babylon10_setup.exe

Babylon Ltd.

This is part of the Babylon web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application babylon10_setup.exe by Babylon has been detected as adware by 9 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from www2.adtoadd.com and multiple other hosts.
Publisher:
Babylon Ltd.  (signed and verified)

MD5:
952384daa100677d9b7c16bbc7eb8cfe

SHA-1:
f9b8b80090a06ad5c0c494787670e5fe9a1ba795

SHA-256:
b658fb97cf7b4d0d771d728d8a330eefe785922e9a69eba2672afa4a637f5109

Scanner detections:
9 / 68

Status:
Adware

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
4/24/2024 3:11:02 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Agent
7.1.1

Baidu Antivirus
Adware.Win32.Bbylon
4.0.3.1419

Bkav FE
W32.Clodcfc.Trojan
1.3.0.4613

Dr.Web
Adware.Babylon.10
9.0.1.0365

ESET NOD32
Win32/Toolbar.Babylon (variant)
7.9290

Malwarebytes
v2013.12.31.03

Reason Heuristics
PUP.Installer.Babylon.P
14.8.7.19

Trend Micro House Call
TROJ_GEN.F47V0904
7.2.365

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.24.3

File size:
712.6 KB (729,680 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\babylon10_setup.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/27/2012 12:00:00 AM

Valid to:
3/8/2014 11:59:59 PM

Subject:
CN=Babylon Ltd., O=Babylon Ltd., L=Or-Yehuda, S=Or-Yehuda, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
48C39FBA62460E24E169054FE518E0AF

File PE Metadata
Compilation timestamp:
6/16/2013 12:48:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:nlN1j+I91Uq7zkanpKTqEn694USct5IJR54VPuO0xTvIrjK7Vh:lVHDkanp2694U8X5202Mr

Entry address:
0x1595

Entry point:
55, 8B, EC, 83, E4, F8, 81, EC, 44, 0A, 00, 00, A1, 00, 50, 40, 00, 33, C4, 89, 84, 24, 40, 0A, 00, 00, 53, 56, 33, DB, 57, 8D, 74, 24, 10, 88, 5C, 24, 0E, C6, 44, 24, 0F, 01, E8, C3, 05, 00, 00, 53, 89, 9C, 24, 6C, 02, 00, 00, 89, 9C, 24, 70, 02, 00, 00, 89, 9C, 24, 74, 02, 00, 00, C7, 84, 24, 78, 02, 00, 00, 03, 00, 00, 00, FF, 54, 24, 50, 89, 84, 24, 64, 02, 00, 00, 8B, C6, E8, 07, FA, FF, FF, 3B, C3, 0F, 85, 1A, 01, 00, 00, 8D, 84, 24, 78, 02, 00, 00, 50, 8B, FE, E8, 2C, FF, FF, FF, 8B, F8, 3B, FB, 0F...
 
[+]

Entropy:
7.9856

Developed / compiled with:
Microsoft Visual C++

Code size:
12 KB (12,288 bytes)

The file babylon10_setup.exe has been seen being distributed by the following 13 URLs.

http://www2.adtoadd.com/bannerrd.php?rand=5e7433d0ec7e738c04cc53e2d23942cb

http://www.babylon.com/.../download.cgi?type=100&affID=101522

Remove babylon10_setup.exe - Powered by Reason Core Security