icreinstall_freesoundrecorder.exe

Nopumalifo

Huaxinwantong Beijing Technology Ltd

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_freesoundrecorder.exe, “Nopumalifo Setup ” by Huaxinwantong Beijing Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.taggiftflash.com and multiple other hosts. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Purek   (signed by Huaxinwantong Beijing Technology Ltd)

Product:
Nopumalifo

Description:
Nopumalifo Setup

Version:
1.4.2.6

MD5:
f95f5bf8d8ad9f3e6f07f3199eb470a9

SHA-1:
7e49c5ba36827f3925a3f26128bbe5dcc5feb7c4

SHA-256:
d4a44f3d46fb8ba066cb7f1514537b6d8d8e00ee171e732d8a9e31802cb4de65

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Utilizes the InstallCore download manager that may bundle various adware-type offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/28/2024 12:47:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.instalCore.Huaxinwa.Bundler.Meta (M)
16.6.30.12

File size:
906.5 KB (928,248 bytes)

Product version:
2.0.9

Copyright:
Fast Software

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_freesoundrecorder.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/24/2016 7:00:00 AM

Valid to:
3/25/2017 6:59:59 AM

Subject:
CN=Huaxinwantong Beijing Technology Ltd, O=Huaxinwantong Beijing Technology Ltd, STREET="Dong Balizhuang 54, Building 2", L=BeiJing, S=BeiJing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C31292C6449E082B3FBF99E310243E2E

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:eti0NiGXIAR5v3nWi+dZKEUQq3p9UdRC+8Y4:eEcbXV/t+dZKEVq5b+81

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file icreinstall_freesoundrecorder.exe has been seen being distributed by the following 24 URLs.

http://www.taggiftflash.com/GQlvYi2HhYzRBhtTRJS487KzT TTrssnGtx H6MIlRo87v0cPBy M3E52ATQ37fd0mPK57AiaSQNi9I78seOekXxpTTK7SCphQJCmnmUIE5Qp3m mQLSB7ZgOJMl4Dnm5KD5xcj3X2aAlTWQEvMRlBX9Vh_Dwg5Wij0NLNVWGQa1lxKE23tOy_gwWHcF36wjTPulprTYttoRUi42 xkCwgtsu9drLw==-G1cAAATibLFRmk1lXbALit kd8IhUKByQQY4sMBj HxLUPLGLL9i_3Y6E3HZttxxmyp8 VE7SA6x5Sl8AA==

http://www.factorycapitalstock.com/63tpklB5OluF8JzahBbvhgXsJN2SydzRBVhaV1GRngocyoBgsqJm V5ZDSJZVwTDILG7IjmKyJiq8AATo8Hhj9alv7ixddRGJgp2d m hq9BdDg5cyCNyZtvxiDWu EoD PAQQPRpKR4Jq73nU38dnmU6rb7wecK8iz9ZMqST5VWa5C_GA8 IC7n4bxuN3By3GRmY7k Vw ph3UMnK1yJRw6MMvAlqWMj_wUB wK8ZGCgTQahG0IRrq JZ4HDkKpHHJag6DUxG2oFg2E26sM0SBsiyDkeJ2vVYFEA_RKMYX3Xs_TZDR7FyFkYmphMBJxN7LtTyBQitxvM4hque8opbjQYe5cXRNSgwDMo7nbz Y150dSts_D7Yx1B8zhw6N5o1B5j7lgRIOAA9Gieb8BgosaQ4J2hX D4yYkIixzKjVrRPoXgLSlp2_WbQft_wP h1ExH3nyebX_pm9Jtkj1H0Q3Trzbsg==-G1cAAATibLFRmk1lXbALit kd8IhUKByQQY4sMBj HxLUPLGLL9i_3Y6E3HZttxxmyp8 VE7SA6x5Sl8AA==-e

http://www.taggiftflash.com/ktPdO5dyE2ENRINgLY 6hIJdTPNsrXmB8E wwu5Vw5Qln6DNvviFBgeZr1psQ2NVJp4 psioz_uGD0EY8GD_uHZSEnSjH_rUg94ud2ZHwLChNHIsRovqZTsV_dwVt3mjp6U5MSompot2QPjbuNQS 9m4HXcWqNZbYymQ06ZzsEjIf3JyINhxyDwbN1zMfP7aO0AoUVzizMLA4dAJ85gR0j81kSPXA==-G1cAAATibLFRmk1lXbALit kd8IhUKByQQY4sMBj HxLUPLGLL9i_3Y6E3HZttxxmyp8 VE7SA6x5Sl8AA==

http://www.taggiftflash.com/RtflhW3LhreT9wIDjazcFdWssuU_wzTmOGYCTDYUNwf5QR9vzbV8P3 1n942vCo_1jauuG33bJ2l3mH kYZa4UCScuceVBjX9WBkZ7F3C8gSjKIE3kWiin9YzwWxexeaLRxDqwR wdtQiDgvfu6SRNHhZ5PJJ2UcrU7i2OKlHblduYp8gLUDsV37dSl9tVRmidBWDfjn84QneOrzW0d6VTqhQT0vVtHv7R54CsiwjpU9daun3bbDbWe9wxhRtgRQfphMrTDFLl__1aky4dUjZn4zihbOpPxhq1JTQabHmDaOPvzhdf1tdNlivXLJpDfQs0JviR0e0rGwccYLDB6q4mahaS1rdMe9ri2H1cVqHsjiHkhUbh3WC6Mitw56IWKgCmc2wQ7EA2xrTkRI_TROe6WZPENUr3nEZaB5XS_VJxTZYpceIB9Y0n FRzufrGScMGKi5g1ooZcVNymFwQzF RfydKMZw==-G1cAAATibLFRmk1lXbALit kd8IhUKByQQY4sMBj HxLUPLGLL9i_3Y6E3HZttxxmyp8 VE7SA6x5Sl8AA==-e

http://www.giftbundlesfactory.com/XVEnpCOFHWAqeKRR48erkUx53tP7xnmU1k1GCDVi_NuPVUpElsSIdpAfJKDmfpK fnHKIhNvgrGt4Yfe_ 5e8Qj8A 5k uIy3792Li9yZgggvcP1eBvKIXSSDxgA9SydrCzs_xZOVDhlMKL_D4x6AZwdFipmbiaRVVM_rKokhqlBeW6p4zAq0e7MQKhKr4RKXykeeZueT8Fc8G0KuBCX8VDuxg92ew==-G1cAAATibLFRmk1lXbALit kd8IhUKByQQY4sMBj HxLUPLGLL9i_3Y6E3HZttxxmyp8 VE7SA6x5Sl8AA==

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_freesoundrecorder.exe - Powered by Reason Core Security