the sims 3 university life.exe

ВERSHNET LLC

The application the sims 3 university life.exe by ВERSHNET has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from im13cdltc2ix42y.bl-up.ru.
Publisher:
ВERSHNET LLC  (signed and verified)

Version:
1.0.0.0

MD5:
2876653da36af7e58e7ca1ad41461d03

SHA-1:
bf54d9099e1bcbaf98ed4c0d9c4885a64b9ed5fb

SHA-256:
919a79f9629fca931ac079db414cccbc9ba4802b774f3c98dd2ac9f70aaf4860

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
12/28/2024 2:26:24 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.OutBrowse.ERSHNET (M)
16.3.18.16

File size:
7 MB (7,352,616 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\the sims 3 university life.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/5/2015 3:00:00 AM

Valid to:
2/6/2016 2:59:59 AM

Subject:
CN=ВERSHNET LLC, O=ВERSHNET LLC, STREET="600-Richchya, house 66, office 10", L=Vinnitsa, S=Vinnitskiy Region, PostalCode=21027, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0DCBDEF5E756334284571793EA14D465

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:WiZMjSNbZImfODuS7+0u3byyQcFl7OFWqksN9usJtyscToz4YYKUu/VKuzF8D/9n:WG1iDuzbkK5OFWhsasPBLn/VKuzFiOE

Entry address:
0x335930

Entry point:
55, 8B, EC, 83, C4, EC, 53, 56, 57, B8, 68, 4B, 73, 00, E8, F5, 21, CD, FF, BF, 34, C6, 7D, 00, 33, C0, 55, 68, 92, 5A, 73, 00, 64, FF, 30, 64, 89, 20, E8, A5, 4B, D3, FF, 85, C0, 74, 07, 33, C0, E8, 5E, F6, CC, FF, B8, 30, C6, 7D, 00, E8, 10, F7, CC, FF, A1, 30, C6, 7D, 00, E8, D6, F9, CC, FF, 8B, D8, E8, 7F, 4B, D3, FF, 3B, D8, 0F, 85, A3, 00, 00, 00, BB, 20, 00, 00, 00, BE, 23, 50, 75, 00, 57, E8, FF, 33, CD, FF, 57, E8, F9, 33, CD, FF, 57, E8, F3, 33, CD, FF, 33, C0, 8A, 06, 89, 45, EC, DB, 45, EC, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
3.2 MB (3,361,792 bytes)

The file the sims 3 university life.exe has been seen being distributed by the following URL.

Remove the sims 3 university life.exe - Powered by Reason Core Security