freetrimmp3.exe

Nopumalifo

Huaxinwantong Beijing Technology Ltd

The application freetrimmp3.exe, “Nopumalifo Setup ” by Huaxinwantong Beijing Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.giftbundlesfactory.com and multiple other hosts.
Publisher:
Purek   (signed by Huaxinwantong Beijing Technology Ltd)

Product:
Nopumalifo

Description:
Nopumalifo Setup

Version:
1.4.2.6

MD5:
042c6ef1d92c0e2e0a0607b5955f634f

SHA-1:
bb3d57045a5716318887252da77097271fdc7a93

SHA-256:
ba30b0fff605fdea64ded4f0f963c073f01689595073453536fd48f6a14f49a4

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/6/2024 2:09:39 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Huaxinwa.Installer.Meta (M)
16.6.30.12

File size:
906.5 KB (928,248 bytes)

Product version:
2.0.9

Copyright:
Fast Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/24/2016 2:00:00 AM

Valid to:
3/25/2017 1:59:59 AM

Subject:
CN=Huaxinwantong Beijing Technology Ltd, O=Huaxinwantong Beijing Technology Ltd, STREET="Dong Balizhuang 54, Building 2", L=BeiJing, S=BeiJing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C31292C6449E082B3FBF99E310243E2E

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:eti0NiGXIAR5v3nWi+dZKEUQq3p9UdRC+8Y4:eEcbXV/t+dZKEVq5b+81

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9345

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file freetrimmp3.exe has been seen being distributed by the following 19 URLs.

http://www.giftbundlesfactory.com/T8nOg w1dHUuCb3teilmHN3Ysr7dmiXLM4sTkcikfWrVHCZ1rZ4upO_mJ1cCuS6ZGbUlcYhv2bxk6MTygQFRYYFNTuJJnOI9DTO_J02mPvqTNMPV1NAlcTwv2i_QKmODQHM7EPXv5i_M6S1pKyVJB7xZofxbGUsUvJODdcfx7yAPbEl7hQ7Ac03IW_QjIAasoXETxgDgEvzJtO6QpFKX2SdOy1Lrug0MjBF0B_Y4DKfhTOgF_1 Ivy88ZfpyHNy1FpDfmZH5PLkkH2DAD2YwR7UoeJ03F64Q1LPDepVkS9p9hQhTElRqCJNl1jAJ UFXyPqS8FG2aDOY9GoOuUJ9E06On4lo_BAgfQpCfQkllgC1MiGtzWtiAfbN_kUMDXSlNWHA6jfaxW56RUoTsBaQgsHwcXkUGDaBGjr5njYXQTR8YbbetjAE2LwbDp28KpCBTJoVSvlb-G0sAAETdFtsfHrpgEATtBlkYeJVbBIccsH8roawtQAg8hofjX4pCb0z5NuvZnJnAmUn8msaFRz6aAuhBL9VGboIP-e

http://www.taggiftflash.com/8YlQxKt5L SxjK8q_ZI7UwEp78TJXguC9kjwBA0qvSSaAwnZcU50FPcbU2AE6oHPA3VjhvoT4kdQL1YMR8pQSH3h uGsyRjd_3l MH66y4wxCYaGsnadVe1P2nL6fI22Jx xpeDfykDbneG7aQAUJT3se2Qi1IR9XKQRBINlWEUsC q7PvUfZkzLxwAiuBS8ZRAQXtSGVDrk9t_zGXqLZN7yZi qT53UjTbJUWqAh20n7MFfUuyJqUgA2ueIXAcg6MTi5s4TwrRkau8zX0 GERyY0Oifvs3urzZnjHgQHVEuQGR2JQiNhOSNaOYEQ4m6C99I4vvE7UtAMMgtyDvGqdmi5FDZTfOJBYv96i8Cn9xQEq0HHL43NyB2pOHib3iuZ8fF0e6xBH7dtxMppQ4KI1MU8U0uG7oyaEuDaNsb6autkoq8iWmCnRyzmXoyMRQkwCIhhkeG-G0sAAETdFtsfHrpgEATtBlkYeJVbBIccsH8roawtQAg8hofjX4pCb0z5NuvZnJnAmUn8msaFRz6aAuhBL9VGboIP-e

http://www.funtourbundle.com/zAS1rA0dlZCvP_ZqIpGKQr8sT5HFEsbkrav_OoYP1cun5lDnK97II16YCxjGKnwDAl9eMW1E1rlDC SMGJxYDOaCM0sXvOdWbj CFj6fW0LmbcCWGH6Q88DCr19JifAdIajRBifKe2p4qrGarSZ rPx15 YUFtSnuR8Tevy2ZkAmvn cVCkRFigNyKXO4o_37e9mNoTp11ITn5 8b0ATbnUowaYXxII1munCMMbWv3sgSat5UXw6I3sC8xGrY8x1IGFYK85im upKCSzRGjHIdAAIyFz8wFp_rWdrai_qKYI2SLtOtaQbQ0F507F3q5db8sa9whROcp05YDt62w62ZHUFno9sH6DZndTfL84vHgukcDCnOB77ijES0f1KXvhUxnUWFtF47sw1ST1lEyMlv81JSrb83XBrFkhQZapczqM KOfapwATIBa3sxf7j_4X1Ah9zxX-G0sAAETdFtsfHrpgEATtBlkYeJVbBIccsH8roawtQAg8hofjX4pCb0z5NuvZnJnAmUn8msaFRz6aAuhBL9VGboIP-e

http://www.funtourbundle.com/EDXjxv2YC0Ydxbe3zPbtPli514kWBWeV_Qs5wKJZ7uBap0uJD3La W2YCye0ogAixk6E2TNdfwd7wTN6B9CEr0VjhwRlidKUXpFUnEaPKlNaAGeikVu2oV3VfCd_n3oMHy1v51MfdUxy13AIscJFl6zOQgv7ZeGV_CtEunC33SBVVIBvwxBQKmZakHyYtszgsL79Z4w4fXf7q04OafL3ZP2bFlKjlx93l3IayKzrKaO19V8Ax3EqHYHXnP1Nbqt2I3QVwX0GMxEp sTrmkO5nfioJ8sd1axX5g9L_0dfKcczdJAI2iONZM8laXT5SqXb qL3ZGL59oLRHiprzV_CPqh5QnCeYPSJjWVr_Il723Uxs1EhKfWdNQwmExnFUCUFks3zM1sKvDPGB7osb0PCu3ZgTa20uyi7PFFjiZoxmwgmjt8xI7pzXPz6gWW8R tISM9MuuPB-G0sAAETdFtsfHrpgEATtBlkYeJVbBIccsH8roawtQAg8hofjX4pCb0z5NuvZnJnAmUn8msaFRz6aAuhBL9VGboIP-e

http://www.funtourbundle.com/lnHcpSnxiZycgLaybiavEGD6n24YQrkIfDV_O0ogM81tsRFCtA4mECeCIA0UEiCqQStmt5WjYeLnoT2t5Q XV8D6DrYE3Tp2kWtxxJyw9gF5bPDigZ5fw_2UAWLDEsmw3MbliqUMqpkDvIua7pn8G68Yw7XWI3OIdAYWKnGbRb04t8VW9DboCXPB3FNJss8Yj_03cmha15gefT wBE48nHnp9xlIpuDWQxHNkwGheW96MMaV7OArbsf15Zs9oJr1T5dV2IE1Lygag3D8VbxWen 5EWLyoNfLpnro15XGXwNrgbRFTkzKmsOFFG8qVpIJh3q 84267FOewYTLm4Pq12c ZMgPlBxBQcFw9X4hYVOWreHIqyj59HzJftxQ4X0CZsJ7EhqMLzYO6H frAqhiv9sNG1kY2E6Mxdbzgj9EPxc eVLOx5dDI P7Hi43m8Ox6AlDwna-G0sAAETdFtsfHrpgEATtBlkYeJVbBIccsH8roawtQAg8hofjX4pCb0z5NuvZnJnAmUn8msaFRz6aAuhBL9VGboIP-e

Remove freetrimmp3.exe - Powered by Reason Core Security