setup.exe

Sambamedia LLC

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Sambamedia has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. The file has been seen being downloaded from ttb.latestvideoplayer.com.
Publisher:
Sambamedia LLC  (signed and verified)

MD5:
c4ec6456d8450cf1c1c23bb1bfea2bc3

SHA-1:
f67d10d1430bea72cc9d1e5a0b30f94c9ffb03c5

SHA-256:
7535d3dbbfb4888c745cbc522d84c1255be3c5cd0fd6899d942988446b547540

Scanner detections:
8 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/10/2024 10:09:17 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

Avira AntiVirus
PUA/Softpulse.Gen
7.11.212.80

ESET NOD32
Win32/SoftPulse.X potentially unwanted application
7.0.302.0

K7 AntiVirus
Unwanted-Program
13.198.15065

Kaspersky
not-a-virus:Downloader.Win32.DriverUpd
15.0.0.543

Panda Antivirus
Trj/Genetic.gen
15.02.24.10

Reason Heuristics
PUP.Installer.Softpulse
15.2.24.9

VIPRE Antivirus
Threat.4150696
37588

File size:
484.6 KB (496,272 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/13/2015 12:00:00 AM

Valid to:
2/13/2016 11:59:59 PM

Subject:
CN=Sambamedia LLC, O=Sambamedia LLC, STREET="501 Silverside Road, Suite 105", L=Wilmington, S=Delaware, PostalCode=19809, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B3008B962204B9EFCE56FF0B2B9C2C13

File PE Metadata
Compilation timestamp:
2/23/2015 2:21:27 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:DEoPDUSLJ1Omtgb8iHObwqmyrqAWbEeJNhi4U4:P1DtniQ1mmqAOi4U

Entry address:
0x1000

Entry point:
B8, 94, D8, 58, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, ED, EC, 7D, 32, CE, E8, B7, CC, A8, D5, 00, D6, CD, A2, BF, 2C, 65, 45, 72, 83, 44, A3, AA, 40, 9F, 72, FC, C8, 29, 21, 07, D7, 1C, 98, B1, 14, B5, BD, E9, CD, F0, 5F, E7, F7, 3B, 60, FD, E1, 1A, 85, 66, D4, C5, C5, 62, 0D, E3, 18, 15, AA, 6D, 6D, 6C, 78, 80, DB, 55, B7, 83, 72, 7E, 47, DF, D5, 8C, C3, CF, 3B, E0, CF, 6A, 33, 7A, C1, D2, 66, 5A, EC, C5, E4, 86, E3, 74...
 
[+]

Entropy:
7.9398

Packer / compiler:
PECompact v2

Code size:
965.5 KB (988,672 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security