freevideotoaudioconverter.exe

Nopumalifo

Huaxinwantong Beijing Technology Ltd

The application freevideotoaudioconverter.exe, “Nopumalifo Setup ” by Huaxinwantong Beijing Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.taggiftflash.com and multiple other hosts.
Publisher:
Purek   (signed by Huaxinwantong Beijing Technology Ltd)

Product:
Nopumalifo

Description:
Nopumalifo Setup

Version:
1.4.2.6

MD5:
fdba47b36e7f25aa0ce360c568b92cbf

SHA-1:
f9907927a615097e159f268d5061b836a0455daf

SHA-256:
59861ee1bbc5672e981b8a3adb19542608e60cdf85995e59bac77f07889bb222

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/28/2024 1:23:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Huaxinwa.Installer.Meta (M)
16.6.30.13

File size:
906.5 KB (928,248 bytes)

Product version:
2.0.9

Copyright:
Fast Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/23/2016 5:00:00 PM

Valid to:
3/24/2017 4:59:59 PM

Subject:
CN=Huaxinwantong Beijing Technology Ltd, O=Huaxinwantong Beijing Technology Ltd, STREET="Dong Balizhuang 54, Building 2", L=BeiJing, S=BeiJing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C31292C6449E082B3FBF99E310243E2E

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:qti0NiGXIAR5v3nWi+dZKEUQq3p9UdRC+8Y4:qEcbXV/t+dZKEVq5b+81

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9345

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file freevideotoaudioconverter.exe has been seen being distributed by the following 30 URLs.

http://www.taggiftflash.com/B55rfESTsp4HtrTSnAcu0wAedvAK4pYsuiE9gSc1e6l8gdFFqYDTqTBMZRaeEHznHKo9Q5DzldqWmvh_V1wgaSDDcs Ui2aulKwkFNHUM0Pa09aeMWHR8luz N0YUAr93KtMHCdEkepIYk302gv8zvbtA6m2ERKeDdPr8zx vo2dudNIoRDnE2QPY5PJLOLp0ReeVncmwTllaZ3xFgbZpFtN_4Vhxg==-G18AAAQibzE9ISs2makCF34zvz2BUw7YWyVd7NuFz5ynrAmNGcL7dY0xvs3Wjs5OkEeqjaQnc7q5 h6zQ9eFNUv4T eXh49SAx8=

http://www.funtourbundle.com/2Yy7_pjFcjPgZsmLll56nGMcTM3tfKpIdp2MpcU8UU4Q9LIFvsM_z4xoct ccAd76K9WXOs4RDLjj7IYJoD360dwx3LMXhwpAI44FLNC1AdhBAuhiF3m7PHr994NqJl4Y0vqDkQBNXIBaazWzXw A7mXM_g3V4pDJoARjUNEAWi7v4I6NprmJ5zoYzsfHMTV98U7FQ1zpPEEtwfTjTgj1np5jBo3Tg==-G18AAAQibzE9ISs2makCF34zvz2BUw7YWyVd7NuFz5ynrAmNGcL7dY0xvs3Wjs5OkEeqjaQnc7q5 h6zQ9eFNUv4T eXh49SAx8=

http://www.factorycapitalstock.com/unsTFh_aIjrCiRWw6wo4Wpddvw6fD9MOZLRIlNWR8KqSjRe6V9cHCgBwql2eZKTM5Gj_O2POahMX9RN99fShENT1wcJ4_RAAV3unwSq5esNwEHKSiALLuzhEotSrfpLd_M9TF_iTSSzjsRRr esWqfQpFP8QJHwgeQkcOvtc7z_wGAooX Lq7YPQb9hA6Xp0fRsYzhYEP26fxawPx8prvUW3JBgkzg==-G18AAAQibzE9ISs2makCF34zvz2BUw7YWyVd7NuFz5ynrAmNGcL7dY0xvs3Wjs5OkEeqjaQnc7q5 h6zQ9eFNUv4T eXh49SAx8=

http://www.taggiftflash.com/M4URy85dHPgw8k1CUCAkvhI4fnejBYr_PPvhuK6bDcWAiv7TD3qGNUdHsBRq7JEvZBZc77cRAGbflenKZlTBXHIg_X84wKBN_5K49lhVUMY9WoCwPLWakVIox1Zg0wCiMRuNWqdXXxpu6mJSTGWSRC_Hl6sjCqdtw9EDpik9NvxorLAmiYjBljK76Yri7lnBpa9idGmUBuVGwGdpq2mYrf_RAW T8Q==-G18AAAQibzE9ISs2makCF34zvz2BUw7YWyVd7NuFz5ynrAmNGcL7dY0xvs3Wjs5OkEeqjaQnc7q5 h6zQ9eFNUv4T eXh49SAx8=

http://www.giftbundlesfactory.com/aO1b6H01SNa2WB0q f2TQBHfjXhfV u3foFYO8nwhztiL5coyopfK P_wpvxM3FH_l8zxlMDb57sDvdDPH_aQ3VFvShDvpdcg5eJfObEc3omxUiIIInpHkY2olXMAt7baX2G1qpq_1pKD1sAzdcmP1tbmn1w0YL8XaMZUKJmwk8s2ejLPCd8Um1RXnP4IudfE33znDu_u3AGqPgYQl4v4FtfQ0Uq9A==-G18AAAQibzE9ISs2makCF34zvz2BUw7YWyVd7NuFz5ynrAmNGcL7dY0xvs3Wjs5OkEeqjaQnc7q5 h6zQ9eFNUv4T eXh49SAx8=

http://www.factorycapitalstock.com/ssSkGZip3AHXY7Ajhwu9F30euFRxBuzCj GSfqNhFibAAvtkRTO4Eu6ndO5xD7PeBOQKBKBt5fX_5OyBGbBOnPJs11rFvgWClFv6ci8yuMwLnl1apHI xmWp0K2Hj4EB821J2NsTeQYcMaZPLxSawAtGdIWFT7bSFEYTqQBd53uY5rXlN V1LkURlOEGI6Yf88d2bj9ON6wGNtV11xWXDO2UBMOd_g==-G18AAAQibzE9ISs2makCF34zvz2BUw7YWyVd7NuFz5ynrAmNGcL7dY0xvs3Wjs5OkEeqjaQnc7q5 h6zQ9eFNUv4T eXh49SAx8=

http://www.taggiftflash.com/zKn_Jn6bqZA iVleLXioH7J6z3X5KVlwuloRd6nm_TR nhNonkj Iuo9ZmISYPHq0wtSQhU_a_V GbbTbmgtJ6mVN_ydVanbaCzLMyV K zzYiApw C4vwNb7MmsgEx_GF5nTEz643R5yIhk20deQm wa7OrypUraGFl7A8I9kEuLV22T5_jsW EsHxyLgPJzQtmrp4PXWLa5nIMtYN0Nj3olZ9OQ==-G18AAAQibzE9ISs2makCF34zvz2BUw7YWyVd7NuFz5ynrAmNGcL7dY0xvs3Wjs5OkEeqjaQnc7q5 h6zQ9eFNUv4T eXh49SAx8=

http://www.funtourbundle.com/e7Zi_HNXLF8x8f01P_Ro0nAifN0kNRrYt84Ubb9VHENRSQ8b2 Y5xdMZnCkrPId1PLBHo4xAhIUWJsjX3h4maYzhdAt6Z0QU_nCfWy_m5PI9KRQ2 vwsFL_qohFpnB0fa NCsqvPL6ngjE6VavpcbulVUa2huMJp0FkKuzKhp3u5Wzln3orgF6azKM3IYH4bn7Ei1YtuRGXs0 F04L7oKxmzIwbauw==-G18AAAQibzE9ISs2makCF34zvz2BUw7YWyVd7NuFz5ynrAmNGcL7dY0xvs3Wjs5OkEeqjaQnc7q5 h6zQ9eFNUv4T eXh49SAx8=

Latest 30 of 30 download URLs

Remove freevideotoaudioconverter.exe - Powered by Reason Core Security