freeaudioeditor.exe

Kakalume

Huaxinwantong Beijing Technology Ltd

The application freeaudioeditor.exe, “Kakalume Setup ” by Huaxinwantong Beijing Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.taggiftflash.com and multiple other hosts.
Publisher:
Huaxinwantong Beijing Technology Ltd  (signed and verified)

Product:
Kakalume

Description:
Kakalume Setup

MD5:
1ef9101f255b6719fcf47265d096407e

SHA-1:
405bb3a3a9c3919722c8614689d60ad38922fe63

SHA-256:
57b196dcb8b4946f7aecab0f06f589c82de32713102a65ce9b1fd319716669f8

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/29/2024 8:44:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Huaxinwa.Installer.Meta (M)
16.4.25.11

File size:
920.8 KB (942,856 bytes)

Product version:
5.4

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\freeaudioeditor.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/23/2016 9:00:00 PM

Valid to:
3/24/2017 8:59:59 PM

Subject:
CN=Huaxinwantong Beijing Technology Ltd, O=Huaxinwantong Beijing Technology Ltd, STREET="Dong Balizhuang 54, Building 2", L=BeiJing, S=BeiJing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C31292C6449E082B3FBF99E310243E2E

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Q6BlAcWnMHpp1wd/N9DEtfnjmXDkLqBCihLCtF7CRPe6rcVj:Q6fSnM3GFNAMrMihLGF7CRNrch

Entry address:
0xAA98

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 2E, 86, FF, FF, E8, 35, 98, FF, FF, E8, 9C, 9B, FF, FF, E8, B7, 9F, FF, FF, E8, 56, BF, FF, FF, E8, ED, E8, FF, FF, E8, 54, EA, FF, FF, 33, C0, 55, 68, 69, B1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 32, B1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, D0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, C2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, 24, 93, FF, FF, 8D, 55, F0, 33, C0, E8, 66, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
40.5 KB (41,472 bytes)

The file freeaudioeditor.exe has been seen being distributed by the following 50 URLs.

http://www.taggiftflash.com/c?x=MeNt1Acz1nXARuUp2swKT fDa1P0fld6EkxGL YLDuY=&c=kAmibN5SlfOAeoq5EPqO0kaO0aGVdrDnyPyaERfDKgMfSVT/Y9MOKs3Ed4LjdpDw LM9 nPKbzyhr7b3CwogwRbK07AFABCMbhwljYPjeeGgLNGFlJxB352JUORDs1djHaSWaR67PZPnW6PgV6S7C02oqf3FiOO0HB/PB0PJmm8=&e=0&downloadAs=FreeAudioEditor.exe&fallback_url=http://www.downloadonic.com/free-audio-editor.com/.../FreeAudioEditor_IS.exe

http://www.taggiftflash.com/c?x=t2 JegFsWRu0eVaAsON5EC4DeWi/cybzw8T TcG zLc=&c=6onINkMcYqtJQ2UPV9o oxRB0b/fwWZQVTpJrQUejH9UJaoF/vZBnLWxXFiidWXGqthVRgG1S2o0xGwRA0ZDHS7I GO1NcghXyYsohPAVBbq31koEPNGjpcywMZdpF8LhHG75sdJ6cTOekmS9CEH1O6YwN/IkigHRGkry GdiR4=&e=0&downloadAs=FreeAudioEditor.exe&fallback_url=http://www.downloadonic.com/free-audio-editor.com/.../FreeAudioEditor_IS.exe

http://www.taggiftflash.com/c?x=fmF7Zadb9G5W8PI/omwwmnn2XjiWn5SrkLavt53AqKE=&c=RgteaK2zjKf4sq/iCyrLMcC1sxHrDS2qCc0RgMcXhsDHhfX2NFCsIq 3sJI8xd1i5ZsQlmClBCc8Jn0qJ8xX5lPxPPn7ffB0heDVkUZApR1iCIzHD O6kwzkmXo/t7SrQ YM4JGVvLykpAuAWdao6u6Nw s42rxtGxiFaNWI3iLMgSHj6iJurq4CuyDIbycP&e=0&downloadAs=FreeAudioEditor.exe&fallback_url=http://www.downloadonic.com/free-audio-editor.com/.../FreeAudioEditor_IS.exe

http://www.taggiftflash.com/c?x=hcd7tKxbpguvrZ/d9jsMYOwle3jVcrwN7CSFSJR7nXw=&c=82Ehg245645 O4BsimrhfjZB470q1w1zHKJREAYcC6Q6CRkhqPmwAs2eDBB 3g1t8CcLSzMVbNi2qNqL6aSkZWA79oVIi9 8bovNHjcsi/wuTuwhUo/YVzW2adSv/kydG45z6NjwSDP9DREkx1Y7sY4ugQl qeyhr9P7Z0cOca8=&e=0&downloadAs=FreeAudioEditor.exe&fallback_url=http://www.downloadonic.com/free-audio-editor.com/.../FreeAudioEditor_IS.exe

http://www.taggiftflash.com/c?x=YcwVQwlvcsSqDme8VZ o6A138m1lgrAMRb2wW2jdVpM=&c=lftRpnyUvwJMyrmlTWpFgqjxoDHzrtRem9Ntwa3VzCoEwcSDvdHiuNgSsDQXpTudoCn2AKiuFVUKTCYmzmzqPCMLB4RYAxE4HCky 7YAiEUrOherOqmm2avtNf/18ErmXJ PMDmXo7PeTDdeb Nzu/702cirW/zy89cKuwIpCt8qnbcBq SWvqrWr08IrE6Z&e=0&downloadAs=FreeAudioEditor.exe&fallback_url=http://www.downloadonic.com/free-audio-editor.com/.../FreeAudioEditor_IS.exe

http://www.taggiftflash.com/c?x=raOA6OdbS8VcUdcqM6iJAMd8wKnVnJ8qJJquTvDnukU=&c=Aqxuv2McQUCjDFmVTAmpfjfMSKGC57fNsxnHK 6c6NR1Zl0Xvlzq2NhIbL5J2D4CVmb/HIgaQZwiPaHqnP9yTui1j06giVc34SLFPrQ6Nn725CKL2K CZSbxMuBD4y/kCyGctlI/ g/vkJ4cTyk6Mdm0TicJu/WztHy/uI1cuXw=&e=0&downloadAs=FreeAudioEditor.exe&fallback_url=http://www.downloadonic.com/free-audio-editor.com/.../FreeAudioEditor_IS.exe

http://www.taggiftflash.com/c?x=jwNi3euHHCBOp0K8a/tR9xt3j9o7JHdiF6bV vH6lw=&c=DWAEtnEzpO5TUGPMQ/Q0uV3KgPLr07 mP8ctrmTdp6oH4pmPVocnCgp92xouLwWJIeLmqfCaDzuuH76pUZ9GQ3sv55vXOFtkJGuVuqjbJAai/bBR1 KJJ7KyyXcn8klTO/KK8qvdG5I7bSAOSpvTopZZmzmqRPUJCwTBUZD5oP8fdnjD29U1iu9l2p42ZRcz&e=0&downloadAs=FreeAudioEditor.exe&fallback_url=http://www.downloadonic.com/free-audio-editor.com/.../FreeAudioEditor_IS.exe

Latest 30 of 92 download URLs

Remove freeaudioeditor.exe - Powered by Reason Core Security