musiceditorfree.exe

Lipocali

Huaxinwantong Beijing Technology Ltd

The application musiceditorfree.exe, “Lipocali Setup ” by Huaxinwantong Beijing Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.taggiftflash.com and multiple other hosts.
Publisher:
Huaxinwantong Beijing Technology Ltd  (signed and verified)

Product:
Lipocali

Description:
Lipocali Setup

Version:
1.3.5.6

MD5:
03cb17024af24990d32b9cc27fb9c7e6

SHA-1:
d6e733fb01b30eebdaef2aaf2f393fdc4b871c74

SHA-256:
e0456d54f9dc8f2ce00f2c46a404d5fd2f54af6a067eb4987f7f60723023dca4

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/29/2024 9:16:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Huaxinwa.Installer.Meta (M)
16.5.19.11

File size:
899.5 KB (921,088 bytes)

Product version:
5.0

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\Musiceditorfree.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/24/2016 8:00:00 AM

Valid to:
3/25/2017 7:59:59 AM

Subject:
CN=Huaxinwantong Beijing Technology Ltd, O=Huaxinwantong Beijing Technology Ltd, STREET="Dong Balizhuang 54, Building 2", L=BeiJing, S=BeiJing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C31292C6449E082B3FBF99E310243E2E

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:xiUKOMvXkVygzG7zzgY6EQDTbJWhF5GwaL0re+Xw:gTmq/gYfQHbJ4aIDw

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9362

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file musiceditorfree.exe has been seen being distributed by the following 50 URLs.

http://www.taggiftflash.com/c?x=t7BVOml2PC8ajoc4XMo9LEvNqvF/R5e8Tl2Ua5FjuIg=&c=PUbRUBigrezX6N ZaGH45Z79x9fS8MGWKFJHfApqWCIKqc4C4D dAv8q8ukufRk1aUW2Kgej/5kYYThjg7vxJR1VXPkkYaGxR5hBj UcaNniQ8h6snqO8/45Qu74CdAujOTtc82F3zNQktWOr/A mw==&e=0&downloadAs=MusicEditorFree.exe&fallback_url=http://www.downloadonic.com/music-editor.net/.../MusicEditorFree_IS.exe

http://www.taggiftflash.com/c?x=e3fa7vxrMbcqTgeD5yfH3Be94hl/h3R5ucDOhNs3USk=&c=5BmN4Tjwpv6Rls5SiE6aVnbLQaMMtKrSrjGjxqt7xYQcvD5/Itg1bZrwUbRjKAVLnZcg4dqclpNSx1IdKNXBlHtuYQDT0GvnmCF/G8QbeTfRLaoNX0lzDtt3uRLhM3HqkPGpOJFDAn3AOQlLWWnW5eCZWj6N2xCZs 7WESCqKv4=&e=0&downloadAs=MusicEditorFree.exe&fallback_url=http://www.downloadonic.com/music-editor.net/.../MusicEditorFree_IS.exe

http://www.taggiftflash.com/c?x=SBHdlB0TtHa/jobvAgUA1sISXlM2MxXjdgZUP/0aPQU=&c=nlAtnybtFP9iB2eeJTkif3l6 ucT EiVSXKoWRcbodEEW8t04aV/IPEsBNUPxfPOgUpnuCZ4hvBw0rRoA5Q9TaZDnxg8WOGEB wYB9jINWt3IIUoFVjjbIh9wtYSH6qpF9QW xHhdMT7RtfvFbZwpM8sjr/Zaw/iwHvthU3uz/A=&e=0&downloadAs=MusicEditorFree.exe&fallback_url=http://www.downloadonic.com/music-editor.net/.../MusicEditorFree_IS.exe

http://www.taggiftflash.com/WVl6OTRQV3hHU0RrellXWXliR3AwUTBabVlXaElOMk52YzNrNVpYQkxTVU14WkNVeVFtMWxURVZVT0hSdVZscEtZeVV6UkNaalBUQjRhMUZhUmpBM01qZFVTa2xhTkVKV1luaEpWVE5hUVc5bVNtVkZTSFo1TjNOcGNTVXlSblptZGtZNU56SjFXSFZNVms1YVdGY2xNa0p2YVhkV05sSTVXak14Yms4bE1rSnpURmxKUzJaTFVEZDZiVEZCYkc1d2QycFFhWFF3V0RsMVJERlZaemxRYkd0VlIzQnhjMU16YjAxSVozTmpXRVV4VW1aRVVFTlZlRmt6YzJoU2JXRnNObGRxVVdsWGNXeHBNMmxUVUhKd2MzRktVU1V6UkNVelJDWmxQVEFtWkc5M2JteHZZV1JCY3oxTmRYTnBZMFZrYVhSdmNrWnlaV1V1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2QzZDNMbVJ2ZDI1c2IyRmtiMjVwWXk1amIyMGxNa1p0ZFhOcFl5MWxaR2wwYjNJdWJtVjBKVEpHWm1sc1pYTmtiM2R1Ykc5aFpDVXlSazExYzJsalJXUnBkRzl5Um5KbFpWOUpVeTVsZUdVPQ==

http://www.taggiftflash.com/WVl6OTRQVzk2VEZWa2QyMXVkRmRZVjAxMGNYcEVXRmcwUVZRNVpsRTVhRk5vUmxCeFRXMXpVVVJWVWxwUE5Fa2xNMFFtWXoxUGRsaDVKVEpDY0VsSlpISXlWbTFaWW5RME0wMXhkV2RGWlVvd1RsRklhM0ZsVGsxdk1XZHZWMHBGTXpCd1IzaFZjMFpLVTJKU1JFZEdXVlo0YTFWcFZVUm9TMk5FT1UwNVFuQlhPVlYzWlVoV2FraFNiMWRCTVZNMlFrcGhlRVEwVlRodEpUSkdWMnN5WjI1M05sVnZlVU5wU3pGU2RrbFRSM0ZUYTNGQ2NtUldaMEVtWkc5M2JteHZZV1JCY3oxTmRYTnBZMFZrYVhSdmNrWnlaV1V1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2QzZDNMbVJ2ZDI1c2IyRmtiMjVwWXk1amIyMGxNa1p0ZFhOcFl5MWxaR2wwYjNJdWJtVjBKVEpHWm1sc1pYTmtiM2R1Ykc5aFpDVXlSazExYzJsalJXUnBkRzl5Um5KbFpWOUpVeTVsZUdVPQ==

http://www.taggiftflash.com/c?x=OYufCFJQ29v5U Wlz/c1fl6qglhZpTvBUgtirKPvoPo=&c=VAFk6 JB/RHMu7Kl7EYijT6qTImGe ZAaCF7U7VfiWrjHh0DMoYt9BBSbtpUgc2Dz7zqJxmq1gLagg5U8YlsMAkPjoFQtsX1MnwP/7ji3fciOBwCjkjvFWFIIPiLnLBdAX5oR0L27NnPpOFE3kO68qIw51FCXLz8gDdNKq8YYm4=&e=0&downloadAs=MusicEditorFree.exe&fallback_url=http://www.downloadonic.com/music-editor.net/.../MusicEditorFree_IS.exe

http://www.taggiftflash.com/WVl6OTRQVk5NUkdsM1VrOURWWEJ5Y3psbFdHaFlWVWxhT0ZJbE1rWlVkR2hQZUZkUFRFeFhjMDVFZUhwMWJFeGxOQ1V6UkNaalBXUlFlbGhXYXpBeVFqTjZOWGQyVjNZM2FYQk9Ua3BrT1ZvbE1rSWxNa1pwUjNVM1dpVXlSbE5IYVZvMmIwdENTbWxaTm5GNlFtaFVaRk5SVEZBeFIySnROV3BJSlRKQ2NHcFZNMHhGT1RNd1duSnFVMmMxU1ZsWmVHVkVabkZtZG1JMlZFOW9PRUpxUWtSNk1WRk1lbXR0VEhCTVN5VXlSbkJrUldSdGQxVTNWV3hFVTJGRVlXYzRNMWs0V0VkMFNETkJlblp1SlRKQ2FXRmlRelZpZW5CTFp5VXpSQ1V6UkNabFBUQW1aRzkzYm14dllXUkJjejFOZFhOcFkwVmthWFJ2Y2taeVpXVXVaWGhsSm1aaGJHeGlZV05yWDNWeWJEMW9kSFJ3SlROQkpUSkdKVEpHZDNkM0xtUnZkMjVzYjJGa2IyNXBZeTVqYjIwbE1rWnRkWE5wWXkxbFpHbDBiM0l1Ym1WMEpUSkdabWxzWlhOa2IzZHViRzloWkNVeVJrMTFjMmxqUldScGRHOXlSbkpsWlY5SlV5NWxlR1U9

Latest 30 of 68 download URLs

Remove musiceditorfree.exe - Powered by Reason Core Security