deltatb.exe

Visual Tools

The application deltatb.exe by Visual Tools has been detected as adware by 8 anti-malware scanners. This is a setup program which is used to install the application. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from dl.cdn-services.com.
Publisher:
Visual Tools  (signed and verified)

MD5:
76e8f7f1e17ad61fa3a0f00e154179c1

SHA-1:
b005e1571f42b877d80f3358516130a60d1b3745

SHA-256:
9e398ddc1b3a6d9463cd05b76a7bef527d328dc3eff88cf5fdbdad13c841ead8

Scanner detections:
8 / 68

Status:
Adware

Analysis date:
4/26/2024 11:52:20 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Bbylon
4.0.3.15221

Dr.Web
Adware.Babylon.25
9.0.1.052

ESET NOD32
Win32/Toolbar.Babylon.H potentially unwanted (variant)
9.11209

K7 AntiVirus
Trojan
13.197.15038

Malwarebytes
PUP.Optional.ToolBarInstaller.A
v2015.02.21.04

NANO AntiVirus
Riskware.Win32.Babylon.dffshm
0.30.0.296

Reason Heuristics
PUP.VisualTools
15.2.21.4

Vba32 AntiVirus
suspected of Trojan.Downloader.gen
3.12.26.3

File size:
766.5 KB (784,880 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\deltatb.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/10/2013 5:30:00 AM

Valid to:
1/11/2015 5:29:59 AM

Subject:
CN=Visual Tools, O=Visual Tools, L=Belgrade, S=Serbia, C=RS

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
789958B0264F06055619270074AFA61F

File PE Metadata
Compilation timestamp:
10/31/2013 8:53:08 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:V4RoGUdYf8YDyYRGr+JUvPu785vEVhF8UYGuGayZpmnzpGCCD61yoUAnXanh/zPv:V4G1swOqvGA5DGpmnzsX6UAoyYB

Entry address:
0x1C35

Entry point:
55, 8B, EC, 83, E4, F8, B8, 7C, 1A, 00, 00, E8, BB, 62, 00, 00, 53, 56, 33, DB, 57, 8D, 8C, 24, E0, 07, 00, 00, 88, 5C, 24, 0E, C6, 44, 24, 0F, 01, E8, E6, 1A, 00, 00, 53, 89, 9C, 24, 3C, 0A, 00, 00, 89, 9C, 24, 40, 0A, 00, 00, 89, 9C, 24, 44, 0A, 00, 00, C7, 84, 24, 48, 0A, 00, 00, 03, 00, 00, 00, FF, 94, 24, 20, 08, 00, 00, 8D, 8C, 24, E0, 07, 00, 00, 89, 84, 24, 34, 0A, 00, 00, E8, 6D, FA, FF, FF, 8D, 8C, 24, E0, 07, 00, 00, E8, DF, FA, FF, FF, 85, C0, 0F, 85, ED, 00, 00, 00, 8D, 44, 24, 10, 50, 8D, 8C...
 
[+]

Entropy:
7.9234

Developed / compiled with:
Microsoft Visual C++

Code size:
30 KB (30,720 bytes)

The file deltatb.exe has been seen being distributed by the following URL.

Remove deltatb.exe - Powered by Reason Core Security