bobylyricsdisplay2.exe

BobyLyrics

Visual Tools

The application bobylyricsdisplay2.exe by Visual Tools has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from dl.cdn-services.com.
Publisher:
BestOnlineBounty  (signed by Visual Tools)

Product:
BobyLyrics

Version:
1.0

MD5:
ac797885b9dfa69a2ef533148492ccad

SHA-1:
81834e4205cc338fbbe3114a685642d9520054e5

SHA-256:
1453e51b6bf2441d68e761ef850d382dd1fea3b86f89d2cd573d19d9747c6cf3

Scanner detections:
1 / 68

Status:
Adware

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
4/19/2024 7:05:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Babylon.Banylon.Installer (M)
16.2.10.15

File size:
611.6 KB (626,248 bytes)

Copyright:
© BestOnlineBounty

Trademarks:
BobyLyrics

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\bobylyricsdisplay2.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/10/2013 12:00:00 AM

Valid to:
1/10/2015 11:59:59 PM

Subject:
CN=Visual Tools, O=Visual Tools, L=Belgrade, S=Serbia, C=RS

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
789958B0264F06055619270074AFA61F

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:ZMU/RVVLxkTNLHLskwwVz7VBmMmJ1mMz5dY05m8Hfs3cltLG73XoV0yhCe+J:ZvVF6Nblz3kbhI2ssltLGzXoetXJ

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file bobylyricsdisplay2.exe has been seen being distributed by the following URL.

Remove bobylyricsdisplay2.exe - Powered by Reason Core Security