itunes32_64.exe

Sambamedia SL

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application itunes32_64.exe by Sambamedia SL has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. With this installer, users are expecting to download Apple's iTunes but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Sambamedia SL  (signed and verified)

MD5:
87ba642a37ae47fc31ce65de099d56e7

SHA-1:
c02fc94fbe29e43b91f31a1ddb8f286087104d47

SHA-256:
8b4d489511dc29ef66b9fc93891ee25e05a40592cd62912b73a710715e6c52d4

Scanner detections:
15 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/26/2024 11:20:30 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

avast!
Win32:SoftPulse-U [PUP]
140617-1

AVG
Generic
2015.0.3391

Dr.Web
Adware.Downware.5878
9.0.1.05190

ESET NOD32
Win32/SoftPulse (variant)
8.10197

herdProtect (fuzzy)
2014.9.12.23

K7 AntiVirus
Unwanted-Program
13.182.12926

McAfee
Socrydo
5600.7047

NANO AntiVirus
Trojan.Win32.Buzus.ddkefn
0.28.2.61349

Norman
Malware
11.20140912

Panda Antivirus
Trj/Genetic.gen
14.08.06.04

Reason Heuristics
PUP.SambamediaSL.L
14.8.6.2

Sophos
SoftPulse
4.98

VIPRE Antivirus
Threat.4783235
31208

File size:
1.2 MB (1,248,440 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\itunes32_64.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
4/28/2014 10:13:17 AM

Valid to:
4/29/2015 10:13:17 AM

Subject:
E=contact@sambamediasl.com, CN=Sambamedia SL, O=Sambamedia SL, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A6F5CA8560763435DF885221AE3B200F

File PE Metadata
Compilation timestamp:
8/2/2014 2:51:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:B+dW0LXXy9G36xN9G36xtozdXea60Pm+XdEKjV14tPId3laEbRfK57WmI1:sWq35vzH60++Xzx14ZIbaEy56/

Entry address:
0x5CB0

Entry point:
E8, 0F, 20, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 8B, 45, 0C, 83, EC, 20, 56, 57, 6A, 08, 59, BE, 10, 20, 41, 00, 8D, 7D, E0, F3, A5, 8B, 4D, 08, 5F, 5E, 85, C0, 74, 0D, F6, 00, 10, 74, 08, 8B, 01, 8B, 40, FC, 8B, 40, 18, 89, 4D, F8, 89, 45, FC, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, AC, 10, 41, 00, C9, C2, 08, 00, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 8B, 4D, EC, 33, CD, E8, 37...
 
[+]

Code size:
61.5 KB (62,976 bytes)

The file itunes32_64.exe has been seen being distributed by the following URL.

Remove itunes32_64.exe - Powered by Reason Core Security