freevideoeditor.exe

Daho

Digital Wave Ltd

The application freevideoeditor.exe, “Daho Setup ” by Digital Wave has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.heartvaultdl.com and multiple other hosts.
Publisher:
Nakonimo   (signed by Digital Wave Ltd)

Product:
Daho

Description:
Daho Setup

MD5:
0dfda9332aa695c60e60799e009d4015

SHA-1:
24a88be13eae2611d5b505b97147b24e9e8b132b

SHA-256:
adfa04958150764f31ad135d07bbc8d04e5d13f9689574edb92a8755cf3ffadf

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/15/2024 11:18:02 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.DigitalWave.Bundler.Installer.Meta (L)
16.4.6.16

File size:
1013.2 KB (1,037,560 bytes)

Product version:
5.7

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\freevideoeditor.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/23/2014 8:00:00 AM

Valid to:
12/23/2017 7:59:59 AM

Subject:
CN=Digital Wave Ltd, O=Digital Wave Ltd, L=London, S=London, C=GB

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
1825ED6422D189492317AAD87B5382C5

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:VquCERgQOyip4iD3w2pnTbdKxoI3g2pRsCrM1QJd:V7eyip3DtpnTRKGX2sgKE

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9081

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file freevideoeditor.exe has been seen being distributed by the following 17 URLs.

http://www.heartvaultdl.com/c?x=5CXiTLi3wWwPjW1UMTVgxLp0PCOeeU40WsZm5aPTGCw=&c=xm4BkbddoN5fCz0qsBJgrnZ4ycmclURxbDWhbEBj6v AiUugQL3EDxpnp6sgrROv6zjT8G0K4nYQ9E4GcIxu/CuAN NqZUqMQUiQGbntE oesIxdRwfCl hStI6ZzHv9&downloadAs=FreeVideoEditor.exe&fallback_url=http://off.dvdvideosoft.net/.../FreeVideoEditor.exe

http://www.heartvaultdl.com/c?x=Rru9gUSXDNhoU4WyT/IFs4e9Zum5XdOOV6O 0xR9n/A=&c=bXzGk3eHk4ob4OkSFVqPRS0lr3qpC3pXag5HiOhY ZhBb3YogzDV6e9UGzXQm9DubPuseVj9jhksLYUVzWsukkoMSWjf5 ui2B7ol/lIf4gASn3mclRxvTqQIL2CMqHu&downloadAs=FreeVideoEditor.exe&fallback_url=http://off.dvdvideosoft.net/.../FreeVideoEditor.exe

http://www.heartvaultdl.com/c?x=npQ nx8wnG5Ivm brZ/ji6iey6unLK7SlSe2iumSH4Q=&c=kMnL2V9KFEFk sho0ACGuTj0thFWCVW4MliHNWox4 IjdorKJPGdCTwwBRpLHst/NCFTPsk6/ wEHHpkGjWaawy5ZbL2R1K/csUqQfjVrSvftylB0aKL6uLCvgeSu9DM&downloadAs=FreeVideoEditor.exe&fallback_url=http://off.dvdvideosoft.net/.../FreeVideoEditor.exe

http://www.vaultsfactorycentral.com/c?x=9JhjrBMMa22UJquAIoQUO/y6mLboHrXRiyjWTyaNtB0=&c=5k QcNZsdrz3zSaAoC1qCPP12wPxeQmD51HGlJZa Dt1Dg/ATx2oLMrJsqPEU8KladcYCTl5Zl6AipEWBWGYH8b05q4Gaj 0p31mky1Lh6F ruSQKDle9j/rByeHF dq&downloadAs=FreeVideoEditor.exe&fallback_url=http://off.dvdvideosoft.net/.../FreeVideoEditor.exe

http://www.vaultsfactorycentral.com/c?x=YLun4eoGXnftDYWoVczGGTyF43JSbIXJoocupqBpyHw=&c=C3Nb042bdeOidtmAlWOk0e0ubUSpRqIQez62UZIxfQLGA4gPBI7Zry1W1Bz/RnOWL2niZtWKo5kMXTNxMP/3BILVSorZfBi/ 1y750Nq2HDQZ9/OmNMAiwQEXcmrLpPD&downloadAs=FreeVideoEditor.exe&fallback_url=http://off.dvdvideosoft.net/.../FreeVideoEditor.exe

Remove freevideoeditor.exe - Powered by Reason Core Security