freedvdtoavimp4wmvmpeg3gpflvconverter.exe

Nopumalifo

Huaxinwantong Beijing Technology Ltd

The application freedvdtoavimp4wmvmpeg3gpflvconverter.exe, “Nopumalifo Setup ” by Huaxinwantong Beijing Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.giftbundlesfactory.com and multiple other hosts.
Publisher:
Purek   (signed by Huaxinwantong Beijing Technology Ltd)

Product:
Nopumalifo

Description:
Nopumalifo Setup

Version:
1.4.2.6

MD5:
764f83a4d12bdc77c666fd867e08ca54

SHA-1:
eebf176e3e5dd3e9de512b769d30b9c790e00c44

SHA-256:
b947f17cd1e9a4ab9b38421d1a2f690f5814f34ae5664026d5501ae15a47034b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
2/25/2025 2:05:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Huaxinwa.Installer.Meta (M)
16.7.1.3

File size:
906.5 KB (928,248 bytes)

Product version:
2.0.9

Copyright:
Fast Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\freedvdtoavimp4wmvmpeg3gpflvconverter.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/23/2016 9:00:00 PM

Valid to:
3/24/2017 8:59:59 PM

Subject:
CN=Huaxinwantong Beijing Technology Ltd, O=Huaxinwantong Beijing Technology Ltd, STREET="Dong Balizhuang 54, Building 2", L=BeiJing, S=BeiJing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C31292C6449E082B3FBF99E310243E2E

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:iti0NiGXIAR5v3nWi+dZKEUQq3p9UdRC+8Y4:iEcbXV/t+dZKEVq5b+81

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file freedvdtoavimp4wmvmpeg3gpflvconverter.exe has been seen being distributed by the following 11 URLs.

http://www.giftbundlesfactory.com/f4RYANoicghsC_sI6bxi759qO_rTO1pR7oOKP57KAA4sggtjdWJL6JbeKzZ9K w_kwmp6LmBfYkfWRtK7_yX4JNXvEs77S5uvJR6J_FjLrMyZaexITGZlfUT0a0zOoiQHamg24o0TXWwT6MUtA8_ScmmDrdrUNzomzT05A266Mgct_sYSWMkBjTSE26qRANMn298RKE4 HwX9lzx80w_eyOO5ySMIQf1 abTgRVeIQdZykE6a6U=-G2wAAMRv548bA8OiIOXqSp3RoDcoUb7hQzMO2L KZHcDgoHQPIfPBUXav1xjyq_ZnD1HJuhKJiobM7Rz4RP86ngBL_4dJ5nYNhLikEziWOQD_ePh9lwVfgA=

http://www.taggiftflash.com/C3bxZKEAvWM2zwR9aHiqgTBNWmo8PR34ncRXXCG2dCVG4mHg66U9eimhaLXq6Fp5IvT2g1yG6hwbxh9Pys_vgjuD40GEiDBhByYr7IQ0N6HYKPk65GWCnwS3j5RghSi50J7gbeB4NAoqda7iQlYaQsJI9ZMnaL94r 3o 8ylzy3bjBBNfdSaLYz8wi2ZHfcWl8YuH57ezPtuaFPsIpabZc6I_PcYV R0XU_no88FVRioJPdrPtk=-G2wAAMRv548bA8OiIOXqSp3RoDcoUb7hQzMO2L KZHcDgoHQPIfPBUXav1xjyq_ZnD1HJuhKJiobM7Rz4RP86ngBL_4dJ5nYNhLikEziWOQD_ePh9lwVfgA=

http://www.funtourbundle.com/DXBIRb9_PRwkbEXKb8EhfYZ2lpESZmA3hqvdTtFJCkNnxkm8UntK rX3ETB6v8jiR1qwvIhWFCY1owGWJ_yFLEWG_8 nrCGasHzeqHufmnizPo_in8yz2zcU3cfodhuPffjfSJ2qIT1ut11VmjJuD16TjcUduOm0lJoud0aMUxVaxwKxk1FBL2WWHluHXQ5040uPwF1B0BZBU_rXXUM1nGYJr6pRMDJoiaVh4aB6mqkUHCUPPu0=-G2wAAMRv548bA8OiIOXqSp3RoDcoUb7hQzMO2L KZHcDgoHQPIfPBUXav1xjyq_ZnD1HJuhKJiobM7Rz4RP86ngBL_4dJ5nYNhLikEziWOQD_ePh9lwVfgA=

http://www.funtourbundle.com/C5lh3V_RXKYoZoo8C2UvmOZiqBUnIzLT7lHy 10KBPoRh2GpS92lusxWS4 FrRIgvyH7i1Wam44uK5spcAKQwtVcjBwfTUKDf_o7GklyxN6ktna0ALbte_C2uQUvqLuwdJnmxlK5pCeuiTtZzZ4oYc8uZPbPuCJvxLM_w65_zxVvU89OsqSwBwlJgrrcxytzePMr1P94pTgW0LkgVMtufAkElhuh5BYwE3fzjB6tikICDO 3Tz0=-G2wAAMRv548bA8OiIOXqSp3RoDcoUb7hQzMO2L KZHcDgoHQPIfPBUXav1xjyq_ZnD1HJuhKJiobM7Rz4RP86ngBL_4dJ5nYNhLikEziWOQD_ePh9lwVfgA=

http://www.taggiftflash.com/OnFRIHGjOBAMFcb0E8uDWKGRJL0d29O75xtlT5DJEsRIFBcqChQG9UiBEMCGzCxvDGZ_Ynoq_NQ7cl3w2mO_RcBGFaRKuavEo_hOtSiO hXseLKemF28MYghee68aKehgJG3Ogsw 4 LsmgFsl2tAVHYWqxFI1 DWW2FwyOakh7t Mo62_b6WuvC2jIs9cFMMpPj_iB5gRXB1pvHNDSlID2Li71SZAVH58Pik3MMQTTNEAXDD1I=-G2wAAMRv548bA8OiIOXqSp3RoDcoUb7hQzMO2L KZHcDgoHQPIfPBUXav1xjyq_ZnD1HJuhKJiobM7Rz4RP86ngBL_4dJ5nYNhLikEziWOQD_ePh9lwVfgA=

Remove freedvdtoavimp4wmvmpeg3gpflvconverter.exe - Powered by Reason Core Security