musiceditorfree.exe

Nopumalifo

Huaxinwantong Beijing Technology Ltd

The application musiceditorfree.exe, “Nopumalifo Setup ” by Huaxinwantong Beijing Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.funtourbundle.com and multiple other hosts.
Publisher:
Purek   (signed by Huaxinwantong Beijing Technology Ltd)

Product:
Nopumalifo

Description:
Nopumalifo Setup

Version:
1.4.2.6

MD5:
3bd6589954f6681eb827671ff8a59072

SHA-1:
9dfa065887133cc71ba1961a216b5fdad0bea266

SHA-256:
0b9a0a8cb7d639b825944f65a4d41d91c81e694b6d91256541fa5031e3c0db39

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/6/2024 6:30:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Huaxinwa.Installer.Meta (M)
16.6.30.12

File size:
906.5 KB (928,248 bytes)

Product version:
2.0.9

Copyright:
Fast Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\Musiceditorfree.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/24/2016 8:00:00 AM

Valid to:
3/25/2017 7:59:59 AM

Subject:
CN=Huaxinwantong Beijing Technology Ltd, O=Huaxinwantong Beijing Technology Ltd, STREET="Dong Balizhuang 54, Building 2", L=BeiJing, S=BeiJing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C31292C6449E082B3FBF99E310243E2E

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:uti0NiGXIAR5v3nWi+dZKEUQq3p9UdRC+8Y4:uEcbXV/t+dZKEVq5b+81

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9345

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file musiceditorfree.exe has been seen being distributed by the following 30 URLs.

http://www.funtourbundle.com/d8swXEWIctvaAvJ2w9bJK5E7Da2j13H7BvzQskw3q0FJBQqCLSw6QN04dBjUzobadTWWGsosaX7kQdZaOQzDDRMDK6ZqxmHJMTntfc6hVRjzYVaEhXjXGs31jUx2ZFjaZwEoWtVQ0hzRD4 p8hiq03f33Ehx wXF73ghA79C v19aQGi4lIKq7MJlYr626CqoCSYIaaNHZpVsWivh9ow_3TRfRgM0g==-G1AAAMTOFhNKYhMk64JdUNg PTTjgL2_kkYDHZANnGPFkIeoh_sba_yY3e10J Ch4JyT3kFXAqnqsweUJ MD

http://www.factorycapitalstock.com/M_5HiyD2 ThsvfYZ1mx13F6 VILXF qQVL4vHL9rjpgad9cWZGJTnxUlXOoMxsuKeU5fgrFaEauLft4PZ_Cw7ywsSq5qcmqi0BTmAViUbYK2o cnNnzWeNuxPYowtbCtLlIJltoTFrCjRruRuEOTPbe57Zd yMsdnd69P9McAiuzqlsA6VptUEt3w9GUGUhgMY55qSWvlon9sB_mBooiMbP6VCgtNw==-G1AAAMTOFhNKYhMk64JdUNg PTTjgL2_kkYDHZANnGPFkIeoh_sba_yY3e10J Ch4JyT3kFXAqnqsweUJ MD

http://www.funtourbundle.com/hxYbxqTS kKfNSFFIitixqclSqBEvfNpMrOF8K7Ae9XGoM1jR 2N3t0Mx9fDzEiZ2ZrwAnOdCGiIcJm BEZjXqDk5h3vzeCHd8DgdrqKOOpdQbcuB5Ms1S0rcOIQEZ0hSrlN_dwLunGR2c aO5GKy3RpK59B131UYIZGZ YZj1S8f0neqDsVcd1ApRt7YkfdCb2kJlgBOM6ZRTO_P_CpgQrZ6MRDjg==-G1AAAMTOFhNKYhMk64JdUNg PTTjgL2_kkYDHZANnGPFkIeoh_sba_yY3e10J Ch4JyT3kFXAqnqsweUJ MD

http://www.funtourbundle.com/LLrhsMMh6HQ9oAdRC1hXdWbot xq4VCTWIgqzFHIs7TN4WYcG9ouQ8fr4rmU4heE5gTXVAffrxT2lZCRZx1UpvUS09rtHh2Or3uzTGop4qBvJh0BnON6_57uUiAzzdBsXXEZomk5NBKFkkp6R890Yal9Z7iA9AVVAbCA98zUmvYREbbGmqPFKBx1h0_C76P41aYu2oC6wejQML3Nj0w9OdHLwyMs8g==-G1AAAMTOFhNKYhMk64JdUNg PTTjgL2_kkYDHZANnGPFkIeoh_sba_yY3e10J Ch4JyT3kFXAqnqsweUJ MD

http://www.factorycapitalstock.com/AnlGh3ojyOHJKDrr6jDv4NuRm2Aufqdik DbZiBLrRv8oauG0j7NYnZs9bu7ylADWLITHT8Xhfm9jcUM2GVgBY7xDySwjQ2guyjBp9cPyJNPQEdrK2p9jxGzmOpAWyQK8v1OoZ_0tcK6o5LTheuhzcD1sCE3DAc5EaY43fLVgQi1UUFtqCZfXhNiWLQv2xd3MAXeTHNd1KNDGG53wy6 YxWKYJnmkA==-G1AAAMTOFhNKYhMk64JdUNg PTTjgL2_kkYDHZANnGPFkIeoh_sba_yY3e10J Ch4JyT3kFXAqnqsweUJ MD

http://www.taggiftflash.com/zANPfOwjxemkFQM_6n8D7giD6AG2mfuNP0tOI8ZgTbfQa3kuZweo 5rtxaCy9tMlFWgJyxH 5t6JK96YqtqWHPpjqwMuGr4o_aNyqO25RyrX PniDx3yaOvILj8rZx0OHo7Z8ysyrxKTbnY5MethY6aVruLaD4dKEtPReigaYgsiojjGdodfpRFN_b0W12c5PFTh00PDfW0mhgL1oCDetc SUNS_xA==-G1AAAMTOFhNKYhMk64JdUNg PTTjgL2_kkYDHZANnGPFkIeoh_sba_yY3e10J Ch4JyT3kFXAqnqsweUJ MD

http://www.funtourbundle.com/Phkzw2Ik7gNoBI63LxLHIPbKWHPOAo8nZlHw ONAc3RwjpMjfHFsZER8ejm0uetekVK9JhJYA4iNoriTrH0JVajQXc0hvewOSgueSvJe BEHtpon9mKqC8MjjxkjZFXsACII5G4 U9KzoXcEjnN42raE1QUqn6aksBgbL9T80ZJKkZaWwMUT8r8gJB2cNiQuX F4q0n0rgXT1sCQEtUar1JBknqC8g==-G1AAAMTOFhNKYhMk64JdUNg PTTjgL2_kkYDHZANnGPFkIeoh_sba_yY3e10J Ch4JyT3kFXAqnqsweUJ MD

http://www.funtourbundle.com/fDB6d7C9oNyBrzclptUEW8QZMoF TDqCe9 9kcZF0E_E4y9lfgNlSCLlRDRrckQ jRLUXCfJcWj iCnOEbQdFIhPKTew6PYyIln tQ1oJFKWFkp7__5stvRSJ3AHMm ZafAv1NhE5Ks8BQ2 lCb95Gm_kD1R03UEvKVH6Vd82EO 9MeFh_k8tjtRv0oV2ZeDfSYnsQWz8ZhENE6hww1LmzNETaHuyw==-G1AAAMTOFhNKYhMk64JdUNg PTTjgL2_kkYDHZANnGPFkIeoh_sba_yY3e10J Ch4JyT3kFXAqnqsweUJ MD

http://www.funtourbundle.com/CSWXSG8j4TLqhyMVJ_fdPYSuDC07mm0fdRl1DDvE85qzt4qh93ro2gIP0pWfwMr0OIB9QsuCeH58I3u4V7bnNZdVoqsiav8fc BnUhmwsoKMEypqpyB AmjpJC62dxQyM0yBZsIEwfm7z8ee7brj5P9utcbeRKBs0HlOBaIG8 cXJ0ZxJaFzdvll7L3gevLClVvvZ2SzTaeIkmoU014Mj0e2vtihpA==-G1AAAMTOFhNKYhMk64JdUNg PTTjgL2_kkYDHZANnGPFkIeoh_sba_yY3e10J Ch4JyT3kFXAqnqsweUJ MD

http://www.factorycapitalstock.com/TR41UVnWAAr0wd3VGie5ihYdL6AE90qBpFDtyqLIK19xp0ccYSCHgsMun33edXV_x_GvS CT8 r1mv grMWszBM4k9XYNFM5XJA84BjR_5VtSE5LEiRtOQ68P9NnLcOB8N4AdMd0xsnulDkfNj2i3a4OfRVX9KOk43ZZyKkV6ZEhxeOxHPDJ1px6m5M1 6ERsGTN1EwS87c6LWtxGfFBZRREiZAlohYd2Wr9SgOGk_G0zhsP5uk4D8NRzDBGad8ri jESvVqyvlI0bexw 8S6gcRAN5jnWo3E6tiEBtwODGgCfMQ58zaHOgUJygF_SMChhomqWekcJx3fS39ERhx4OhHjA1GrR1n_9Z9C31fStRrUlJ6mPr1R65YiI RoXm4wZdl7X1VT4PdrIFerkXA8rZlXLmx2U6 J8DK9Yz8FooqnpS1 7guNWIVOYRLAjAu8Hq3L 9EC0eNP6lPh1DE dkjqhX3Bw==-G1AAAMTOFhNKYhMk64JdUNg PTTjgL2_kkYDHZANnGPFkIeoh_sba_yY3e10J Ch4JyT3kFXAqnqsweUJ MD-e

http://www.taggiftflash.com/BHMQ1b_9KRASegVisb0 1pFWS2hyX89AeSnsMXHALWUGkEuDpDiAToeoTEYMWGZlXcAZKImZTiVLdcOiuQNemK4kXC9YoC9DBy0pWwfYUhBZKFYYDE2PZcItTKuwDiYx_kwB2jE4WRr4JL1zf 3_89E3UoWeDpte7E_COT1vHeKtnpN7CCVXJk0D3Ww7_zDBKNUnp3Wei5DTBpUvypK7UEB9TwU1mQ==-G1AAAMTOFhNKYhMk64JdUNg PTTjgL2_kkYDHZANnGPFkIeoh_sba_yY3e10J Ch4JyT3kFXAqnqsweUJ MD

Latest 30 of 30 download URLs

Remove musiceditorfree.exe - Powered by Reason Core Security