babylon10_setup_ns.exe

The application babylon10_setup_ns.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from www.babylon.com.
MD5:
06e5ed5527da64532aa903812973ac92

SHA-1:
3ebc8a70785749df25adbcbcabdecf6bff6f0958

SHA-256:
d6877fad413664e4bcf951a708d894819af2d7d8a31c4adffd5da764b70fafe1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
4/24/2024 6:00:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Babylon
16.1.21.0

File size:
726.7 KB (744,096 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\babylon10_setup_ns.exe

File PE Metadata
Compilation timestamp:
4/19/2015 2:29:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:KZW4UKNnXYYE4oZG+EcuZy1sh1r/y1EpRaq/4KeNB1+l7i/W/K10Z6zvv4g8AkLx:KVUKNEjdh1szFmqAKqBu/KBz5U

Entry address:
0x4EEF

Entry point:
E8, 46, 26, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 28, 4A, 41, 00, E8, 0B, 28, 00, 00, E8, A1, 13, 00, 00, 0F, B7, F0, 6A, 02, E8, D9, 25, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 98, 1D, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
59.5 KB (60,928 bytes)

The file babylon10_setup_ns.exe has been seen being distributed by the following URL.

Remove babylon10_setup_ns.exe - Powered by Reason Core Security