Sambamedia SL

Publisher Information

Sambamedia SL is a software developer located in Adeje, Santa Cruz De Tenerife in Spain*. The company is a primary distributor of unwanted software by bundling various potentially unwanted programs (PUPs) in a bundled installer. Thre are 4 additional code signing certificates issued to this publisher.
Remove Sambamedia SL Malware - Powered by Reason Core Security
Authority:
GlobalSign nv-sa

Valid from:
4/28/2014 10:13:17 AM

Valid to:
4/29/2015 10:13:17 AM

Subject:
E=contact@sambamediasl.com, CN=Sambamedia SL, O=Sambamedia SL, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121a6f5ca8560763435df885221ae3b200f

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.SambamediaSL.G, PUP.Installer.SambamediaSL.F, PUP.SambamediaSL.K, PUP.SambamediaSL.V, PUP.SambamediaSL.O, PUP.SambamediaSL.L, PUP.SambamediaSL.P, PUP.SambamediaSL.T, PUP.Bundler.Softpulse, PUP.Softpulse.Sambamedia.Bundler (M)
100.00%

McAfee
PUP-FIG!80B7D2700B25, CryptDomaIQ, Socrydo, SoftPulse, Program.SoftPulse
46.51%

AVG
Generic, Win32/DH{gRJ+UIEHeVRPFVGBFYEJHFOBE0GBDw}, Win.Threat.High, Found Win32/DH{gRJ UIEHeVRPFVGBFYEJHFOBE0GBDw}
44.19%

McAfee Web Gateway
PUP-FIG!80B7D2700B25, BehavesLike.Win32.Dropper.bh , Socrydo, BehavesLike.Win32.MPlug.tc, SoftPulse, BehavesLike.Win32.Dropper.tc
41.86%

Avira AntiVirus
APPL/Downloader.Gen, TR/Dropper.Gen, APPL/Softpulse.Gen8, Adware/Softpulse.djcr.8, Adware/Agent.djcr.7, Adware/Agent.djcr.8
41.86%

ESET NOD32
Win32/SoftPulse.B potentially unwanted application, Win32/SoftPulse.J potentially unwanted application, Win32/SoftPulse.I potentially unwanted application
39.53%

Agnitum Outpost
Riskware.Agent, PUA.Downloader, PUA.Agent
39.53%

Panda Antivirus
Trj/Genetic.gen
39.53%

avast!
Win32:PUP-gen [PUP], Win32:Malware-gen, Win32:SoftPulse-U [PUP], Win32:GenMalicious-GU [PUP], Win32:SoftPulse-X [PUP], Win32:SoftPulse-W [PUP]
37.21%

VIPRE Antivirus
Threat.4783235, Threat.4150696, Trojan.Win32.Generic, Threat.4783262
34.88%

1 / 68      (Adware)
00000000  (94b864ba6aebc5a484157f7e13d9aef7)

1 / 68      (Adware)
00000000  (f43359a3263bccb7e84f297388b1f650)

1 / 68      (Adware)
microsoft office 2010.exe  (c7af36e0e320c6addc396d02800154cf)

1 / 68      (Adware)
microsoft-office-2010.exe  (478dc83d84827f1553ee65a936b59fdb)

1 / 68      (Adware)
new player.exe  (6f7e655784b1edc37ab712afaea3534c)

1 / 68      (Adware)
new player.exe  (36d38650b7783ac27d218985352f11fc)

1 / 68      (Adware)
microsoft_office_2010.exe  (e34c220e0c1b0d3117a1b3d5329677aa)

1 / 68      (Adware)
microsoft_office_2010.exe  (b782a5e23a244a48a9fa8b8076a932c3)

1 / 68      (Adware)
itunes.exe  (93e612e2b17bb15a577b3ca08f9425cb)

1 / 68      (Adware)
microsoft_office_2010.exe  (4ba3c19d7acaf9d46034b1751af3bdea)

1 / 68      (Adware)
microsoft-silverlight.exe  (970abfeb6a8dc229c1ebea931f82e8fd)

1 / 68      (Adware)
microsoft_silverlight.exe  (14cd316d32424b464c29ebdfdcb9baec)

1 / 68      (Adware)
microsoft-publisher.exe  (e107b95cf5f259186daff7c499f430a3)

1 / 68      (Adware)
microsoft publisher.exe  (5407a3373b5ba9e4e24a23fe82f158ef)

1 / 68      (Adware)
microsoft publisher.exe  (3c9edd1bdd88d102eb785850cf23c80f)

1 / 68      (Adware)
00000001  (ee32c394ed4c578c7ba7b58831af9d31)

1 / 68      (Adware)
nero.exe  (e86db176bb7614c007e7be6b80600c39)

1 / 68      (Adware)
itunes.exe  (6097cc92daf651a2b19eb6df02567037)

1 / 68      (Adware)
itunes.exe  (352a3a4fef9594b153196caa83e05d46)

1 / 68      (Adware)
itunes.exe  (e6063f481279abf252e9d279b9ae121a)

1 / 68      (Adware)
00000000  (4d78be25e0232215550f424e89df41f0)

1 / 68      (Adware)
player_setup.exe  (96207c173dcdc06ce9ea8c9b95abf780)

7 / 68      (Adware)
avg anti virus free edition.exe  (5a05355af3c75f8387556f43a4bb9e50)

36 / 68    (Adware)
00000001  (ac5e147ae4cf19dc673594e77be5890e)

31 / 68    (Adware)
ask_com_toolbar.exe  (811edf542e663219403805032838904c)

33 / 68    (Adware)
itunes.exe  (2a69a9d822d41f69a3adaeedf9475041)

31 / 68    (Adware)
microsoft-office-2010.exe  (fb820a978d5dd26dfbd5a07174cd4156)

28 / 68    (Adware)
itunes.exe  (d63a00c56d2bf8118828ffadea9b8cdd)

22 / 68    (Adware)
microsoft publisher.exe  (ef82d48774238ef551aac599bd56157d)

9 / 68      (Adware)
itunes.exe  (5b5d825fc906d36a25220cf512eebf53)

 
Latest 30 of 43 files

Downloads URLs for files signed by Sambamedia SL.

1 / 68      (Adware)
http://www.lpmxp2.com/.../Player_Setup.exe  (96207c173dcdc06ce9ea8c9b95abf780)

10 / 68    (Adware)
http://downloads.gufile.com/.../whatsapp.exe  (c67fa4dbc065c4ee8a2f2db9169b8218)

18 / 68    (Adware)
http://downloads.gufile.com/.../itunes32_64.exe  (87ba642a37ae47fc31ce65de099d56e7)

13 / 68    (Adware)
http://downloads.gufile.com/.../Microsoft-Silverlight.exe  (3519899bf9c193da678b7c539d4013f7)

The following websites host and distribute files published by Sambamedia SL.

The certificates below are also signed by Sambamedia SL.

45EC30691B6FCCE67A70FF47105196DF  (Sep 06, 2014 to Sep 07, 2015)

2E18A24E7306F07F934BE75CA0E80137  (Sep 23, 2014 to Sep 07, 2015)

0CC1DC4BFF437A219B57FD821A92EE57  (Apr 28, 2014 to Apr 29, 2015)

00B3AB0358C7184E7B47E1675806B74132  (Apr 25, 2014 to Apr 26, 2015)

The following publishers (by Authenticode signature organization name) are related.

Remove Sambamedia SL Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Sambamedia SL by GlobalSign nv-sa on April 28, 2014 with the serial number '1121a6f5ca8560763435df885221ae3b200f'.