itunes.exe

Sambamedia SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application itunes.exe by Sambamedia SL has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. With this installer, users are expecting to download Apple's iTunes but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Sambamedia SL  (signed and verified)

MD5:
5b5d825fc906d36a25220cf512eebf53

SHA-1:
901129c699271161608a2fee89e6170f04afbd88

SHA-256:
f866f8eac32b7433a58d3b9b01a14ebf530db0420f310460aef82b5f79a56150

Scanner detections:
8 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 11:05:45 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
APPL/Softpulse.Gen8
7.11.170.174

AVG
Generic
2015.0.3362

ESET NOD32
Win32/SoftPulse.J potentially unwanted application
7.0.302.0

Malwarebytes
PUP.Optional.DomaIQ
v2014.09.03.01

McAfee
SoftPulse
5600.7018

Panda Antivirus
Trj/Genetic.gen
14.09.03.01

Reason Heuristics
PUP.SambamediaSL.G
14.9.3.8

File size:
1.2 MB (1,240,688 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\itunes.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
4/28/2014 4:13:17 PM

Valid to:
4/29/2015 4:13:17 PM

Subject:
E=contact@sambamediasl.com, CN=Sambamedia SL, O=Sambamedia SL, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A6F5CA8560763435DF885221AE3B200F

File PE Metadata
Compilation timestamp:
9/1/2014 12:32:41 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:vJB0GuOkSEW30BCtJSfrZtqtDFVGoHzS0QxfNWsS2px1vkU:heTO9EEPtJKqjMoHsfNWs9pjM

Entry address:
0x52D8

Entry point:
E8, 91, 36, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 40, 02, 41, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, B0, 00, 41, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63...
 
[+]

Code size:
60 KB (61,440 bytes)

Remove itunes.exe - Powered by Reason Core Security