00000000

Softpulse SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file 00000000 by Softpulse SL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Softpulse SoftwareBundler installer.
Publisher:
Softpulse SL  (signed and verified)

MD5:
d7983d954848aef1b2286ee4c5c82244

SHA-1:
7724803c1457163e51321263b42f627982cd199d

SHA-256:
d088f634dcd5f21f1d1b7e5c51f23625a4f95c77bc52594f860abe4ced2ef1be

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/25/2024 2:40:36 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softpulse.Bundler (M)
16.2.12.9

File size:
810.8 KB (830,280 bytes)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\appdata\local\google\chrome\user data\default\file system\002\t\00\00000000

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/11/2014 11:48:56 AM

Valid to:
2/12/2015 11:48:56 AM

Subject:
CN=Softpulse SL, O=Softpulse SL, L=Guia de Isora, S=Tenerife, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11210602DAEE0BE4AA7D855EE48D3D77A3CC

File PE Metadata
Compilation timestamp:
6/3/2014 11:09:31 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:XHAVdbgYZFkLri0InZF1o2Bd9aFtry9rK1u3sPDaYskpR3rY:XH1AFx0Ild9aFtrmrKgY7rY

Entry address:
0x4E119

Entry point:
E8, EA, 7A, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, D2, 37, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, CD, 0C, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 23, 14, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, A2, 0A, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73, 0E, E8, 83, 37, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, AD...
 
[+]

Entropy:
6.3120

Code size:
464.5 KB (475,648 bytes)

Remove 00000000 - Powered by Reason Core Security