setup.exe

Sambamedia LLC

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Sambamedia has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Softpulse SoftwareBundler installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Sambamedia LLC  (signed and verified)

MD5:
65dc52a7de3b605c2de1f5185b788f23

SHA-1:
48fb16d67b4a195e225172689233f921a4cef95e

SHA-256:
10c472c8134995def6d0c923789efa87fc48f419ada6e8adb97971e9c2128690

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/15/2024 11:43:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
16.10.22.10

File size:
138.5 KB (141,840 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler (using Nullsoft Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/19/2016 7:00:00 PM

Valid to:
5/20/2017 6:59:59 PM

Subject:
CN=Sambamedia LLC, O=Sambamedia LLC, STREET="501 Silverside Road, Suite 105", L=Wilmington, S=Delaware, PostalCode=19809, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009D69E38A548309120F465065F4F6C970

File PE Metadata
Compilation timestamp:
4/1/2016 10:20:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:/PA6jXFN2Mc903aBqs4AUyMTFz4Vra3PCnlKRCq/G6:/hjmtBjUHTFma3KxO

Entry address:
0x326C

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 57, 33, DB, 68, 01, 80, 00, 00, 89, 5C, 24, 20, C7, 44, 24, 14, 30, 91, 40, 00, 89, 5C, 24, 1C, C6, 44, 24, 18, 20, FF, 15, B4, 70, 40, 00, FF, 15, B0, 70, 40, 00, 66, 3D, 06, 00, 74, 11, 53, E8, 07, 2E, 00, 00, 3B, C3, 74, 07, 68, 00, 0C, 00, 00, FF, D0, BE, 80, 72, 40, 00, 56, E8, 83, 2D, 00, 00, 56, FF, 15, AC, 70, 40, 00, 8D, 74, 06, 01, 38, 1E, 75, EB, 6A, 0D, E8, DB, 2D, 00, 00, 6A, 0B, E8, D4, 2D, 00, 00, A3, 64, 3F, 42, 00, FF, 15, 38, 70, 40, 00, 53, FF, 15, 6C...
 
[+]

Entropy:
7.7848

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file setup.exe has been seen being distributed by the following URL.

https://s3-us-west-2.amazonaws.com/ext-content/searchfreemovies.com/.../setup.exe

Remove setup.exe - Powered by Reason Core Security