freewifihotspot.exe

Damunikut

Huaxinwantong Beijing Technology Ltd

The application freewifihotspot.exe, “Damunikut Setup ” by Huaxinwantong Beijing Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.taggiftflash.com and multiple other hosts.
Publisher:
Huaxinwantong Beijing Technology Ltd  (signed and verified)

Product:
Damunikut

Description:
Damunikut Setup

Version:
2.8.3.7

MD5:
9fffa3089dc1d6951f97d67ddf9e25c3

SHA-1:
28a49ac0e8dd1edd1880d9d3c04b37e843a88f1c

SHA-256:
bcf7b0a1cdfd91371729fc3c83308498326cc19267c3e1f6dcc78440d2fe556d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/6/2024 1:51:22 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Huaxinwa.Installer.Meta (M)
16.6.20.13

File size:
915.6 KB (937,544 bytes)

Product version:
5.6.4

Copyright:
Installer

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\freewifihotspot.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/23/2016 9:00:00 PM

Valid to:
3/24/2017 8:59:59 PM

Subject:
CN=Huaxinwantong Beijing Technology Ltd, O=Huaxinwantong Beijing Technology Ltd, STREET="Dong Balizhuang 54, Building 2", L=BeiJing, S=BeiJing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C31292C6449E082B3FBF99E310243E2E

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:XyiFYkHhfdqyupoYSSvZzXk96X5EifGIWggZrIy:X7ekHOyunZnJEipE8y

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file freewifihotspot.exe has been seen being distributed by the following 50 URLs.

http://www.taggiftflash.com/DzsbutNstVMIDy8ok8P3DcoT70TmtPjcDlyDZY2LDQcm5EHRgIUbnUoJ0 gcxIA0q7cT58hL5J6n7XScef__eJQAHjl6XlUmeMw7ZWje5I5vzUmtwYM_grAZ4gBILcpBo2rOYZAvy5fbFoIVEI1N_VrFNoLvS8EMIwhalLHOfdxsElnI4TcM_gsEGDmqjFuHVbeeTSvwvT8cf1n3yXAR8V27Rf2DnSkMbN3XKacQJ4rkmL2NM27s4mzhnqlwN50XLWCIBKv8JUh_KsuTVzKY8ZJgN_T1purgYtV2viOtT1nLopRpnJxNmIToJ049y3O9U 4o6NGCOJHEchMETIEGMDgzGlXfYSnTJSVQVQHJa0riFf84kYOet4qv7GN4q oFC8dUBn4hmg3warjasL4ho7dhnQ1UaxPaFmPi7cW2Ij4AIOA2ZFZzjPvftzw1j3UTMSVehbH0 TGlJLSSxr2Ep41pwiEvrg==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/QMOlcSborMoELg__tp0yyGswsQG8mkOu5Pj8YMp2IlmvKltryCYZdPp6eOiCi UWM AcQvjaK0k7ToGZIK58CwbS2c Axaqxoye_UbJundrEEQoAg1NYAqLWOpwSEHnmX2W1iAi9i_rJuu_yVwT23qqQRKBeKznCveKPRcvgBZspM FfnKDh0qqwh8YTqxje_9TFqNGOoexBVQzGYf9cADhsCQDhuzJRCXbqSi3OkZqJSxxPT_nu5C1LCKo7mNCiPIVpcpWKssrao95Nh30ND2E2dgob8MAEqslaZkd37PMPoTNm54auqcLKuapzJIgb7dT0Z9UgO5jgsYf25zgkzpiI0v7o3x6UWW0tNEPe8oiRNmivARSl93Ejb5PVQJBq4HGTkKd_pVe_gtHeVCgU9 gJ5b7J0ZHPCXOR2 YmVgB hhLVg_Rpp43K3fOOleRoirdcootzNdldFZu9nnQnjBdyNMGW0Q==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/GC2IIxdxQDhpIrYx4A6OeMxrTIXk8Ok4m3jyP7Ov4ExnJqEtm505vB1lqlboGciONSP1sTSJSKJM6gm_F3e_p8RbUYQ9rS1_5pM 2EU_QzoonKopf8QR4D Y_O5gH9z48ycXG9aVQTc5iSMr7atuP6n2g6rw8qten 7Uu5XO3xK2jKwwTMvORyjWn6FBddPDpAft Q4bvM9buJ8Y6MjUh_ksbFnF_C5bzDhqqALWXS4mjAwcnvX9ZGwsR95xfMq4vZ6wprkpUNBED0VIRhYl0ulz89i8MUAIK4ZM9aliRqEY4wau_ sAt2CItZwWpX56lmp1YWhaBiRqI0lqkSXpDiRXSK31P3dJmz1vCf9vJqFWPJ keMEBdnad1y9diELoZZvQ3qA S2PiK32xpblvGGPPxxYOUeEr141yDpqQFAmcOjYfHrquDX7_np5ZWkI4k0V1w68IXpUpgSNpehOEyhLVQzqOAw==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/DBd_ bXxceGK3xvlTm7yqmGI3eLI4lhDH4HVZuKzo30t1_9scd6kQktTgdeeg3z1dLF5FI9QiQ68Xuy2CSwX0n2c4X_GYxN5uEeKNPZf4JDkNqPtJwRFabZqP9_SPxhWeGkcRoxIzEhz29lKLvtcyYJJv50i232AI5Z7jtKTlqio QrctGWvYjYzrNqi8LwFeiJidcO7Wy1WjXEEdGUdXTIe7WcPiZDhabTq_sEskDpP1lOkbO2ho8cmUukL O_2KdYu00M68hzhgsttpyZqKA4TenPvCR HVaq5k3SaWTw9JTI9FeVyom95BvXg2qm3 mAscXmoKFrtQ8Csj8EbwoKGQLMgw_WpGIVKJMwkq6neNoCm4LJIW8zwjZP QRQ8sTYLbAOAn5I19Hp8OqBz0pl9zqZnNpe9nuv6ZqRl3ZoRC5PMbOCE1zomKc9jhj7BY94Isi3mRwS ZdQbbV7DsjHCCW1yXw==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/CKBjQJMGcdxPr1tF1CsBNuT4PtXB1pzozx3i_oGF2N1_RlLcofvvpimP9cbvPdZ433DzpvHHw8gKAoV7o5GioOt8WFrX7BOEfyenisbaEgPN9nXAoDCIdhxpBiIPKEU8k5xvcFIzAfpVijSLP6IFDTZqSXmp6Uvb GBjdf5vqursokwKTanG GnVlx1SbvgvYIpKNEj2SFubqJw89uHHQ3GX96uQdAz srfSFLOKbdunrJHe lzB97elBanlCVSGwKt6n7bmAavJSAf_wVqtKtDFfwIIQn4mcHsd1purAK8 laphH e5ETBNI5rb lwu eg3ghEsywgIBfdt5 HihxgnzthJJSiIqT TcomBzm4dC6Cy7fptggL9ADDdgAm8d3lwCJ 8ItCZIOMUwc0dx0bW_dIwipku2c1p4oF_yCtMokzXeIU85cHJ5tEucac37fHWwe5oqPlBmVyGnrUHF9EgzP5X7Q==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/0WfBl WBBrAPTOHzgW_JQw6bELEMaVS563ZFAkR9bRBaUlrFYAn_cM3ZOoqQ nfnjRJN7G Kf9UnBKtaEk6553Ldaq2gTCzyDoyBasbELM2t J9EW485JeIjsUyDtiDBCrDR5iiCm rbrfnaPeSXpXhKC6yaLCrfI2Aa_28JYOiG4A61baSuBsMUbO5ZRwGhE0mPQGE_bYAXuNSuHoIuzd0KX_S_oWq9TV1MK9_NTBubiLkZW2sjUi4pnoWsE_liR8kZXwSatfR4X95zXRiihH6Og_JLE3Q3KzMwJ0OwolOpqPywTXgkRXHnsjWW5fE puwWjRWNeGTAcvWr6GdI986KKqb7w2MPlta1rPSF_xqJBv_A7hdk7TIRu7kpdJBgEZBGxzEfhjhhxKZonLUCHzvIdvqI3250o6MeCWIWL4kzU5IDoIHhF7MtPu2JVxzzvgGiYlpo5Er77PRz9f6YeA_ohug ww==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/fv3MJJoVOT7tncjdT6T3rJx5az9W1oGmyj MU_m1HqbK8Wkb2D6K opZC5HYwPUIwJP_4zR4Lz4wgWSEBv6IXDqFt3Zs2vD5uklRM7ugsGV6L2dbG5lNJ7871vnudpSkUZSjounCC5HX95TduL0JRlnWyYOX Tc8 1GEnreuhScNjG8OuPojwxrNo7aaW7uAWfL3Lc8OhabeyZLYfI5bEqxHC1ladqe hvF_1KXT_Qgkz7gw5Jlmojwg8BoTecWLTq7KpgWItyM1SJcfSebc9vOZQ 0h4FJUptaEmMdf3zvzm9gdF9KSZUa 143UtIjwULCiJ_eg_eeLAKgvs8zq2IW4ih7Ll7rsIZRgZShwbIn w4htHIxQk BC8SA6Sp9jBxNuTyxe8dhsBbqxEQI6mXuK6GcdR Zp_XZMOBmDmsjYqUlxO3dl1AF8h4npclzJjUvxoIST0aHsZ97XGPutEzPR3xaHCw==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/6rvWn3y1Q1MsqbuzHsiNuqKszBIyc1VZK4 uMEZmpH8ehn5O8aVpER OKjXOADihhsGSgwgmpYovHiJPzkv05Scu9DO6t0qM3QAd8D7qdXuNhgjOtFznFRm4PYgrwuGedF0VZ5YO6P4LiUJHEASp47D16jLfdXbNuBxHhvc7bEHKG7 iWF_MmkQwC3P2PGcT7ht5yJwXYYS7HVxfCRGAegaTMnEXyU QmKg1Axv VAnYJVU1xcDxtJRptzVHeah5OwWxk3FD1YdHjqauXBf9hpgewPC3_LDGG2V6luguHTnD50YWs_WI 6x7ML Zd0Kr8pxs1Q_SrQCRI4Pa0gjKzGppsJrtXXuSRIYiJadfTkbvwUe98b1ez1quy8CXQuiJnEZ_QydpPMKs2qD09oGnlSq_ fgiV3 ttgeA9j6tLA4bzEnk55Gz90Qrowmswl WjWUCMdzQTgL43dLwXrvSrbpe0vVOtQ==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/jw8neqDyo mf8gFm1JA0J97vBEOxBDwZzv_B0o12HipKRScstHIyhFEqTfsN2L5htybVBCgIt4mDOFpQAYkCZVK17JId_G2ct7p9X77DR9MrUGV_gGGZYtndmgu_T0lnJZNWW1cGEzQzK8lsYJm4N0VO5xV6 3L4MczKFjNA_MAQ8kbJAwbWNudZlxOGfQgnGE7lUwxYoP5ne82JxL62u7o9MERA4qZj1fZ3YJQ61osVGiMY112XxBZgWuir9Qky4T0rCFYigos06nNgUSjk8w8iccRP3N3XndHY1wgQBUgINcuYR2fkk8czq23y8B3ldkB3URLpjqWKzqHHF7Z5P99WFhrK1GYLKPwJ4oJGXY93aFrg1NP5S5oeuF6E8T5Eev6TiGtg8YYLMgk4q4sg65BJq vWk0x may1bpGX4jjmyE_o4VzHTkhs3MLkmxSormMw53U1QMFA4vtr72YKCLk yVbFEw==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/MTS_bEkM3VBdMzRgjHZy2D6 pw1Qs_DE5B3fMm53 aYS7MDms8LGlRbBuzq_gyEB_tCnixsJHiRm17m7oBDFfP8FeSmCV9vCTP aF65IDcXK QdRYr8YJR0Z3QN2fM9L9_ q6I 0jhN vYFKDrjcMFdBZbD54tKZBiyjDNscZybpunS7M2 msLpO4DbKEYJ27zeX3ro4hKMpB6XGWpNRdBOXCWSr9By8QS2cmIQPPl yeiwRos5NSQJmGxcYftT1gYCIEj5SVchRTyveDc97wKHx2fIh8X TYqgfXCXhZpKNdJExA8NUcqcy0MswkAkYKMExSEbWBPs8HFniAodeODxvuiLR71WFkF5XsLHSS1RfVLkuCJlu8OP2BVO_K2O9Y57jOwH1UnRmbQRJGGdbuz8tT xAhyeYJqUgSLtsnQ6zusTRILm9HRXsR56FsLCq4uj9szgbmDi1F_oua9gmiVGXCWam4Q==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/TPaZM5ViaiE3IY4GIyGIMg2naobL8NDD0IHLPADJQJ17kUwX16ntknNlvb2yzcseF_GB9sr_Pm6I PR4lL a3Ck WUfsxlX8hhSnsOm6g0oJANpDrGdaULhUU8TvxRQfw9eLyQ4xT9BI_amaHoV WqG50_pcXoIcTnRQVhFMNy0PQbZhEA3VnWCmGBouuO9eRHKfJqXgYy9DR05HK 74AuS S5saUmrNA0qt5n2VgxzVNjGAORqEj P7jTuPHchIGeIxL7asPVNnlmLmSWDIgMSmb6mNJNM1D5yNxHJt52LhUCjOujzdl_fcUZGTn4AcB7KfoLoBVbaohl4cul2k0EP53_1K1rV8XRtWftILcrz3LpuyFN7x PkDhIgwG_EN1mQRS7r92tFQWg7HpEHSuJ1RpyojBWX1R_r 1AyFdOErFxxP1V5S5LVfgmPLMlmVrQMMgOB bw0Tq79_ktzitDRyxA5A==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/ajTySbdZ0 Ph4bwu3xi8A5XnBiD 1QjZplhMy75c3zSVpPlgXiJN2VRfuH9YEh6bcgw0dpjgQkp 4_o7aZJuYS4cX27ydy0KeGdHt4YCqJj_k0977JS83fat7yCtyK0e0fn8tRCAm8enW9c6kIOAL6v26SwpHVa1o_zWZNUwUSZtutT5jGtRvxtGV4EeKlUOsGI7s5XijhMpJEUiCKCqNU_lxFmEN7M4xCYhTlMqDfdSUp6Z3nUv4N9FyKOcjktgecyCdwsS8HoeCf9Z5zZVvV_z_OFWPVknEJbXojLw5ZZbQ229pKfGwNAbaQWzCny9tYJabmwVyu6LO82jDUGPyzqFpGsXiijmsGevl5kSDTEsrE7y5iejMbN1JNKIMxkGyBm0JckdScAkMFgM9ONLzIvgk8LwKhNhCqwlDnq2iyHzP6JNqOWRRhRkFPfCJ0QNs EuO8LrkjiKpFRgsSsKuaPRMU0LKQ==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/laVK6GOJ0q2yQeNr0OzaQtxa1srppYkQzio1v0XkkpNw4D0KkmubMLA9TpPd_GoiyTPxn7QufaQ2tzA AFJTZiIGuw3SUa7w6LDHsRglyoAwkS0Dv2GEliMFzZT48IymXUX6xxaJ89lwxziph6IzxMVihVJ9QLcZMaNxV66RC6O8Wm1 uleMq029FzMrfHSfoqk6CxGIjYObIojniU4jUQYiV0eK2hlTdFkDxXyX5n0fvgPcifallLFZlnFD_pdyUuEqnMqS YzYZnkCL9dn45Kj3O1gbtpwJUrdtdGAKHwS8J2DwHBOzmEl7Kf6sIqIbG0Khrtr3HhgAsrGfW3UNxTltr2bqHOwxI4fHHDHVs1Qozy9KL7iL gTr0uD2cJLKHPKLTjAXVGRklWDCqjWmiO71kilyOTCsXwcwoHwTVpZMhK_33eQgBwA1ugtf2EP18Yy9mIykXvuNhf7RR4hFK4NbQ12Fg==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

http://www.taggiftflash.com/KxV_ehfvJJUR7zGX10lp97 7XwH 1XWnGq771bgH8T8_AeX5UlfKRKwhFlQ2gubceBTyjWcvYOPSQ_hxyTOaEKN7y0 bSuPlQ5teV _Vkfl7w0UD9kW8p Ua2KpV C8BNgwZwLxhhI8vgy6zqGgfzmg7WQrBPlOjgdfijMdoXkrIEkguq6vWuFMJGituXKrfCBPWLwyAQRfOvawjDiZmp9QCDWUEfgV6VCbEGXfi_ O41Pl7JmUYj1V8i5xUJtDhJSEFlDJpV6vURt59CpXOk r7Qpm092w5_OLbaS7tHHYRv8Oh8oa_brUw2o OSfGx2LaX7hvGcw9UHjl4iNefJoJoirqav_R9QuEefsshG9 DbLajmwovADRR2fPi3vJKDScCBJGHlSA5MEekBk8yfxjnBsncORRHi0VhH6YckpYmUI41YsxVH_e0O8 xK1FLU7QkDdlyJnOC8qkzF534mDofBC0DxA==-G1UAAMTaOU7Psn3MBqNBJ1fyQuGUA_ZWkbQ1D4AOB4 h57EUB70xxndYbLJ2An7JY6N0u2eJTjlw MfrBjKVgdoSk8MH

Latest 30 of 152 download URLs

Remove freewifihotspot.exe - Powered by Reason Core Security