java.exe

Sambamedia SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application java.exe by Sambamedia SL has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. With this installer, users are expecting to download the free Oracle Java Runtime but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Sambamedia SL  (signed and verified)

MD5:
533913e2feb123518d33b242d8db2a37

SHA-1:
549ce433b817dd70e4ed5f4de92a8f7efe8a2e35

SHA-256:
ab179dc5951125a85ddb330534e24f009cb9d294a7893190778f33ff5c3fd2d0

Scanner detections:
9 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 3:05:06 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen
7.11.170.170

AVG
Generic
2015.0.3362

Dr.Web
Trojan.Packed.28257
9.0.1.05190

ESET NOD32
Win32/SoftPulse.B potentially unwanted application
7.0.302.0

G Data
Win32.Application.Softpulse
14.9.24

McAfee
SoftPulse
5600.7018

NANO AntiVirus
Trojan.Win32.MLW.dcyjvr
0.28.2.61942

Reason Heuristics
PUP.SambamediaSL.E
14.9.3.8

VIPRE Antivirus
Threat.4783235
32210

File size:
870.5 KB (891,360 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\java.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/28/2014 1:00:00 AM

Valid to:
4/29/2015 12:59:59 AM

Subject:
CN=Sambamedia SL, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Sambamedia SL, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0CC1DC4BFF437A219B57FD821A92EE57

File PE Metadata
Compilation timestamp:
7/11/2014 12:25:53 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:NQzOPOjq9z//7eYNp+7BQrZUGMUytX/f+FkGY7HGKz48jI8X:l9n7eYa7BDUOXH+aGLKz48jI8X

Entry address:
0x4D448

Entry point:
E8, 2B, 89, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, B3, 66, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, BD, 0E, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 64, 39, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 73, 0C, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73, 0E, E8, 64, 66, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, AD...
 
[+]

Code size:
464.5 KB (475,648 bytes)

Remove java.exe - Powered by Reason Core Security