mecanet portable.exe

Sambamedia LLC

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application mecanet portable.exe by Sambamedia has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Softpulse SoftwareBundler installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from admin.magnodnw.com.
Publisher:
Sambamedia LLC  (signed and verified)

MD5:
c2d91955e5474ada97e41fcfb920cc86

SHA-1:
b1d6343e7da093bc5a72237c27b303d8b582a91c

SHA-256:
c2fa827d4210d3b1e91b40da1cff82652f9fe898900d683657ad097df4b645c9

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/11/2024 12:19:02 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softpulse (M)
16.8.3.22

File size:
1.2 MB (1,291,280 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\mecanet portable.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/2/2014 6:00:00 PM

Valid to:
12/3/2015 5:59:59 PM

Subject:
CN=Sambamedia LLC, O=Sambamedia LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5AF374AFD1700F42AFDDF9B5F12FD906

File PE Metadata
Compilation timestamp:
10/8/2015 9:21:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:7ZCjroHnC/ZNk3qPiaF7ipMNh3KSpvRbJAGp9aKdQgA8TA8ya:7sfoaHk3qPiyiYh6SHl3PTA83

Entry address:
0x1000

Entry point:
B8, 10, 30, 89, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 7B, F6, 86, 66, 81, 81, 9F, B5, C5, 6D, 51, D0, 1C, A5, 55, 89, 56, EC, 8F, 62, B8, D3, 51, 8A, BF, B2, 47, 53, A3, 5A, 2B, 53, 9D, 8E, 62, 9F, 45, 7E, AC, 4C, E0, 06, 7E, BD, 53, 9A, EE, 15, D5, F2, 47, 12, E8, 0D, 5F, AD, 62, 5F, DD, D0, B1, 72, 8F, BE, 65, 2B, 3B, 04, 0B, C8, 9A, 4D, 5A, 89, 76, 8C, 88, 56, 18, 67, 18, 9D, 48, 22, 92, BB, 7D, BE, 68, EF, A4, 82, 3B...
 
[+]

Entropy:
7.9556

Packer / compiler:
PECompact v2

Code size:
3.6 MB (3,757,056 bytes)

The file mecanet portable.exe has been seen being distributed by the following URL.

Remove mecanet portable.exe - Powered by Reason Core Security