babylon10_setup.exe

Babylon Ltd.

This is part of the Babylon web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application babylon10_setup.exe by Babylon has been detected as adware by 8 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from www.babylon.com and multiple other hosts.
Publisher:
Babylon Ltd.  (signed and verified)

MD5:
8ee88f4f4fe28b03e9f42eb700447985

SHA-1:
800274fd8d673ee5738c49738b2ac729a26d8110

SHA-256:
d7658faff0c0d13496eafa9bab358e9fee66687f731c14a152e321025f01a28e

Scanner detections:
8 / 68

Status:
Adware

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
4/23/2024 5:11:31 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Bbylon
4.0.3.14613

Dr.Web
Adware.Babylon.25
9.0.1.0164

ESET NOD32
Win32/Toolbar.Babylon (variant)
8.9940

Fortinet FortiGate
Riskware/Toolbar_Babylon
6/13/2014

Malwarebytes
PUP.Optional.ToolBarInstaller.A
v2014.06.13.04

McAfee
Artemis!8EE88F4F4FE2
5600.7100

Reason Heuristics
PUP.Installer.Babylon.P
14.8.7.19

Trend Micro House Call
TROJ_GEN.F47V0605
7.2.164

File size:
634.1 KB (649,336 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/12/2014 1:00:00 AM

Valid to:
3/8/2016 12:59:59 AM

Subject:
CN=Babylon Ltd., O=Babylon Ltd., L=Or-Yehuda, S=Or-Yehuda, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
4A3CB79EE8B7A32A0263FE5D13CC5291

File PE Metadata
Compilation timestamp:
10/31/2013 4:23:08 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:74R2QZkVtwr6PSRUNSYSHj2FOm9PZXpmf2Hxy70Q9YNGmQ:74cQaVtg4SObij6Oe9Qf2HYYNGmQ

Entry address:
0x1C35

Entry point:
55, 8B, EC, 83, E4, F8, B8, 7C, 1A, 00, 00, E8, BB, 62, 00, 00, 53, 56, 33, DB, 57, 8D, 8C, 24, E0, 07, 00, 00, 88, 5C, 24, 0E, C6, 44, 24, 0F, 01, E8, E6, 1A, 00, 00, 53, 89, 9C, 24, 3C, 0A, 00, 00, 89, 9C, 24, 40, 0A, 00, 00, 89, 9C, 24, 44, 0A, 00, 00, C7, 84, 24, 48, 0A, 00, 00, 03, 00, 00, 00, FF, 94, 24, 20, 08, 00, 00, 8D, 8C, 24, E0, 07, 00, 00, 89, 84, 24, 34, 0A, 00, 00, E8, 6D, FA, FF, FF, 8D, 8C, 24, E0, 07, 00, 00, E8, DF, FA, FF, FF, 85, C0, 0F, 85, ED, 00, 00, 00, 8D, 44, 24, 10, 50, 8D, 8C...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
30 KB (30,720 bytes)

The file babylon10_setup.exe has been seen being distributed by the following 17 URLs.

http://www.babylon.com/.../download.cgi?type=100&d=ccd5d2ef7c31ae09d5b7dac72341081a

http://www.babylon.com/.../download.cgi?type=100&d=6d5375fc17a018a91c6e6be0ef236933

http://www.babylon.com/.../download.cgi?type=100&d=68f62f4a4792056d08a95e44b3ee11e0

http://www.babylon.com/.../download.cgi?type=7416&d=36f602fdfba44adf270b07829c195f6d

Remove babylon10_setup.exe - Powered by Reason Core Security