freeburningstudio.exe

Nopumalifo

Huaxinwantong Beijing Technology Ltd

The application freeburningstudio.exe, “Nopumalifo Setup ” by Huaxinwantong Beijing Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.taggiftflash.com and multiple other hosts.
Publisher:
Purek   (signed by Huaxinwantong Beijing Technology Ltd)

Product:
Nopumalifo

Description:
Nopumalifo Setup

Version:
1.4.2.6

MD5:
948aaacd5909779077e2be19506e087e

SHA-1:
969b744743c8f911f7f0a54a27affdc90079dc8f

SHA-256:
f412fc38219918e98a4f199bfa21e2a7da7df3d2c8ce4828b2c9aefdcf8161f2

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/6/2024 6:28:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Huaxinwa.Installer.Meta (M)
16.6.30.12

File size:
906.5 KB (928,248 bytes)

Product version:
2.0.9

Copyright:
Fast Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\freeburningstudio.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/24/2016 3:00:00 AM

Valid to:
3/25/2017 2:59:59 AM

Subject:
CN=Huaxinwantong Beijing Technology Ltd, O=Huaxinwantong Beijing Technology Ltd, STREET="Dong Balizhuang 54, Building 2", L=BeiJing, S=BeiJing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C31292C6449E082B3FBF99E310243E2E

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:2ti0NiGXIAR5v3nWi+dZKEUQq3p9UdRC+8Y4:2EcbXV/t+dZKEVq5b+81

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9345

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file freeburningstudio.exe has been seen being distributed by the following 19 URLs.

http://www.taggiftflash.com/5 P9L7344kCF_rnacdNrTvgdV A 8MZ98LmXUbqU8PE2FXLJgVm9SRbMl_8j5S6X6IlwcO1bGf3NXGkKdRZMFLhvL8oe7l d3Aasc71ayyFgQ0t7h5TzjJJvLpQW6EBJIvQf3nKCyegGWKJK99mNedcW7yjxvWfgP5Ydo5tItir jgSARTYJVT1BEmtVx1eyvYVulnOkMGphqfQiRzqwRXIHWMl1YiCjeHqQHVzb9VflLKUpvjBROp21bH9dQnJ4JuQ8 q9yxUpJdtavI8HgfnXgeq6 zrFtZImYlnFm61K02T2vzb3CfjUEm5SbyN7UZEba4ReDtGFScZpdklDP8ymelZgjzSAbUUajVgYiJv71_qrq0dZUHpP53XkIQq6oFk54yiRLi3vLWclZ1IIUvgLiYnsGkL5y4foKbvqkt2XiXhxi2YTQIyibnLsify9CNrVTwXpu-G1AAAETdFtM1dINglm64Q1Z2uAg65YC9VpJgFuDd7zF2ngjl0xojfJM1RPe0zesmlCyTrg18a0 gvRR1XpqdWGMWfAA=-e

http://www.taggiftflash.com/oW5m0FgqPPpsVQkCxQ1ZZd5mO2pyaw8CC2vx7GC0q coD9AwisIElduUkfaaZb3cP66nPfV4Go3azQjS0oY5p6pQpabXnCuvYZ0tgg6elgCCwEB_r03WzEJaneRrhyoUajcm9lrFGQhuA1jV w xpmOs5FTLqpv_M_VocgixHkmWSRQewlIJqKrM98_U_zTzC85pNeNKSPpmSk3yxUz07pyOIRcdQg==-G1AAAETdFtM1dINglm64Q1Z2uAg65YC9VpJgFuDd7zF2ngjl0xojfJM1RPe0zesmlCyTrg18a0 gvRR1XpqdWGMWfAA=

http://www.giftbundlesfactory.com/BGWmlVTNgqaQNKJN6ZvhXGWukEOQfb0DQq_hwO1Mu8tzVJwnMyoXMmPLQ8gPs2RmsfRe78yD34UGnKJsr4oU Wd6DRvZdWkNzaIITM5_THBt5QJAes pDTV9S70Fi9CPwAx0Tng8ZRmVPxtRNp8UxVxtcRHkNEisfC0CYtiVJvayLfAdT9nV8TvDs4_A7dqJnHJkJ27LkO34RGsbA0VGp933NLyipg==-G1AAAETdFtM1dINglm64Q1Z2uAg65YC9VpJgFuDd7zF2ngjl0xojfJM1RPe0zesmlCyTrg18a0 gvRR1XpqdWGMWfAA=

http://www.taggiftflash.com/yCztBcEWGMEDqZa1Vi HBVMXecOUuYWa9GRDWOjYsgjMU_9wMbFgINpm2fwagpuOlbzP7Jh9xahER6EUosIb8k kK2A2rGV6Z3scCNgvPnXrvQKl_ e5bu1B9pDYb2U5llp1I5Jf13yiuTrBXEfZLlIXYpDe2E7ZV9XLE0BxUXXg61xj2jr7dK5B8XN9tGKt0U 2TPubEzZbbn7gL6SVsT9_wMB7E6xI9CrCqVGTLao3RXgoPjidIAv22X5HyHn9vgdIxExOJ6r9m0TbxaTh3uUAY0j OCOn6GG1OQQuxhw76H9ynYPPDlqpqOJOi7qxc_OgsRjJN9vS3HtroDNnhg4M7mXxduUnp5IOP8tLCrcGASGVbytiT74hXGGEvC6qk47bC6nDSmyauoKp1oqxL8NHEpjASoVR6qtCnxhDX2ijhJQOC_6Fmhz8H7kNUFQxzWq0Rkx3-G1AAAETdFtM1dINglm64Q1Z2uAg65YC9VpJgFuDd7zF2ngjl0xojfJM1RPe0zesmlCyTrg18a0 gvRR1XpqdWGMWfAA=-e

Remove freeburningstudio.exe - Powered by Reason Core Security