00000000

Sambamedia SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file 00000000 by Sambamedia SL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Softpulse SoftwareBundler installer.
Publisher:
Sambamedia SL  (signed and verified)

MD5:
0e8c3ec30834eed62a4ee142c2c31ba7

SHA-1:
d28a0daa3e224208c2f38cd15f6ae926bd59798d

SHA-256:
52fe24538710d24252365d5455510ac89ddff757534e12a34480203492592235

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 4:12:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softpulse.Sambamedia.Bundler (M)
16.2.15.0

File size:
789 KB (807,936 bytes)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\appdata\roaming\baidu\sparksafe\profile\file system\001\t\00\00000000

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/24/2014 9:00:00 PM

Valid to:
4/25/2015 8:59:59 PM

Subject:
CN=Sambamedia SL, O=Sambamedia SL, STREET="La Botavara, 1 2", L=Adeje, S=Santa Cruz de Tenerife, PostalCode=38670, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B3AB0358C7184E7B47E1675806B74132

File PE Metadata
Compilation timestamp:
5/22/2014 1:33:05 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:z21GT5b+s2KVzxFAu27Mms/p9kh3zPSBH/dRUshEMsPDaYBKDEWf8T:z21lRKVzxFAbVshJBH/PHELaU

Entry address:
0x4D137

Entry point:
E8, ED, 7A, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 42, 36, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, D4, 0C, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 95, 12, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, B4, 06, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73, 0E, E8, F3, 35, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, AD...
 
[+]

Code size:
454 KB (464,896 bytes)

Remove 00000000 - Powered by Reason Core Security