+mfhlmyu.exe

Sambamedia SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file +mfhlmyu.exe by Sambamedia SL has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Softpulse SoftwareBundler installer. It is also typically executed from the user's temporary directory.
Publisher:
Sambamedia SL  (signed and verified)

MD5:
ca7ea8ed2ebb81447f7f70c8f6ae5082

SHA-1:
3e7ea1cd347e0895e7a0711d00ddfd3a797f5335

SHA-256:
f38fcd18b0ce71790c0928e3cebe83e63fcabfdaf32f710fdfa2054e7910949c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 9:33:28 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softpulse.Sambamedia.Bundler (M)
16.2.14.18

File size:
788.9 KB (807,824 bytes)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\appdata\local\temp\+mfhlmyu.exe.part

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/24/2014 6:00:00 PM

Valid to:
4/25/2015 5:59:59 PM

Subject:
CN=Sambamedia SL, O=Sambamedia SL, STREET="La Botavara, 1 2", L=Adeje, S=Santa Cruz de Tenerife, PostalCode=38670, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B3AB0358C7184E7B47E1675806B74132

File PE Metadata
Compilation timestamp:
5/22/2014 10:33:05 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:k21GT5b+s2KVzxFAu27Mms/p9kh3zPSBH/dRUshEMsPDaYBKDEWf85:k21lRKVzxFAbVshJBH/PHELay

Entry address:
0x4D137

Entry point:
E8, ED, 7A, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 42, 36, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, D4, 0C, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 95, 12, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, B4, 06, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73, 0E, E8, F3, 35, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, AD...
 
[+]

Entropy:
6.3416

Code size:
454 KB (464,896 bytes)

Remove +mfhlmyu.exe - Powered by Reason Core Security