freeavimpegwmvmp4flvvideojoiner.exe

Nopumalifo

Huaxinwantong Beijing Technology Ltd

The application freeavimpegwmvmp4flvvideojoiner.exe, “Nopumalifo Setup ” by Huaxinwantong Beijing Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.funtourbundle.com and multiple other hosts.
Publisher:
Purek   (signed by Huaxinwantong Beijing Technology Ltd)

Product:
Nopumalifo

Description:
Nopumalifo Setup

Version:
1.4.2.6

MD5:
1103cdde4334d756a2d024ce666f8db7

SHA-1:
db6e3c242e31ebed77a191b79d49484eb37f8df4

SHA-256:
e5c0016757ec8c8b7a956b82546e5143b1ab400036c3df12ead63b5ebe86853c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/6/2024 6:38:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Huaxinwa.Installer.Meta (M)
16.6.30.14

File size:
906.5 KB (928,248 bytes)

Product version:
2.0.9

Copyright:
Fast Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\freeavimpegwmvmp4flvvideojoiner.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/23/2016 9:00:00 PM

Valid to:
3/24/2017 8:59:59 PM

Subject:
CN=Huaxinwantong Beijing Technology Ltd, O=Huaxinwantong Beijing Technology Ltd, STREET="Dong Balizhuang 54, Building 2", L=BeiJing, S=BeiJing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C31292C6449E082B3FBF99E310243E2E

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Ati0NiGXIAR5v3nWi+dZKEUQq3p9UdRC+8Y4:AEcbXV/t+dZKEVq5b+81

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file freeavimpegwmvmp4flvvideojoiner.exe has been seen being distributed by the following 10 URLs.

http://www.funtourbundle.com/uBi5n3ssJ33FQhU dQ_e_mkB4pCPLSD696kBZrDkeuS0LATMDeF5ZtXJPfGo1hyL5mM6HfrD Uk2AFF5CPHTd1GjpuURmReJQ6nAzVrO82RcJwBMWKUo7cCZ6RdDq97pvuisI8G8JoLhDqlQL9EI2PTdJPU4enx56ZEJj3dDozHEsfdN2TT48bnRNqYnGA2EE76IbNt2DH_fMPOumLBdN1YMXZ POxudAuu3opRUuKTAwjvx2RW5WBr43wE5lrpz eh4A0UJtnhwDQrOCUd2 nZJRnaut5Zk5ggNxhastYJifW 7F4nu1GB9znRkT5rjCq3XmTnn4C1GuihjZEvpD1lLxuNzr7oPAG_1j n4Xw0M_XgfBdGT2 uNVp0xm09G2_7c0OhAJFUe7oZ6jBC1SpF8RSovbshkoxsp1zKhDURuJUwxZngq9FOxAuBkrvzB2zW1gWtB6utugZXZxqWs OhXamBDB6TjmAUBhnKTtlqujBk4yMVxXM0R4rOLnf gJLXHtVJchZiXZAF6z0VakROr5bgciQ==-G2YAAMTaOW4shsXgRb6UeqNBN3yJYgHNOGD_KpLdDQgGOM_hrR K1vKNGb9hc7bOTsjVTFJuzNTqwjM8LV3AS IaYmfh6qiI4M5HN 5IzeAD-e

http://www.factorycapitalstock.com/FAew0HkAV OnLjRm81HybZ5Q33BBBpBRkGq 9DmqMpHxMUUFEUkkZ7fxjDf MVlk ntDqGLpLjvLDt6zjjpwSfa0 ukGMK5Afhms5CBMWYkKUK7tAf5RPiHNQZsWTxcEW3Xt8SvUGFEdj8a6bx5pwzfZaqAlpHoYxxjj 0LptlELyWLWtRpYP omu DbL3DBN055PavumdrsWXf0qyo8LMAFMXcK7O iozmhAoirShgbKJvCA0k=-G2YAAMTaOW4shsXgRb6UeqNBN3yJYgHNOGD_KpLdDQgGOM_hrR K1vKNGb9hc7bOTsjVTFJuzNTqwjM8LV3AS IaYmfh6qiI4M5HN 5IzeAD

Remove freeavimpegwmvmp4flvvideojoiner.exe - Powered by Reason Core Security