PUP.SparkOnSoft
The detection of PUP.SparkOnSoft on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It is essential to understand the nature of this threat and take appropriate steps to remove it to prevent potential harm. In this report, we will provide an overview of PUP.SparkOnSoft, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.
Table of Contents
What Is PUP.SparkOnSoft?
PUP.SparkOnSoft is a type of potentially unwanted program that may have been installed on your system without your knowledge or consent. PUPs are software applications that may not be malicious in nature but can still cause problems with your computer's performance, privacy, and security. They often come bundled with other software or are downloaded from the internet, and can be difficult to remove without proper guidance.
How PUP.SparkOnSoft Operates
PUP.SparkOnSoft, like other PUPs, may operate by collecting user data, displaying unwanted advertisements, or modifying system settings without permission. It may also install additional software or components that can further compromise your system's security and performance. The exact operating methods of PUP.SparkOnSoft may vary, but it is essential to be aware of the potential risks and take steps to mitigate them.
Symptoms of Infection
Systems infected with PUP.SparkOnSoft may exhibit a range of symptoms, including slow system performance, unwanted pop-ups or advertisements, and unexpected changes to system settings. You may also notice unfamiliar programs or icons on your desktop, or experience issues with your internet browser, such as redirected searches or unwanted toolbars. If you are experiencing any of these symptoms, it is crucial to take action to remove the PUP and prevent further damage.
How to Remove PUP.SparkOnSoft
- Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for internet access. This will enable you to download and install removal tools if necessary.
- Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of PUP.SparkOnSoft. This may require purchasing a license or subscription to the removal tool.
- Uninstall any suspicious programs or applications that may be related to the PUP. Be cautious when uninstalling programs, as some may be legitimate or required for system operation.
- Reset your internet browsers, including Chrome, Firefox, and Edge, to their default settings to remove any unwanted extensions, toolbars, or settings that may have been modified by the PUP.
- Reboot your system and perform a follow-up scan to ensure that all components of PUP.SparkOnSoft have been removed. This will help to verify that the removal was successful and that your system is clean.
Conclusion
Removing PUP.SparkOnSoft from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined in this report, you can effectively remove the PUP and prevent potential harm to your system. It is essential to remain vigilant and take proactive steps to protect your system from future threats, including keeping your operating system and software up to date, using reputable anti-malware tools, and being cautious when downloading and installing software from the internet. Remember to always prioritize your system's security and performance to ensure a safe and efficient computing experience.
Analysis Report
General information
| Family Name: | PUP.SparkOnSoft |
|---|---|
| Signature status: | Self Signed |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
ca7aee4051ba32dc74eafa1d2f74513c
SHA1:
80eea992a773237bb601d75058f862f7feaffeba
SHA256:
D878E829C49EB5FD247EE15633E949B20270F6E0B93971DE59532B70E64B98EB
File Size:
9.13 MB, 9133552 bytes
|
|
MD5:
c0a9127f8ced890563d9f38dddd29469
SHA1:
ab268ba34430904cbf7f944281f9d00fef83cb1b
SHA256:
B524281FE3F466EC5AF4D147BE1ADF96B076A3AC14AB2AD2F1122AA4F5DFB45A
File Size:
2.83 MB, 2828583 bytes
|
|
MD5:
a1312895bb804a7c52ece6edd72bc8ce
SHA1:
3361cd48c2d2c6e35c94389718f4fc3f072ee620
SHA256:
D95F2642DD2E1E1160FB86ADDE91A28C0A5B2DE2CED5F45004C19C24C61BCBA0
File Size:
749.12 KB, 749120 bytes
|
|
MD5:
5cb9fe5d3f190a6e1d83df1b82cb4f1d
SHA1:
1fd9df2e381f1f1b060fb0d6e57b915ad35774dc
SHA256:
6A5400F9E6694A262CB57007BE91E2DBCF98DA77C041A9556B1A8120C084FD7E
File Size:
2.80 MB, 2801408 bytes
|
|
MD5:
3c4c8e054a99286792d4843b87155342
SHA1:
6ffdbfe79c0df9b2f8b1df80eec7c9f36f5c7a4c
SHA256:
25ED1C694ABD1B26690DC86CD6F2C293A23DC9A6E300620D77DC49927D3F63A0
File Size:
1.66 MB, 1655864 bytes
|
Show More
|
MD5:
9fb769484a284808ba7f1bdc486a1927
SHA1:
699e41de3393c9509ceef07a2ddc3d4599f01ae8
SHA256:
FEDEC49876C2AA8DCF13B78297F5B4D9C437F1509862ABB02E3980FCA9E3AD7D
File Size:
2.97 MB, 2966000 bytes
|
|
MD5:
065ee5084a584caf62b66475f93e15f4
SHA1:
23180e8671cf435bc244a8d9eb1e2ddbd3b02534
SHA256:
5FA0684AEED9A7AE766BB4CE17D4C0FEDDDDB80B1433D21C39497BC153D97DE5
File Size:
2.86 MB, 2855560 bytes
|
|
MD5:
8d71fb862b8b1cc8cd182b281cbf473e
SHA1:
51d89e5df160d052f30cee7fd509d551225488d4
SHA256:
D61282F7D90A6C3C3E5D883B43AEF8B715863DA7E19F9469F6E5F020CDF0FC0B
File Size:
473.67 KB, 473667 bytes
|
|
MD5:
3681ee646eb0de915a26a74bc8b4971c
SHA1:
31e7e0f9667f00ea69d1e697a60225fbe9415238
SHA256:
A36013F6D57B5FF80C609FFD89C61EEA8A6A15F81B893DE40BF94C465C286AAC
File Size:
2.39 MB, 2393664 bytes
|
|
MD5:
eee0046f4f4d2241b80bec9b30b05741
SHA1:
92e8149dd07ae68f3bd9852304b904bded9a049d
SHA256:
0E0BB034855945FE207A781A8725F4911D7A912B2BFE5FDE1DF5E775424F5EAE
File Size:
2.89 MB, 2894472 bytes
|
|
MD5:
9942bd633937989fa63ac96b646954f3
SHA1:
9b2264a5625e69657a8ea53f5f5073a38f5a326a
SHA256:
B976E4207CCE259CC47E3E41210B5B13D3E0B02B4E7647AD1805C898FF8076EB
File Size:
2.45 MB, 2454624 bytes
|
|
MD5:
6d9f5c1da256dffdce52d5d223d66a84
SHA1:
ef7250e0ee497f0e6b12f74c92fe5550bd738408
SHA256:
859389CDB7C9C3764F9E068DCF79629B8C8322AB1F36A585BDBF1D35BA31BBE7
File Size:
4.05 MB, 4054592 bytes
|
|
MD5:
aca4acf8037a8ab1f7cc0316b19867a5
SHA1:
77276fe6d558bd28c0d5a39046e60e3f09baa467
SHA256:
E3D16951DEAC336FC9D82666CCE322B5AB9A493D9716D9AB484CF16CAEF52286
File Size:
1.93 MB, 1927224 bytes
|
|
MD5:
4a9856729d94e9d1139a9adad528a796
SHA1:
47c7f39b4081c0b316a745fa6c05496443a5d548
SHA256:
1F3AE824120BBBA1A359513775229D6D4235CA38C38A3135F71152B5A35DF475
File Size:
4.05 MB, 4054736 bytes
|
|
MD5:
70ef83fbe5081a4a298e29a110fd7564
SHA1:
ba7cd60517536c5b68e8ed9b40e21f1889ceba41
SHA256:
941F7EF682D0C676AF62923BD2210166238469DD290B8A3CE2F785C1613FAA08
File Size:
4.06 MB, 4063240 bytes
|
|
MD5:
ab2d69b27ccd7fbe9cfcfa666d8863aa
SHA1:
11d6a666e1fdcdeee966c2d18e4afdb099d72478
SHA256:
89DF1874342B633F0A5A93B933B4241075F7B8AEA1FF0455A1FEDD6007F73E99
File Size:
1.62 MB, 1617245 bytes
|
|
MD5:
30e2848e86601701d8c5df12a84562c6
SHA1:
8185ba974e58b465a006dafcd207f8517d00d159
SHA256:
0D4D33CE993DD0E4C3F891D278DAB9049485A5BB9213881390796FED9417D090
File Size:
1.37 MB, 1367664 bytes
|
|
MD5:
bbe8c4750680f699f56c1713710427b4
SHA1:
abfa8c271db62baccc46014321dbf10683a99164
SHA256:
D4A5535D754E443843FA9C7BEBED9C9BE43F1BA0C57CB13CE2832B81C2EE87CB
File Size:
2.42 MB, 2416216 bytes
|
|
MD5:
a8e3d2563df652405a4c29a734376439
SHA1:
2a435184f32cd2cfde2d2e9bddd5647007c49c5c
SHA256:
FDD1AFEB298C72873D9C3FA208DA376FA3FAEEFCA033F867629C2BF9EA9E22F0
File Size:
473.67 KB, 473667 bytes
|
|
MD5:
6509b1c7a3c450a0036b8c9f6f80fa34
SHA1:
aaca7ed7e4c5f066925f7965cb12ef838d35021d
SHA256:
4E62F9469218323EAB43A27FE738C7108D43F09BD58992A2097E21DC724236FF
File Size:
534.07 KB, 534072 bytes
|
|
MD5:
8f2400fdf53a8bbdf2d3ee752cb15587
SHA1:
7a6b9d11cedb2a09f907bfe73e6d6bd97fa23a86
SHA256:
28F0CC3DCE3EF774D638488EEB1E3802E23B2ECA73292BF55E0DFE5BD69FC144
File Size:
526.90 KB, 526904 bytes
|
|
MD5:
0cc8363973a344db450419c68bcc69b5
SHA1:
46b81b98b7cf8f397736468110f076dca0e03a1f
SHA256:
ED01EDC6DC29BDCD5B04706DC74614EAD5A5472A6EF75A94A0EF597DF195A8F8
File Size:
58.94 KB, 58944 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have resources
- File doesn't have security information
- File has exports table
- File has TLS information
- File is .NET application
- File is 32-bit executable
Show More
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Show More
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version |
|
| Comments |
|
| Company Name |
|
| File Description |
Show More
|
| File Version |
Show More
|
| Internal Name |
|
| Legal Copyright |
|
| Original Filename |
|
| Product Name |
Show More
|
| Product Version |
Show More
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| Secure PC Software LLC | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Self Signed |
| Rush Delivery, LLC | GlobalSign GCC R45 EV CodeSigning CA 2020 | Self Signed |
| Mainstay Crypto LLC | Microsoft Identity Verification Root Certificate Authority 2020 | Root Not Trusted |
| Secure PC Software LLC | SSL.com EV Code Signing Intermediate CA RSA R3 | Self Signed |
| APP Craftsmen LLC | Sectigo Public Code Signing Root R46 | Root Not Trusted |
Show More
| Smart Contract LLC | Sectigo Public Code Signing Root R46 | Root Not Trusted |
File Traits
- 2+ executable sections
- Inno
- InnoSetup Installer
- Installer Manifest
- Installer Version
- nosig nsis
- Nullsoft Installer
- VirtualQueryEx
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 94 |
|---|---|
| Potentially Malicious Blocks: | 6 |
| Whitelisted Blocks: | 41 |
| Unknown Blocks: | 47 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Brute.BHA
- Chapak.HBX
- CobaltStrike.GI
- CobaltStrike.GIA
- Injector.FFA
Show More
- MSIL.MediaArena.K
- MSIL.TelegramBot.S
- MSIL.TelegramBot.T
- MSILZilla.TC
- Trojan.Agent.Gen.VN
- Trojan.Injector.Gen.GVK
- Trojan.Injector.Gen.GVL
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\sb\bb\installconfig.txt | Generic Write,Read Attributes |
| c:\users\user\appdata\local\sb\bb\metadata.txt | Generic Write,Read Attributes |
| c:\users\user\appdata\local\sb\cm\installconfig.txt | Generic Write,Read Attributes |
| c:\users\user\appdata\local\sb\cm\metadata.txt | Generic Write,Read Attributes |
| c:\users\user\appdata\local\sb\cm\systeminfo.txt | Generic Write,Read Attributes |
| c:\users\user\appdata\local\sb\ph\installconfig.txt | Generic Write,Read Attributes |
| c:\users\user\appdata\local\sb\ph\metadata.txt | Generic Write,Read Attributes |
Show More
| c:\users\user\appdata\local\temp\3bb504e0-4f89-11d3-9a0c-0305e82c33lulp\bb\appsettings.json | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\3bb504e0-4f89-11d3-9a0c-0305e82c33lulp\bbinstaller.log | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\3cmfc1d58-f4a6-44cc-97e7-9637516da167d2w\camerashieldaisetup.log | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\3cmfc1d58-f4a6-44cc-97e7-9637516da167d2w\cm\appsettings.json | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\89fc1d58-f4a6-44cc-97e7-9637516da167ax05\ph\appsettings.json | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\89fc1d58-f4a6-44cc-97e7-9637516da167ax05\phinstaller.log | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\bb09561d420844ffb050b8378eb0acd3\pchelperai.installerupdaterlib.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\bb09561d420844ffb050b8378eb0acd3\pchelperai.installerupdaterlib.dll.lock | Generic Write,Read Attributes,Delete |
| c:\users\user\appdata\local\temp\is-2d7gi.tmp\ba7cd60517536c5b68e8ed9b40e21f1889ceba41_0004063240.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\is-4vcha.tmp\_isetup\_setup64.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\is-4vcha.tmp\physfs.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\is-crm3t.tmp\ef7250e0ee497f0e6b12f74c92fe5550bd738408_0004054592.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\is-d932l.tmp\_isetup\_setup64.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\is-d932l.tmp\physfs.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\is-femh4.tmp\47c7f39b4081c0b316a745fa6c05496443a5d548_0004054736.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\is-lvfsd.tmp\_isetup\_setup64.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\is-lvfsd.tmp\physfs.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsi777b.tmp\banner.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsi777b.tmp\blosc2.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsi777b.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsk2c27.tmp\banner.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsk2c27.tmp\blosc2.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsk2c27.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsr764f.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsr7660.tmp\banner.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsr7660.tmp\nsisunz.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsr7660.tmp\recipelocale.zip | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nss776a.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsu2c16.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\~nsua.tmp\un_a.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52 *1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62 *1\??\C:\P | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\sb\ph::instanceid | 765e0d61-c34f-4cd9-818d-9afb014ee068 | RegNtPreCreateKey |
| HKCU\software\sb\ph::macid | 42c4b0e3-fc98-141c-9afb-f4c8996fb924 | RegNtPreCreateKey |
| HKCU\software\sb\ph::firstlaunchdate | 2026-03-09 | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing | RegNtPreCreateKey |
Show More
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory | %windir%\tracing | RegNtPreCreateKey |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize | RegNtPreCreateKey | |
| HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory | %windir%\tracing | RegNtPreCreateKey |
| HKCU\software\sb\bb::instanceid | 7667ae7d-2e97-4be6-9568-f80ad832fce5 | RegNtPreCreateKey |
| HKCU\software\sb\bb::macid | 42c4b0e3-fc98-141c-9afb-f4c8996fb924 | RegNtPreCreateKey |
| HKCU\software\sb\bb::firstlaunchdate | 2026-03-15 | RegNtPreCreateKey |
| HKCU\software\sb\cm::instanceid | 6aa5a2a8-bfa9-4661-947b-433300317e7c | RegNtPreCreateKey |
| HKCU\software\sb\cm::macid | 42c4b0e3-fc98-141c-9afb-f4c8996fb924 | RegNtPreCreateKey |
| HKCU\software\sb\cm::firstlaunchdate | xT�� | RegNtPreCreateKey |
| HKLM\software\microsoft\tracing\rasapi32::enablefiletracing | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasapi32::filetracingmask | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasapi32::consoletracingmask | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasapi32::maxfilesize | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasapi32::filedirectory | %windir%\tracing | RegNtPreCreateKey |
| HKLM\software\microsoft\tracing\rasmancs::enablefiletracing | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasmancs::filetracingmask | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasmancs::consoletracingmask | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasmancs::maxfilesize | RegNtPreCreateKey | |
| HKLM\software\microsoft\tracing\rasmancs::filedirectory | %windir%\tracing | RegNtPreCreateKey |
| HKCU\software\sb\cm::countrycode | UNK | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | ?m � 8�1tX�jg �� �6 �v xy �� �� T������ 1��dc�%�� �5����3bBx �<�� %��R �7!wz #�#��$kF%:� %`� %�&� &�-'�(�(X�(�)A)�`*J*9*�"*�h+��,��-!R0P%1`1�1HO 1�D5,]9ߔ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | @m � 8�1tX�jg �� �6 �v xy �� �� T������ 1��dc�%�� �5����3bBx �<�� %��R �7!wz #�#��$kF%:� %`� %�&� &�-'�(�(X�(�)A)�`*J*9*�"*�h+��,��-!R0P%1`1�1HO 1�D5,]9ߔ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | @m � 8�1tX�jg �� �6 �v xy �� �� T������ 1��dc�%�� �5����3bBx �<�� %��R �7!wz #�#��$kF%:� %`� %�&� &�-'�(�(X�(�)A)�`*J*9*�"*�h+��,��-!R0P%1`1�1HO 1�D5,]9ߔ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | Am � 8�1tX�jg �� �6 �v xy �� �� T������ 1��dc�%�� �5����3bBx �<�� %��R �7!wz #�#��$kF%:� %`� %�&� &�-'�(�(X�(�)A)�`*J*9*�"*�h+��,��-!R0P%1`1�1HO 1�D5,]9ߔ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | m � 8�tXjg �� �6 �v �� T������ ���%�� 3bBx %��R !wz #��$kF%:� %`� %�&� (�(X�(�)�`*J*9*�"-!R1�1HO 5,];�4>3� @V� B�� FH� G�IH[uH�pH�� J�� N$U_*a$b"hc�w c�zh�ri��j�bk`k�ql(�q@� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | m � 8�tXjg �� �6 �v �� T������ ���%�� 3bBx %��R !wz #��$kF%:� %`� %�&� (�(X�(�)�`*J*9*�"-!R1�1HO 5,];�4>3� @V� B�� FH� G�IH[uH�pH�� J�� N$U_*a$b"hc�w c�ze�vh�ri��j�bk`k�ql(� | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m �� �v����(�*�"1�1HO @V� H[u_�zb"hc�w k�q{b��P� �� ��� ������m� �V ����$�8წ�� ��=�S) � B1_ T�Vw�`�V�`� ��%������ �AE��"��D��&��$���L A *�" | RegNtPreCreateKey |
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4 *1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352 *1\??\C:\P | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �n S � �v�Z xy T������5��!wz %:� &� (�(X�/9� 1`1�1HO 1�D9ߔ>3� @V� H[uH�pJ�� R20V � X�_�z`�2i��k`k�ql(�n�ArnJ tǤu�~ {b�{�=�� �P� �{�ރ �/������7��� �b:��� ����X����� �6� �T��h �T���. | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| User Data Access |
|
| Other Suspicious |
|
| Service Control |
|
| Encryption Used |
|
| Network Winsock2 |
|
| Network Winsock |
|
| Network Winhttp |
|
| Network Info Queried |
|
| Syscall Use |
Show More
21 additional items are not displayed above. |
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Keyboard Access |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\699e41de3393c9509ceef07a2ddc3d4599f01ae8_0002966000.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\23180e8671cf435bc244a8d9eb1e2ddbd3b02534_0002855560.,LiQMAxHB
|
"C:\Users\Blqkerew\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=c:\users\user\downloads\
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\92e8149dd07ae68f3bd9852304b904bded9a049d_0002894472.,LiQMAxHB
|
"C:\Users\Ydtckiks\AppData\Local\Temp\is-CRM3T.tmp\ef7250e0ee497f0e6b12f74c92fe5550bd738408_0004054592.tmp" /SL5="$9040C,1366435,867840,c:\users\user\downloads\ef7250e0ee497f0e6b12f74c92fe5550bd738408_0004054592"
|
Show More
"C:\Users\Szktldre\AppData\Local\Temp\is-FEMH4.tmp\47c7f39b4081c0b316a745fa6c05496443a5d548_0004054736.tmp" /SL5="$140324,1366435,867840,c:\users\user\downloads\47c7f39b4081c0b316a745fa6c05496443a5d548_0004054736"
|
"C:\Users\Mvqnpynz\AppData\Local\Temp\is-2D7GI.tmp\ba7cd60517536c5b68e8ed9b40e21f1889ceba41_0004063240.tmp" /SL5="$180380,1363651,867840,c:\users\user\downloads\ba7cd60517536c5b68e8ed9b40e21f1889ceba41_0004063240"
|
"C:\Users\Cpybdnts\AppData\Local\Temp\~nsuA.tmp\Un_A.exe" _?=c:\users\user\downloads\
|