version
  • 1,4,7,51208
  • 1,4,2,50912
  • 1,3,7,50113
  • 1,2,0,40320

Digital Signatures

Signer Root Status
北京华网智讯软件有限公司 DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed
北京华网智讯软件有限公司 DigiCert Trusted Root G4 Root Not Trusted

File Traits

  • HighEntropy
  • imgui
  • x86

Block Information

Total Blocks: 12,916
Potentially Malicious Blocks: 755
Whitelisted Blocks: 11,544
Unknown Blocks: 617

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x ? ? ? ? 0 0 ? x ? x ? x ? 0 ? ? ? x ? ? 0 0 0 0 x x ? 0 x x 0 0 0 ? x ? ? ? x ? ? x x x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? 0 x 0 ? ? 0 1 1 1 x x x x 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? ? 0 ? 0 0 0 0 0 0 ? 0 ? 0 ? ? 0 0 0 ? ? ? ? 0 0 0 ? 0 ? ? ? ? 0 ? ? ? 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 ? ? 0 0 0 ? ? 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? 0 0 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? x x x ? ? x x ? ? 0 0 ? 0 0 0 0 ? x ? 0 ? ? 0 x 0 ? 0 0 ? ? x 0 ? x ? ? 0 x 0 ? x ? 0 ? ? x x x 0 ? 0 ? 0 x x 0 0 x ? x 0 0 ? ? 0 0 x 0 ? 0 0 ? x ? 0 x ? ? 0 ? ? ? ? ? 0 ? 0 x 0 ? ? x 0 0 0 x 0 ? x ? x 0 x 0 0 0 x x 0 x 0 ? ? ? 0 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 x x x 0 x x x 0 0 0 x x ? ? 0 0 x ? ? ? 0 0 ? ? ? ? x 0 x ? x x x ? ? x ? ? x 0 x ? ? 0 ? 0 0 0 x ? ? ? ? x x x x x x 0 ? ? ? ? ? 0 ? 0 0 0 0 ? ? 0 ? 0 x 0 ? ? 0 ? ? ? ? ? 0 ? ? 0 0 ? x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? 0 ? 0 x x 0 ? ? 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 ? ? x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? 0 x ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? x x 0 0 0 0 0 0 0 0 x 0 x ? ? 0 0 0 0 0 0 0 0 0 x 0 0 x 0 ? 0 0 x x 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 x x 0 0 x ? ? 0 x ? 0 ? 0 0 0 ? ? ? 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 x ? 0 x x 0 0 0 x 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? x x 0 0 x 0 ? 0 0 0 0 x ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? x ? 0 0 x ? 0 0 ? 0 0 0 0 0 ? x 0 ? x 0 ? ? ? 0 x 0 x ? x x x x x 0 x 0 0 x 0 0 0 0 x ? ? 0 x x 0 0 0 0 0 0 0 ? ? x 0 0 x 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? x 0 0 0 0 0 0 ? x ? 0 0 0 0 ? ? x 0 0 x ? 0 0 0 0 0 0 0 0 ? 0 ? 0 x ? x 0 ? 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 x 0 0 x ? x 0 0 x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? x x x 0 ? 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 x 0 x 0 ? 0 0 0 ? ? 0 0 x 0 x 0 0 0 0 0 x 0 0 0 ? x x 0 0 x 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 x 0 0 0 0 0 0 0 0 x ? 0 ? ? x 0 0 0 x 0 0 0 x ? 0 ? ? ? 0 0 0 ? 0 ? 0 ? 0 0 x ? ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? x x 0 0 ? x 0 0 0 ? 0 0 0 x 0 ? 0 0 0 ? ? ? ? 0 0 0 ? ? 0 ? 0 ? 0 0 0 ? 0 0 ? ? x 0 x 0 0 ? ? 0 x 0 0 ? ? ? ? ? ? ? x ? 0 ? ? 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? ? 0 0 ? ? 0 0 0 0 x 0 0 0 0 ? ? 0 0 0 ? 0 0 0 x 0 0 x 0 0 x ? ? x 0 ? ? ? ? ? x ? 0 0 ? 0 0 0 ? 0 ? 0 ? 0 0 0 0 x x 0 x 0 0 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 x 0 ? 0 ? ? ? ? 0 ? 0 0 0 0 ? ? 0 0 0 0 ? 0 ? ? ? 0 0 ? ? ? x 0 ? 0 ? x 0 0 ? ? 0 0 x ? ? 0 0 ? 0 0 x ? ? 0 0 0 0 0 0 ? 0 ? 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 ? 0 0 0 0 ? ? 0 0 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? 0 0 ? 0 0 1 ? ? 0 ? ? 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? 0 x x ? ? ? 0 ? 0 ? ? ? ? 0 0 ? 0 0 0 ? ? ? ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 ? ? 0 ? ? 0 x 0 1 1 ? ? ? 0 ? ? 0 ? 0 x 0 0 x 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? x ? x 0 0 ? ? ? ? ? 0 ? 0 x ? 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 ? x 0 ? 0 ? ? 0 0 0 x 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 x x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 0 0 ? 0 0 ? 0 0 0 0 0 x 0 ? 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 0 x x x 0 0 0 x x x x x x x x 0 0 0 0 0 0 0 x 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.ON
  • Softcnapp.A
  • Softcnapp.KA

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Anti Debug
  • OutputDebugString

Trending

Most Viewed

Loading...