vafplayer.exe

Sambamedia SLU

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application vafplayer.exe by Sambamedia SLU has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the Softpulse SoftwareBundler installer. The file has been seen being downloaded from ttb.vafplayer.com.
Publisher:
Sambamedia SLU  (signed and verified)

MD5:
3f619017f362a2ab2b4b6ec255c6d9ef

SHA-1:
dc4acba28164bcca7e5a22888544ae10a7a3e848

SHA-256:
c6541d6f148a11fd8602f281632b1d95d1e179be4e270762afd1b9c60ab56d21

Scanner detections:
12 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/2/2024 7:31:56 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.SoftPulse
2015.05.31

Avira AntiVirus
PUA/Softpulse.Gen
8.3.1.6

AVG
Adware AdPlugin
2016.0.3077

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Domaiq.175
9.0.1.0166

ESET NOD32
Win32/SoftPulse.X potentially unwanted application
9.7.0.302.0

herdProtect (fuzzy)
2015.6.15.21

IKARUS anti.virus
PUA.SoftPulse
t3scan.1.9.2.0

NANO AntiVirus
Trojan.Win32.Domaiq.dpomrw
0.30.24.1636

Reason Heuristics
PUP.Bundler.Softpulse
15.3.9.17

VIPRE Antivirus
Threat.4150696
40552

File size:
1.3 MB (1,356,744 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\vafplayer.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/28/2014 2:00:00 AM

Valid to:
4/29/2015 1:59:59 AM

Subject:
CN=Sambamedia SLU, O=Sambamedia SLU, L=Adeje, S=Santa Cruz de Tenerife, C=ES

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
1D2678833456F6A11CEBC944E8AFF2C6

File PE Metadata
Compilation timestamp:
3/9/2015 12:50:16 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:mZNzx7jam3NkiOTrK5PZEvX+cEuJqQVmXIXBwh5uOezdOSqIpquDwfEfFFmIvaxp:mZNzVj9NOTrKZmvX+cLVm8MOdOSPB0oA

Entry address:
0x1000

Entry point:
B8, 54, 6C, 90, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 62, E3, FF, F2, 24, 85, E0, 4B, 9C, 44, DF, 4B, FB, E9, 84, 9E, 7C, 19, 7F, 90, F3, 90, 7D, 59, 3E, 23, 92, 98, EB, B3, 21, 00, 4C, 9E, 61, 63, 69, 77, 94, 29, 14, 10, D6, 9F, 55, 74, 64, 7C, 06, 1E, 12, 17, 2B, E7, 82, 69, B2, 53, 20, DD, F4, C3, EE, 5B, 1C, 85, 14, 0A, 54, B2, FD, 6C, 7B, 0A, 9A, 19, F9, C8, E9, 93, 99, F3, EC, 4D, 00, 64, EC, 09, DB, 6C, 2A, E4, 64...
 
[+]

Packer / compiler:
PECompact v2

Code size:
3.7 MB (3,851,776 bytes)

The file vafplayer.exe has been seen being distributed by the following URL.

Remove vafplayer.exe - Powered by Reason Core Security