the-sims-4-full-version.exe

Bebokekek

Destiny Dream S.A.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application the-sims-4-full-version.exe, “Bebokekek Setup ” by Destiny Dream S.A has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The file has been seen being downloaded from www.bodybundleflash.com and multiple other hosts.
Publisher:
Destiny Dream S.A.  (signed and verified)

Product:
Bebokekek

Description:
Bebokekek Setup

MD5:
448239fd51d7d478e0584dd8709d8e40

SHA-1:
27e3eb388c2e7b3ad1dc7ad837edd3c913614c31

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/5/2024 8:33:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore.DestinyD.Installer (M)
16.5.10.7

File size:
993.2 KB (1,017,016 bytes)

Product version:
4.4

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\My documents\downloads\the-sims-4-full-version.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/9/2015 9:58:51 AM

Valid to:
10/2/2016 8:36:18 AM

Subject:
CN=Destiny Dream S.A., O=Destiny Dream S.A., L=Clarens, S=Vaud, C=CH

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112188521AED0C8EC20707151AF45D10C88E

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:dJTWlt94fR7jZcnhoPhjSX548zMzXWqCL24zHx0T1+6f6:dZICZcY0uwMzXLCL2u

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9238

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file the-sims-4-full-version.exe has been seen being distributed by the following 42 URLs.

http://www.bodybundleflash.com/c?x=knkfKOEpQkccBEx7P3KlMphfp0kShKy/swf7YUb/VJU=&c=KqGh50IIyeTfGjJCeQLLVbTOUTmlrMtN8TFiStGPRiYYIujEG Ve6Y0q3uwE 58r7OdXicrJiWA9ydTbZdzXVTsgcxjDj6yiIkspKtB JJKHTxFcSQcAQ0F0ZTuIc7LIs6jre6UBUwpOWRFBmOJwSw==&e=0&downloadAs=the-sims-4-full-version.exe&fallback_url=http://www.thesims.com/en-us/.../product

http://www.bundleuniversenew.com/c?x=OwD9Dr77Df6GAz00ZQrtOF91Trkt3SAnn/0l0/MYiic=&c=d 8TyVYBQbWAWBWxq3tE/zOrCPrUE1Q8y5b3o884U uPxPL49Pi3zxuufgx7u/VPGGsC0XAS9IUfBtbThH1iO3JVzJSg98jhD7J1F//R9cmFz1c1dZ1 7BRXENPFl7hS3TAVxaecWOgTBnn5a4fMcQ==&e=0&downloadAs=the-sims-4-full-version.exe&fallback_url=http://www.thesims.com/en-us/.../product

http://www.stockclearhead.com/c?x=vdqfaZWrqwtFrFhVLFBuwQGGos37STQFxgi2rtaYSHQ=&c=fLprUY4NFAOuD6AMN6TJaQanMJoYClSiOsepgdnNkQbeHxBoRQlqy68L6J9RvR/4bWZRoEfTTDV9q3KqbomTZo8lHFNQXL4eNkByJDsFjQ2aZ7QmQUGhZeIy/HRO2dr1AYexgtXzBA3FU F GN6RV1EVEe5Xx0vfCs15q7PEGXU=&e=0&downloadAs=the-sims-4-full-version.exe&fallback_url=http://www.thesims.com/en-us/.../product

http://www.clearsharetoday.com/c?x=zEELU1RSaj JK88MNAFY tfTHkgmttGS4xro o0byAs=&c=cyHVowRBWKE2uED23aUdMbYSGkkCfuY5CIVkL9/sUEYpf5dYYj5TKoDcpIOJk uDFxMkMsWxvBTc3yB7SbAYf7fqUdcAIHxHHT/F/ZLgDk1MWanNwIkXznHCl7qD5ZqYWTfXbv7sF56KQApRtwTpvIsTQvV3WP6 Otv5TURRX7g=&e=0&downloadAs=the-sims-4-full-version.exe&fallback_url=http://www.thesims.com/en-us/.../product

http://www.signsfilesclean.com/c?x=Kpsq21fCiObITOkFceDz beMzr5tGv4yqR30OQca56I=&c=fk715qV3UUPFTZnX5mDwPZHQTZ 5x EESAEn7iusl8tG /GUclqYSK8xI7RZnNvuewSBSrSTM2vH546c8R1go0Mm2b3eua2n/0Dr X52lxwwwzEGSViWKSt99sKjStaBnxxAaAjx7vCahM/bqVRMaw==&e=0&downloadAs=the-sims-4-full-version.exe&fallback_url=http://www.thesims.com/en-us/.../product

http://www.towerstodayvaults.com/c?x=PSQoMbZnnkChfhK9u0kfKTVMSYCgrPMVZSls8SYUUs0=&c=hXRXl3WSFThTfTXXGcrctKKmMO7QGru1ELiFb/MMBrzJpEGXLLHxt/AYr6JRKI3C3EWDAV S95LTQoJqvWC13WXXWGE/d4kIW93jR2a1f37CFcPY/9CgPDFV97Aj34g4HVJBnaqKdVNoaa1SJ DN6hCVj5LzFQ2xyP1s7zTvOGw=&e=0&downloadAs=the-sims-4-full-version.exe&fallback_url=http://www.thesims.com/en-us/.../product

Latest 30 of 42 download URLs

Remove the-sims-4-full-version.exe - Powered by Reason Core Security